EDR Query Filters

This document provides details on the filters supported by each provider for each API operation. Filters can be used to restrict the results of an API operation, such as filtering by a specific field or value.

They are used in conjunction with the filter query parameter in the API request.

CrowdStrike EDR filters for query_alerts

FieldOperatorsSupported Values
attacks.tactic.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
attacks.tactic.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
attacks.technique.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
attacks.technique.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
commenteq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
confidence_scoreeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.os.typeeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.uid_alteq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.titleeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
finding_info.typeseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
finding_info.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
metadata.feature.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
metadata.loggers.logged_timegt, gte, lt, ltedatetime
metadata.tenant_uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
resources.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
resources.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
risk_scoreeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
start_timegt, gte, lt, ltedatetime
start_time_dtgt, gte, lt, ltedatetime
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime
vulnerabilities.desceq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
vulnerabilities.titleeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring

Defender EDR filters for query_alerts

FieldOperatorsSupported Values
actor.user.nameeq, in, nestring
analytic.categoryeq, in, nestring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.uideq, in, nestring
metadata.uideq, in, nestring
severityeq, in, nestring
statuseq, in, nestring

Malwarebytes EDR filters for query_alerts

FieldOperatorsSupported Values
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.uideqstring
metadata.uideqstring
severityeqstring
statuseqstring

SentinelOne EDR filters for query_alerts

FieldOperatorsSupported Values
actor.process.file.pathlikestring
confidenceeqstring
device.container.imagelikestring
device.container.namelikestring
device.container.taglikestring
device.hostnameeq, likestring
device.last_seen_timegt, gte, lt, ltedatetime
device.modified_timegt, gte, lt, ltedatetime
device.org.uideqstring
device.os.typeeqstring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.first_seen_timegt, gte, lt, ltedatetime
metadata.product.versioneqstring
timegt, gte, lt, ltedatetime

Sophos EDR filters for query_alerts

FieldOperatorsSupported Values
finding_info.created_timelt, gtdatetime
finding_info.last_seen_timelt, gtdatetime
finding_info.titlelt, gt, eq, instring
metadata.product.namelt, gt, eq, instring
metadata.uidlt, gt, eq, instring

CrowdStrike EDR filters for query_applications

FieldOperatorsSupported Values
metadata.modified_timegt, gte, lt, ltedatetime
metadata.modified_time_dtgt, gte, lt, ltedatetime
product.nameeq, ne, in, not_instring
product.patheq, ne, in, not_instring
product.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
product.vendor_nameeq, ne, in, not_instring
product.versioneq, ne, in, not_instring
start_timegt, gte, lt, ltedatetime
start_time_dtgt, gte, lt, ltedatetime
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime

Defender EDR filters for query_applications

FieldOperatorsSupported Values
product.namelikestring
product.uideq, likestring
product.vendor_namelikestring
product.versioneq, likestring

Malwarebytes EDR filters for query_applications

FieldOperatorsSupported Values
device.uideqstring
product.nameeqstring
product.uideqstring
product.vendor_nameeqstring
product.versioneq, gt, gte, lt, ltestring

SentinelOne EDR filters for query_applications

FieldOperatorsSupported Values
product.namelikestring
product.uideq, likestring
product.vendor_namelikestring
product.versioneq, likestring

Sophos EDR filters for query_applications

FieldOperatorsSupported Values
product.namelt, gt, eq, instring
product.pathlt, gt, eq, instring

CrowdStrike EDR filters for query_endpoints

FieldOperatorsSupported Values
device.first_seen_timegt, gte, lt, ltedatetime
device.hostnameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.hw_info.bios_manufacturereq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.hw_info.bios_vereq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.hw_info.chassiseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.hw_info.serial_numbereq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.instance_uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.ipeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.last_seen_timegt, gte, lt, ltedatetime
device.maceq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.modified_timegt, gte, lt, ltedatetime
device.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.org.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.org.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.os.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.os.typeeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.os.type_ideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.os.versioneq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.typeeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.type_ideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.zoneeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
statuseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
timegt, gte, lt, ltedatetime

Defender EDR filters for query_endpoints

FieldOperatorsSupported Values
cloud.account.uideq, ne, like, not_likestring
device.hostnameeq, ne, like, not_likestring
device.ipeq, ne, like, not_likestring
device.last_time_seeneq, ne, like, not_likestring
device.os.nameeq, ne, like, not_likestring
device.risk_leveleq, ne, like, not_likestring
device.uideq, ne, like, not_likestring
enrichments.reputation.scoreeq, ne, like, not_likestring
metadata.labelseq, ne, like, not_likestring
metadata.product.versioneq, ne, like, not_likestring
risk_level_ideq, ne, like, not_likestring
statuseq, ne, like, not_likestring
status_codeeq, ne, like, not_likestring
status_detaileq, ne, like, not_likestring

