Skip to content

CrowdStrike Falcon® Insight EDR

OperationProvider Endpoints
Create IOCsPOST /iocs/entities/indicators/v1
Delete IOCsDELETE /iocs/entities/indicators/v1
Get EndpointGET /devices/combined/devices/v1
Quarantine EndpointsPOST /devices/entities/devices-actions/v2
Query AlertsPOST /alerts/combined/alerts/v1
Query ApplicationsGET /discover/entities/applications/v1
GET /discover/queries/applications/v1
Query EDR EventsGET /alerts/queries/alerts/v2
POST /alerts/entities/alerts/v2
Query EndpointsGET /devices/combined/devices/v1
Query IOCsGET /iocs/entities/indicators/v1
GET /iocs/queries/indicators/v1
Query Posture ScoreGET /devices/combined/devices/v1
GET /zero-trust-assessment/entities/assessments/v1
GET /zero-trust-assessment/queries/assessments/v1
Query Threat EventsGET /alerts/queries/alerts/v2
POST /alerts/entities/alerts/v2

ESET Connect

OperationProvider Endpoints
Query AlertsGET /v1/detections
Query EndpointsGET /v1/device_groups
GET /v1/device_groups/{deviceGroupId}/devices
GET /v1/devices:batchGet

ThreatDown Endpoint Detection & Response

OperationProvider Endpoints
Query ApplicationsPOST /nebula/v1/assets/software
Query EndpointsPOST /nebula/v1/endpoints
Query Threat EventsPOST /nebula/v1/detections

SentinelOne Singularity™ Endpoint

OperationProvider Endpoints
Create IOCsPOST /web/api/v2.1/threat-intelligence/iocs
Delete IOCsDELETE /web/api/v2.1/threat-intelligence/iocs
Query AlertsGET /web/api/v2.1/cloud-detection/alerts
Query ApplicationsGET /web/api/v2.1/application-management/inventory
Query EndpointsGET /web/api/v2.1/agents
Query IOCsGET /web/api/v2.1/threat-intelligence/iocs
Query Threat EventsGET /web/api/v2.1/threats

Sophos Endpoint

OperationProvider Endpoints
Query AlertsGET /common/v1/alerts
GET /whoami/v1
Query EndpointsGET /endpoint/v1/endpoints
GET /whoami/v1