Retrieves an ApplicationInstall by its graph object id: one installed copy of an application on one endpoint, with its version, size, code signature, and matched CVEs. Installs are read from the Windows Uninstall registry keys, macOS application bundles, and Linux dpkg, RPM, and snap packages. An Endpoint lists its installs through applicationInstalls and their history through applicationInstallsSeenOn, and an Application through installs; find them across endpoints with graphSearch on the APPLICATION_INSTALL object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an ApplicationInstallPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The ApplicationInstall identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform |
Example
Query
query applicationInstall(
$id: ID!,
$mockOptions: MockDataInput
) {
applicationInstall(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
seen {
...SeenOnlineFragment
}
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
endpointsSeenOn {
...EndpointConnectionFragment
}
application {
...ApplicationFragment
}
userSettings {
...ApplicationInstallUserSettingsConnectionFragment
}
installDate
lastAccessedDate
lastModifiedDate
size
diskUsage
path
version
versionMajor
versionMinor
versionPatch
permissions
signature {
...ApplicationSignatureFragment
}
iconUrl
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
vulnerabilities {
...PlatformVulnerabilitiesFragment
}
}
}
}
Variables
{"id": 4, "mockOptions": MockDataInput}
Response
{
"data": {
"applicationInstall": {"node": ApplicationInstall}
}
}