Endpoint configuration · GraphQL query

executable query

Retrieves an Executable by its graph object id: a unique executable file seen running on an endpoint, aggregating the peak resource use of its processes and the files and network sockets they opened. An Endpoint lists its current executables through executables and their history through executablesSeen; for the individual processes last reported running use processes. Find executables across endpoints with graphSearch on the EXECUTABLE object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns an ExecutablePayload!

Arguments

Name Description
id - ID! The Executable identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query executable(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  executable(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      path
      name
      cpuPercent
      memory {
        ...ProcessMemoryFragment
      }
      threads
      openFiles {
        ...OpenFileFragment
      }
      openFilesSeen {
        ...SeenOpenFileFragment
      }
      openSockets {
        ...OpenSocketFragment
      }
      openSocketsSeen {
        ...SeenOpenSocketFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"executable": {"node": Executable}}}