A software product as an identity shared across an organization, independent of any one computer. Every Endpoint that reports a product with the same name, compared case-insensitively, contributes to the same Application, so one Application answers "where is this product installed" across the whole fleet through its installs field. Per-endpoint install state (path, version, size, code signature, and vulnerabilities) is on ApplicationInstall; per-user, per-install configuration is on ApplicationInstallUserSettings. Applications are discovered on Windows, macOS, and Linux endpoints.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
Unique identifier for this graph object. |
orgId - OrganizationId!
|
Unique identifier for the owning organization. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A human-readable label for this object; the product name. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
seen - SeenOnline!
|
Describes when this Application was last seen on any endpoint. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
name - String!
|
Name of the product. |
publisher - String!
|
The publisher of the product, if known. |
iconUrl - String
|
A short-lived presigned URL that downloads the canonical icon bytes for this Application directly from object storage (no proxy through the API). The URL is an unauthenticated, time-limited bearer link: anyone holding it can fetch the icon until it expires, so treat it as a credential and do not persist or share it. The bytes resolve to the highest-voted ApplicationIconRef; see icons for the full voting set. For the exact icon a specific installation reported, use iconUrl on ApplicationInstall. Null when the Application has no icon. |
icons - [ApplicationIconRef!]!
|
The full voting set of icons reported for this Application across all installs. The resolver that backs iconUrl picks the highest-voted ref; this list exposes the underlying state for debugging and UI. |
installs - ApplicationInstallConnection!
|
All ApplicationInstall records for this Application across every endpoint in the organization. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
applicationquery: Retrieves an Application by its graph object id: an organization-wide software product identity that ties together every install of that product…
Used by
ApplicationInstalltype: One installed copy of an application on one Endpoint.ApplicationPayloadtype: Payload wrapper for a single Application result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
Related types
ApplicationInstallOne installed copy of an application on one Endpoint.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"seen": SeenOnline,
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"name": "xyz789",
"publisher": "abc123",
"iconUrl": "abc123",
"icons": [ApplicationIconRef],
"installs": ApplicationInstallConnection,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}