-
Notifications
You must be signed in to change notification settings - Fork 54
Detections
Joshua Hiller edited this page May 15, 2026
·
3 revisions
Find and analyze detections to understand malicious activity in your environment.
Alerts: READ
Required scopes: Alerts: READ
Retrieve details for detection IDs you already have.
Use ONLY when you have specific composite detection ID(s). To find detections
by criteria (severity, status, hostname, etc.), use falcon_search_detections.
Example prompts:
- "Get me the details for this detection"
Required scopes: Alerts: READ
Find detections by criteria and return their complete details.
Use this tool to discover detections - filter by severity, status, hostname, time range, etc. Returns full detection information including behaviors, device context, and threat details.
Example prompts:
- "Show me new high severity detections from the last 7 days"
- "Find all unassigned critical detections"
-
falcon://detections/search/fql-guide: Contains the guide for thefilterparam of thefalcon_search_detectionstool.
