Overview
Manage container image security, registry integrations, vulnerability assessments, and security policies for Falcon Container Security. These cmdlets enable comprehensive container lifecycle security including image scanning, policy enforcement, registry management, and runtime protection.Prerequisites
- Falcon Container Image: Read - Required for retrieval operations
- Falcon Container Image: Write - Required for provisioning and modifications
Container Images
Get-FalconContainerImage
Search for Falcon Cloud Security container images.Get-FalconContainerImage
Parameters
Falcon Query Language expression to limit results
Property and direction to sort results
Maximum number of results per request
Include container image configuration detail
Position to begin retrieving results
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
New-FalconContainerImage
Create a Falcon Cloud Security base container image.New-FalconContainerImage
Parameters
Container image identifier
Container image digest
Container registry
Container repository
Container tag
Example
Remove-FalconContainerImage
Remove a Falcon Cloud Security base container image.Remove-FalconContainerImage
Parameters
Container image identifier
Example
Container Registries
Get-FalconContainerRegistry
List Falcon Cloud Security registries.Get-FalconContainerRegistry
Parameters
Container registry identifier (GUID format)
Property and direction to sort results
Maximum number of results per request (default: 100, max: 5000)
Position to begin retrieving results
Retrieve detailed information
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
New-FalconContainerRegistry
Create a registry within Falcon Cloud Security.New-FalconContainerRegistry
Parameters
Desired registry name within Falcon Cloud Security
Registry type. Valid values:
acr, artifactory, docker, dockerhub, ecr, gar, gcr, github, gitlab, harbor, icr, mirantis, nexus, openshift, oracle, quay.ioURL used to log in to the registry
Hashtable containing username and password used to access the registry
Registry URL alias
Example
Edit-FalconContainerRegistry
Modify a registry within Falcon Cloud Security.Edit-FalconContainerRegistry
Parameters
Container registry identifier (GUID format)
Falcon Cloud Security registry name
Registry connection state. Valid values:
pause, resumeHashtable containing credentials to access the registry
Example
Container Policies
Get-FalconContainerPolicy
List Falcon Cloud Security container policies.Get-FalconContainerPolicy
Example
New-FalconContainerPolicy
Create a Falcon Cloud Security container policy.New-FalconContainerPolicy
Parameters
Policy name
Policy description
Example
Edit-FalconContainerPolicy
Modify a Falcon Cloud Security container policy.Edit-FalconContainerPolicy
Parameters
Image assessment policy identifier (GUID format)
Policy name
Policy enablement status
Policy description
One or more hashtables containing rule “action” and “policy_rules_data”
Example
Remove-FalconContainerPolicy
Delete Image Assessment Policy by policy UUID.Remove-FalconContainerPolicy
Parameters
Image assessment policy identifier (GUID format)
Example
Vulnerability & Assessment
Get-FalconContainerAssessment
Search for Falcon Container Security image assessment results.Get-FalconContainerAssessment
Parameters
Falcon Query Language expression to limit results
Property and direction to sort results. Valid values include:
first_seen.asc, first_seen.desc, highest_detection_severity.asc, highest_detection_severity.desc, highest_vulnerability_severity.asc, highest_vulnerability_severity.desc, image_digest.asc, image_digest.desc, registry.asc, registry.desc, repository.asc, repository.desc, tag.asc, tag.descMaximum number of results per request (1-100)
Position to begin retrieving results
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
Get-FalconContainerVulnerability
Search for Falcon Cloud Security container image vulnerabilities.Get-FalconContainerVulnerability
Parameters
CVE identifier
Falcon Query Language expression to limit results
Property and direction to sort results. Valid values include:
cps_current_rating.asc, cps_current_rating.desc, cve_id.asc, cve_id.desc, cvss_score.asc, cvss_score.desc, description.asc, description.desc, images_impacted.asc, images_impacted.desc, packages_impacted.asc, packages_impacted.desc, severity.asc, severity.descMaximum number of results per request
Position to begin retrieving results
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
Container Runtime
Get-FalconContainer
Search for containers in Falcon Cloud Security.Get-FalconContainer
Parameters
Falcon Query Language expression to limit results
Property and direction to sort results
Maximum number of results per request
Position to begin retrieving results
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
Get-FalconContainerSensor
Retrieve the most recent Falcon container sensor build tags.Get-FalconContainerSensor
Parameters
Create a URL using the most recent build tag