Retrieves an Executable by its graph object id: a unique executable file seen running on an endpoint, aggregating the peak resource use of its processes and the files and network sockets they opened. An Endpoint lists its current executables through executables and their history through executablesSeen; for the individual processes last reported running use processes. Find executables across endpoints with graphSearch on the EXECUTABLE object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an ExecutablePayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The Executable identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query executable(
$id: ID!,
$mockOptions: MockDataInput
) {
executable(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
path
name
cpuPercent
memory {
...ProcessMemoryFragment
}
threads
openFiles {
...OpenFileFragment
}
openFilesSeen {
...SeenOpenFileFragment
}
openSockets {
...OpenSocketFragment
}
openSocketsSeen {
...SeenOpenSocketFragment
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"executable": {"node": Executable}}}