Details

This atomic belongs to the CrowdStrike atomic group.

Searches CrowdStrike for actors that are being tracked. This atomic will return the first 100 search results.

Target: CrowdStrike integration target or an HTTP Endpoint for "api.crowdstrike.com"

Account Key: None if using an integration-provided target, access token if using an HTTP Endpoint target

Steps:
[] Build the authorization header
[] If there is a query, build the query string
[] Search for matching actors
[] Check if the API request succeeded:
[]> If it did, extract the results and set the output variable
[]> If it didn't, output an error

More information about this API can be found in the CrowdStrike documentation.

About
Authorship
Cisco Managed