Malwarebytes EDR filters for query_endpoints

FieldOperatorsSupported Values
created_atgt, gte, lt, ltedatetime
deleted_atgt, gte, lt, ltedatetime
device.domaineqstring
device.group_ideqstring
device.group_nameeqstring
device.hw_info.serial_numbereqstring
device.ipeqstring
device.last_seen_timegt, gte, lt, ltedatetime
device.maceqstring
device.nameeqstring
device.os.cpu_bitseqstring
device.os.nameeqstring
device.os.typeeqstring
device.os.versioneqstring
device.protection_statuseqstring
device.uideqstring
metadata.product.versioneq, gt, gte, lt, ltestring
timegt, gte, lt, ltedatetime

SentinelOne EDR filters for query_endpoints

FieldOperatorsSupported Values
device.domaineq, likestring
device.hostnameeq, likestring
device.hw_info.serial_numberlikestring
device.instance_uideqstring
device.iplikestring
device.maclikestring
device.nameeq, likestring
device.os.namelikestring
device.os.typeeq, likestring
device.os.versionlikestring
device.typeeq, likestring
device.uideq, likestring
statuseq, likestring

Sophos EDR filters for query_endpoints

FieldOperatorsSupported Values
device.typene, lte, gte, lt, gt, eq, instring
device.uidne, lte, gte, lt, gt, eq, instring
first_seen_timeeqdatetime
last_seen_timeeqdatetime
statusne, lte, gte, lt, gt, eq, instring
status_detailne, lte, gte, lt, gt, eq, instring
timeeqdatetime

CrowdStrike EDR filters for query_iocs

FieldOperatorsSupported Values
createdgt, gte, lt, ltedatetime
created_by_ref.ideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.actioneq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.expiredeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.host_groupseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.mobile_actioneq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.modified_byeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.platformseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
extensions.severityeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
labelseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
modifiedgt, gte, lt, ltedatetime
patterneq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
pattern_typeeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
valid_untilgt, gte, lt, ltedatetime

Defender EDR filters for query_iocs

FieldOperatorsSupported Values
createdeq, instring
created_by_ref.Ideq, instring
created_by_ref.nameeq, instring
extensions.actioneq, instring
extensions.alerteq, instring
extensions.applicationeq, instring
extensions.rbacGroupIdseq, instring
extensions.rbacGroupNameseq, instring
extensions.severityeq, instring
nameeq, instring
patterneq, instring
pattern_typeeq, instring
valid_untileq, instring

Malwarebytes EDR filters for query_iocs

FieldOperatorsSupported Values

SentinelOne EDR filters for query_iocs

FieldOperatorsSupported Values
createdgt, gte, lt, ltedatetime
created_by_reflikestring
descriptionlikestring
extensions.accountIdseqstring
extensions.batchIdeqstring
extensions.categoryeqstring
extensions.externalIdeqstring
extensions.groupIdseqstring
extensions.sideIdseqstring
extensions.sourceeqstring
extensions.uploadTimegt, gte, lt, ltedatetime
ideqstring
modifiedgt, gte, lt, ltedatetime
namelikestring
patterneqstring
valueeqstring

Sophos EDR filters for query_iocs

FieldOperatorsSupported Values

CrowdStrike EDR filters for query_threatevents

FieldOperatorsSupported Values
actor.process.cmd_lineeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
actor.process.file.md5eq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
actor.process.file.nameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
actor.process.file.patheq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
actor.process.file.sha256eq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
actor.process.file.typeeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
confidence_scoreeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.first_seen_time_dtgt, gte, lt, ltedatetime
device.hostnameeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.ipeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
device.last_seen_time_dtgt, gte, lt, ltedatetime
device.modified_time_dtgt, gte, lt, ltedatetime
device.product_uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
severityeq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
severity_ideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
statuseq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring
tenant_uideq, ne, gt, gte, lt, lte, in, not_in, like, not_likestring

Defender EDR filters for query_threatevents

FieldOperatorsSupported Values
actor.user.namelt, gt, eq, instring
finding_info.created_timelt, gtdatetime
finding_info.modified_timelt, gtdatetime
statuslt, gt, eq, instring

Malwarebytes EDR filters for query_threatevents

FieldOperatorsSupported Values
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.uideqstring
metadata.uideqstring
severityeqstring
statuseqstring

SentinelOne EDR filters for query_threatevents

FieldOperatorsSupported Values
actor.process.created_time_dtgt, gte, lt, ltedatetime
actor.process.file.pathlikestring
confidenceeqstring
device.container.imagelikestring
device.container.namelikestring
device.container.taglikestring
device.groups.uideqstring
device.hostnameeq, likestring
device.ideqstring
device.last_seen_timegt, gte, lt, ltedatetime
device.modified_timegt, gte, lt, ltedatetime
device.org.uideqstring
device.os.typeeqstring
malware.classificationseqstring
metadata.product.versioneqstring

Sophos EDR filters for query_threatevents

FieldOperatorsSupported Values
actor.user.nameeqstring
attacks.tactics.nameeqstring
device.first_seen_timeeqdatetime
device.first_seen_time_dteqdatetime
device.last_seen_timeeqdatetime
device.last_seen_time_dteqdatetime
device.locationeqstring
device.os.nameeqstring
device.os.typeeqstring
device.typeeqstring
hostnameeqstring
metadata.product.nameeqstring
risk_scoreeqstring
severityeqstring
type_nameeqstring
vendor_nameeqstring
vulnerabilities.titleeqstring