EDR Connector: Accessed Provider APIs

The following APIs are accessed by the EDR connector.

Defender EDR

Synqly APIProvider API
DELETE /v1/edr/iocsPOST /api/indicators/batchdelete
POST /v1/edr/iocsPOST /api/indicators

CrowdStrike EDR

Synqly APIProvider API
GET /v1/edr/alertsGET /alerts/queries/alerts/{item}
POST /alerts/entities/alerts/{item}
GET /v1/edr/endpointsGET /devices/queries/devices/{item}
GET /devices/entities/devices/{item}
GET /v1/edr/endpoints/{id}GET /devices/queries/devices/{item}
GET /devices/entities/devices/{item}
POST /v1/edr/endpoints/actions/quarantinePOST /devices/entities/devices-actions/{item}