Skip to content

Cloud Security Accessed Provider Endpoints

AWS Cloud Security

OperationProvider Endpoints
Query Compliance FindingsPOST /findingsv2
Query IOMsPOST /findingsv2
Query ThreatsPOST /findingsv2

AWS EventBridge SQS

OperationProvider Endpoints
Query Compliance FindingsPOST /

CrowdStrike Falcon® Insight EDR

OperationProvider Endpoints
Query Cloud Resource InventoryGET /cloud-security-assets/entities/resources/v1
GET /cloud-security-assets/queries/resources/v1
Query Compliance FindingsGET /cloud-security-assets/combined/compliance-controls/by-account-region-and-resource-type/v1
Query IOMsGET /detects/entities/iom/v2
GET /detects/queries/iom/v2

Microsoft Defender for Cloud

OperationProvider Endpoints
Query Cloud Resource InventoryPOST /providers/Microsoft.ResourceGraph/resources
Query Compliance FindingsGET /subscriptions/{subscriptionId}/providers/Microsoft.Security/regulatoryComplianceStandards
Query EventsPOST /api/v1/activities/
Query ThreatsGET /subscriptions/{subscriptionId}/providers/Microsoft.Security/alerts

Palo Alto Networks Cortex Cloud Security

OperationProvider Endpoints
Query Cloud Resource InventoryPOST /public_api/v1/assets
Query Compliance FindingsPOST /public_api/v1/issue/search
Query IOMsPOST /public_api/v1/issue/search