Skip to content

EDR Connector: Accessed Provider APIs

The following APIs are accessed by the EDR connector.

Microsoft Defender

Synqly APIProvider API
DELETE /v1/edr/iocsPOST /api/indicators/batchdelete
GET /v1/edr/alertsGET /api/alerts
GET /v1/edr/endpointsGET /api/machines
GET /v1/edr/iocsGET /api/indicators
GET /v1/edr/posture_scoreGET /api/machines
GET /v1/edr/threatsGET /api/incidents
POST /v1/edr/iocsPOST /api/indicators

Tanium EDR

Synqly APIProvider API
GET /v1/edr/alertsGET /plugin/products/threat-response/api/v1/alerts
GET /v1/edr/applicationsPOST /plugin/products/gateway/graphql
GET /v1/edr/endpointsPOST /plugin/products/gateway/graphql
GET /v1/edr/posture_scorePOST /plugin/products/gateway/graphql

SentinelOne Endpoint

Synqly APIProvider API
DELETE /v1/edr/iocsDELETE /web/api/v2.1/threat-intelligence/iocs
GET /web/api/v2.1/threat-intelligence/iocs
GET /v1/edr/alertsGET /web/api/v2.1/cloud-detection/alerts
GET /v1/edr/applicationsGET /web/api/v2.1/application-management/inventory
GET /v1/edr/edr_eventsPOST /api/query
GET /v1/edr/endpointsGET /web/api/v2.1/agents
GET /v1/edr/iocsGET /web/api/v2.1/threat-intelligence/iocs
GET /v1/edr/threatsGET /web/api/v2.1/threats
POST /v1/edr/iocsPOST /web/api/v2.1/threat-intelligence/iocs