Applications and updates · GraphQL type

ApplicationInstall type

One installed copy of an application on one Endpoint. The install path is part of its identity, so a product installed in two locations on the same computer yields two ApplicationInstall objects. The agent reads the registry uninstall keys on Windows, application bundles in the system and per-user Applications folders on macOS, and the dpkg or RPM package database plus snap packages on Linux. Where the platform reports them, each install carries its version, install and access dates, installer-reported and measured size, code-signature verification result, and the CPE and CVE matches in vulnerabilities. The abstract product identity lives on Application; the per-user, per-install configuration lives on ApplicationInstallUserSettings.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A human-readable label for this object; the install path.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! When this ApplicationInstall was last observed on the endpoint.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this Application is installed on.
endpointsSeenOn - EndpointConnection! Historical sightings of this ApplicationInstall on Endpoints. Each edge records when the install was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Restrict edges to a date/time range.

includeSeen - Boolean

Include the per-edge seen series in the response.

application - Application The Application software identity this install installs.
userSettings - ApplicationInstallUserSettingsConnection! All ApplicationInstallUserSettings records that configure this install.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

installDate - Time Date the application was installed, if available.
lastAccessedDate - Time Date the application was last accessed.
lastModifiedDate - Time Date the application was last modified.
size - Int64! The installer-reported size of the application in bytes.
diskUsage - Int64 The measured disk-usage of the install directory in bytes, as last computed by the paced background disk-usage walk. Null if the walk hasn't completed yet for this install.
path - String! Filesystem path of the install root.
version - String! Version of the installed application, if available.
versionMajor - Int! Major version number.
versionMinor - Int! Minor version number.
versionPatch - Int! Patch version number.
permissions - String File permissions of the install root formatted as a Unix mode string (e.g. "-rwxr-xr-x").
signature - ApplicationSignature Code-signing state of this install as verified on the endpoint. Null when the endpoint has not reported a signature verification result for this install. See ApplicationSignature.
iconUrl - String A short-lived presigned URL that downloads the PNG icon most recently reported by this particular installation, directly from object storage (no proxy through the API). The icon is stored per install and always reflects the last icon processed for this install path — it is independent of the canonical icon elected across all installs on Application. The URL is an unauthenticated, time-limited bearer link: anyone holding it can fetch the icon until it expires, so treat it as a credential and do not persist or share it. Null when this install has never reported an icon.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.
vulnerabilities - PlatformVulnerabilities CPE identifiers determined for this installed application and the CVEs they match in the vulnerability catalog. Null when the install could not be identified precisely enough to match vulnerabilities accurately. See PlatformVulnerabilities.

Returned by

  • applicationInstall query: Retrieves an ApplicationInstall by its graph object id: one installed copy of an application on one endpoint, with its version, size, code…

Used by

  • Application type: A software product as an identity shared across an organization, independent of any one computer.
  • ApplicationInstallUserSettings type: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • ApplicationInstallConnection type: Collection payload for ApplicationInstall edges with total count.
  • ApplicationInstallEdge type: Edge payload for an ApplicationInstall with optional seen data.
  • ApplicationInstallPayload type: Payload wrapper for a single ApplicationInstall result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.

Related types

  • Application A software product as an identity shared across an organization, independent of any one computer.
  • ApplicationInstallUserSettings The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "endpointsSeenOn": EndpointConnection,
  "application": Application,
  "userSettings": ApplicationInstallUserSettingsConnection,
  "installDate": "2021-10-07T18:23:25.829Z",
  "lastAccessedDate": "2021-10-07T18:23:25.829Z",
  "lastModifiedDate": "2021-10-07T18:23:25.829Z",
  "size": "-8589934592",
  "diskUsage": "-8589934592",
  "path": "abc123",
  "version": "abc123",
  "versionMajor": 987,
  "versionMinor": 987,
  "versionPatch": 987,
  "permissions": "xyz789",
  "signature": ApplicationSignature,
  "iconUrl": "abc123",
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary,
  "vulnerabilities": PlatformVulnerabilities
}