Policy Management
Get-FalconFileVantagePolicy
Search for FileVantage policies.Parameters
FileVantage policy identifier(s)
Operating system type:
Linux, Mac, WindowsProperty and direction to sort resultsOptions:
created_timestamp|asc, created_timestamp|desc, modified_timestamp|asc, modified_timestamp|desc, precedence|asc, precedence|descMaximum number of results per request (1-500)
Include additional properties:
exclusionsPosition to begin retrieving results
Retrieve detailed information
Repeat requests until all available results are retrieved
Display total result count instead of results
New-FalconFileVantagePolicy
Create FileVantage policies.Parameters
Policy name (1-100 characters)
Operating system platform:
Linux, Mac, WindowsPolicy description (0-500 characters)
Edit-FalconFileVantagePolicy
Modify FileVantage policies.Parameters
FileVantage policy identifier
Policy name (1-100 characters)
Policy enablement status
Policy description (0-500 characters)
Rule Group Management
Get-FalconFileVantageRuleGroup
Search for FileVantage rule groups.Parameters
FileVantage rule group identifier(s)
Rule group type:
LinuxFiles, MacFiles, WindowsFiles, WindowsRegistryProperty and direction to sort results
Maximum number of results per request (1-500)
New-FalconFileVantageRuleGroup
Create FileVantage rule groups.Parameters
Rule group type:
LinuxFiles, MacFiles, WindowsFiles, WindowsRegistryRule group name (1-100 characters)
Rule group description (0-500 characters)
Edit-FalconFileVantageRuleGroup
Modify FileVantage rule groups.Rule Management
Get-FalconFileVantageRule
List FileVantage rules within a rule group.Parameters
FileVantage rule group identifier
FileVantage rule identifier(s)
New-FalconFileVantageRule
Create a rule within a FileVantage rule group.Parameters
FileVantage rule group identifier
Precedence for the new rule inside the rule group
Path of the directory, file, or registry key to monitor (1-250 characters)
Monitoring depth:
1, 2, 3, 4, 5, ANYRule severity:
Low, Medium, High, CriticalRule description (0-500 characters)
Files/directories to monitor (glob patterns, comma-separated)
Files/directories to exclude (glob patterns, comma-separated)
Track file write events
Track file delete events
Track file permission change events
Track file rename events
Track directory create events
Track directory delete events
Enable the capture of file content during events
Track file hash
Edit-FalconFileVantageRule
Modify a rule within a FileVantage rule group.Change Monitoring
Get-FalconFileVantageChange
Search for Falcon FileVantage changes.Parameters
FileVantage change identifier(s)
Falcon Query Language expression to limit results
Property and direction to sort resultsOptions:
action_timestamp|asc, action_timestamp|desc, ingestion_timestamp|asc, ingestion_timestamp|descMaximum number of results per request (1-5000)
Pagination token to retrieve the next set of results
Retrieve detailed information
Repeat requests until all available results are retrieved
Get-FalconFileVantageContent
Retrieve content recorded in a Falcon FileVantage change.Parameters
FileVantage change identifier
Invoke-FalconFileVantageAction
Perform actions on Falcon FileVantage changes.Parameters
Action to perform:
suppress, unsuppress, purgeAudit log comment
FileVantage change identifier(s)
Use Cases
Monitor Critical System Files
Review Recent File Changes
Investigate Suspicious Changes
Requires Falcon FileVantage: Read scope for read operations and Falcon FileVantage: Write scope for modifications. Content retrieval requires Falcon FileVantage Content: Read scope.