Endpoint configuration · GraphQL query

security query

Retrieves an endpoint's Security posture by its graph object id: firewall, antivirus, and antispyware products, Windows Firewall profiles, Linux nftables rules, and per-volume disk encryption, each summarized as a health rating. Each Endpoint on Windows, macOS, or Linux has at most one, also reachable through its security field; find them across endpoints with graphSearch on the SECURITY object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns a SecurityPayload!

Arguments

Name Description
id - ID! The Security identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query security(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  security(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      firewallProducts {
        ...FirewallFragment
      }
      firewallPrivateProfile {
        ...FirewallPrivateProfileFragment
      }
      firewallPublicProfile {
        ...FirewallPublicProfileFragment
      }
      antivirusProducts {
        ...AntivirusFragment
      }
      antispywareProducts {
        ...AntispywareFragment
      }
      health {
        ...HealthFragment
      }
      tables {
        ...TableFragment
      }
      diskEncryption {
        ...DiskEncryptionFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{"id": 4, "mockOptions": MockDataInput}

Response

{"data": {"security": {"node": Security}}}