2.2.9 #485
bk-cs
announced in
Announcements
2.2.9
#485
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Removed Commands
detects
falcon-complete-dashboards
New Commands
case-files
casemgmt
cases
correlation-rules
cloud-security-assets
fem
fwmgr
humio
hunting
intel
it-automation
ngsiem-content
oauth2
policy-content-update
policy-device-control
real-time-response
Issues Resolved
Invoke-FalconDeploydoesn't execute scripts specified in theFileparameter #441: Added code to ensure that the finalrunstep takes place when usingFilewith Windows or Machosts. Previously, the
runstep was never reached because theextractstep (only necessary when using theArchiveandRunparameters) was not processed. Now that step will be effectively ignored when using theFileparameter for Mac and Windows which should lead everything completing successfully.Import-FalconConfigfails to modify and ignores defaultSensorUpdatePolicy#444: Corrected use ofHomeCidto properly evaluate policies to be modified when not in a FlightControl environment, along with errors related to
variantsandschedulerinSensorUpdatePolicy.Import-FalconConfiggeneratesCannot overwrite variableerror #445: Solved withImport-FalconConfigre-write.Import-FalconConfiggeneratesIoaRuleorIoaGroupproperty-related error #446: Forcedcommentwhen creating/modifyingIoaRule, andversionwhen creating/modifyingIoaGroupusing
Import-FalconConfig.Import-FalconConfigonly createsScriptfor a singleplatform#447: CorrectedCompare-ImportDataunderImport-FalconConfigto check both target CID and import filesfor possible
platformvalues and ensure thatScript(and other imports) check all availableplatformvalues.
Remove-FalconSensorTagreturns statusTAG_NOT_PRESENTwhen attempting to delete only tag #450: Updated internalInvoke-TagScriptfunction to properly remove single tag present on target host.Import-FalconConfigPrevention policy with multiple prevention policies using settings of first policy #453: Solved withImport-FalconConfigre-write.Import-FalconConfigCID check issue #454: Solved withImport-FalconConfigre-write.Import-FalconConfigcreates invalidFirewallRule#455: Various bugfixes added toEdit-FalconFirewallGroupandNew-FalconFirewallGroupto properlyhandle rules that have singule property values under property arrays.
New-FalconIOCandEdit-FalconIOCExpiration parameter error #463: CorrectedValidatePatternforExpirationunderEdit-FalconIocandNew-FalconIocto onlyallow UTC ISO 8601.
update_check.jsondenied when installed as administrator, can it be disabled? #470: UpdatedInvoke-UpdateCheckfunction to check for write access to module folder before attemptingto create
update_check.json.Edit-FalconIocgenerates400: Provided data does not match expected formaterror #479: Updatedformat.jsonto removebulk_updatefields which were causing errors withEdit-FalconIoc.General Changes
Send-FalconPutFileattempts.Command Changes
Add-FalconRole
ExpiresAt. Thanks @cr4shtest!ConvertTo-FalconFirewallRule
[PSCustomObject[]]to[hashtable[]]to better support pipelining toNew-FalconFirewallGroup.ConvertTo-FalconIoaExclusion
ConvertTo-FalconMlExclusion
Copy-FalconDeviceControlPolicy
Edit-FalconDeviceControlPolicyandNew-FalconDeviceControlPolicycommands.Edit-FalconAsset
Triage.CommenttoDescriptionand modified help text for parameter.Edit-FalconCertificateExclusion
CidtoMemberCid. CorrectedValidatePatternto properly handle CCID values.Edit-FalconCloudAwsAccount
ClientId,DeploymentMethod, andRootStackId.Edit-FalconDeviceControlPolicy
/policies/entities/device-control/v2:patch.Default,Blocked,UseBlocked,Restricted, andUseRestricted.Propagated.Edit-FalconFirewallLocation
