Skip to content

Receive FalconArtifact

bk-cs edited this page Dec 12, 2022 · 18 revisions

Receive-FalconArtifact

SYNOPSIS

Download an artifact from a Falcon Intelligence Sandbox report

DESCRIPTION

Artifact identifier values can be retrieved for specific Falcon Intelligence Sandbox reports using 'Get-FalconReport'.

Requires 'Sandbox (Falcon Intelligence): Read'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Path String Destination path
Id String X X Artifact identifier
Force Switch Overwrite an existing file when present

SYNTAX

Receive-FalconArtifact [-Path] <String> [-Id] <String> [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]

SDK Reference

falconpy

GetArtifacts

USAGE

Download a strict IOC pack

$Report = Get-FalconReport -Id <id>
Receive-FalconArtifact -Id $Report.ioc_report_strict_csv_artifact_id -Path .\ioc_report_strict_csv_artifact_id.csv

See Get-FalconReport.

2022-12-12: PSFalcon v2.2.3

Clone this wiki locally