---
title: executable query | Wartiva GraphQL API
description: Retrieves an Executable by its graph object id: a unique executable file seen running on an endpoint. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/queries/executable.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL query

# `executable` query

Retrieves an [Executable](https://wartiva.com/api-docs/types/executable.html) by its graph object id: a unique executable file seen running on an endpoint, aggregating the peak resource use of its processes and the files and network sockets they opened. An [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) lists its current executables through `executables` and their history through `executablesSeen`; for the individual processes last reported running use [processes](https://wartiva.com/api-docs/queries/processes.html). Find executables across endpoints with [graphSearch](https://wartiva.com/api-docs/queries/graph-search.html) on the EXECUTABLE object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

## Response

Returns an [`ExecutablePayload!`](https://wartiva.com/api-docs/types/executable-payload.html)

## Arguments

| Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The Executable identifier. |
| `mockOptions` - [`MockDataInput`](https://wartiva.com/api-docs/types/mock-data-input.html) | Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |

## Example

### Query

```graphql
query executable(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  executable(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      path
      name
      cpuPercent
      memory {
        ...ProcessMemoryFragment
      }
      threads
      openFiles {
        ...OpenFileFragment
      }
      openFilesSeen {
        ...SeenOpenFileFragment
      }
      openSockets {
        ...OpenSocketFragment
      }
      openSocketsSeen {
        ...SeenOpenSocketFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

```

### Variables

```json
{
  "id": "4",
  "mockOptions": MockDataInput
}

```

### Response

```json
{"data": {"executable": {"node": Executable}}}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