HttpsReachableHostandIcmpRequestTargetto handle pipelined objects instead of only strings.Edit-FalconMlExclusion
ExcludedFrom.Export-FalconConfig
FirewallLocation.Select, now the command will only export assigned items insteadof forcing all items of that type. For example, if
PreventionPolicyis chosen, assignedHostGroupandIoaGroupwill be included, instead of allHostGroupandIoaGroupitems.Find-FalconDuplicate
Fieldproperty withGet-FalconHost.Find-FalconHostname
Fieldproperty withGet-FalconHost.Get-FalconAlert
/alerts/combined/alerts/v1:postwhen usingDetailedandFilter.Get-FalconAsset
/fem/queries/external-assets/v2:getendpoint.Get-FalconCompleteAlert
/falcon-complete-dashboards/queries/alerts/v2:get.Get-FalconContainerCount
Filterwhen usingResource: containerandType: count-by-registryGet-FalconContentState
Idvalues per request.Get-FalconCorrelationRule
ValidatePatterntoId./correlation-rules/queries/rules/v2:getand/correlation-rules/entities/rules/v2:get.Get-FalconDeviceControlPolicy
/policy/entities/device-control/v2:getand removedDefaultparameter.Get-FalconFirewallPlatform
ValidateSetto account for new platform values.Get-FalconFirewallRule
PolicyIdvalue.Get-FalconFoundrySearch
JobStatusOnly.Get-FalconHost
/devices/combined/devices/v1:getand/devices/combined/devices-hidden/v1:getwhen using newFieldparameter.
FieldwithIncludewhendevice_idis not inFieldlist.10000when using new endpoints (5000for others).filesystem_containment_statusvalues toSort. Thanks @agent268!Get-FalconMalwareFamily
/intel/combined/malware/v1:getwhen usingDetailed.Field.Get-FalconRole
/user-management/combined/user-roles/v2:getand/user-management/entities/roles/GET/v2:post.Get-FalconRule
Typevaluescql-changelog,cql-master, andcql-update.Get-FalconWorkflowAction
Libraryswitch to show all Fusion SOAR library actions.Import-FalconConfig
Import-FalconConfig. Cleaned up code and moved into functions for easier troubleshooting in thefuture.
Selectparameter to allow filtering of files used from import archive.Allvalue toModifyExistingandModifyDefault.Edit-FalconDeviceControlPolicyandNew-FalconDeviceControlPolicycommands andnew
Edit-FalconDeviceControlClasscommand.FirewallLocation.Invoke-FalconContentPolicyAction
override-allow', 'override-pause,override-revert,remove-pinned-content-version, andset-pinned-content-versionactions.Invoke-FalconHostAction
lift_filesystem_containment_alltoName. Thanks @agent268!filesystem_containment_statustoInclude. Thanks @agent268!Invoke-FalconIdentityGraph
Invoke-FalconIdentityGraphto ensurehasNextPageis true before trying second page.Allswitch withtimelineresults.New-FalconCertificateExclusion
CidtoMemberCid. CorrectedValidatePatternto properly handle CCID values.New-FalconCloudAwsAccount
ClientId,DeploymentMethod, andRootStackId.New-FalconDeviceControlPolicy
/policies/entities/device-control/v2:post.New-FalconFirewallLocation
HttpsReachableHostandIcmpRequestTargetto handle pipelined objects instead of only strings.New-FalconHostGroup
New-FalconScan
CloudPupDetectionandCloudPupPrevention.CpuPriorityto mandatory.New-FalconScheduledScan
CloudPupDetectionandCloudPupPrevention.CpuPriorityto mandatory.New-FalconSubmission
Aid,AutoDetect,Browser,Interactivity, andSendEmail.ubuntu20_x64andwin11_x64toEnvironmentId.Receive-FalconRule
Typevaluescql-changelog,cql-master, andcql-update.Remove-FalconCorrelationRule
ValidatePatterntoId.Remove-FalconHostGroup
500: Contact Supporterrors.Show-FalconToken
no_authorization_request_madetono_access_request_made.Test-FalconToken
no_authorization_request_madetono_access_request_made.This discussion was created from the release 2.2.9.
Beta Was this translation helpful? Give feedback.
All reactions