Applications and updates · GraphQL query

applicationInstall query

Retrieves an ApplicationInstall by its graph object id: one installed copy of an application on one endpoint, with its version, size, code signature, and matched CVEs. Installs are read from the Windows Uninstall registry keys, macOS application bundles, and Linux dpkg, RPM, and snap packages. An Endpoint lists its installs through applicationInstalls and their history through applicationInstallsSeenOn, and an Application through installs; find them across endpoints with graphSearch on the APPLICATION_INSTALL object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns an ApplicationInstallPayload!

Arguments

Name Description
id - ID! The ApplicationInstall identifier.
mockOptions - MockDataInput Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

Example

Query

query applicationInstall(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  applicationInstall(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      seen {
        ...SeenOnlineFragment
      }
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      endpointsSeenOn {
        ...EndpointConnectionFragment
      }
      application {
        ...ApplicationFragment
      }
      userSettings {
        ...ApplicationInstallUserSettingsConnectionFragment
      }
      installDate
      lastAccessedDate
      lastModifiedDate
      size
      diskUsage
      path
      version
      versionMajor
      versionMinor
      versionPatch
      permissions
      signature {
        ...ApplicationSignatureFragment
      }
      iconUrl
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
      vulnerabilities {
        ...PlatformVulnerabilitiesFragment
      }
    }
  }
}

Variables

{"id": 4, "mockOptions": MockDataInput}

Response

{
  "data": {
    "applicationInstall": {"node": ApplicationInstall}
  }
}