Applications and updates · GraphQL type

Application type

A software product as an identity shared across an organization, independent of any one computer. Every Endpoint that reports a product with the same name, compared case-insensitively, contributes to the same Application, so one Application answers "where is this product installed" across the whole fleet through its installs field. Per-endpoint install state (path, version, size, code signature, and vulnerabilities) is on ApplicationInstall; per-user, per-install configuration is on ApplicationInstallUserSettings. Applications are discovered on Windows, macOS, and Linux endpoints.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A human-readable label for this object; the product name.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! Describes when this Application was last seen on any endpoint.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
name - String! Name of the product.
publisher - String! The publisher of the product, if known.
iconUrl - String A short-lived presigned URL that downloads the canonical icon bytes for this Application directly from object storage (no proxy through the API). The URL is an unauthenticated, time-limited bearer link: anyone holding it can fetch the icon until it expires, so treat it as a credential and do not persist or share it. The bytes resolve to the highest-voted ApplicationIconRef; see icons for the full voting set. For the exact icon a specific installation reported, use iconUrl on ApplicationInstall. Null when the Application has no icon.
icons - [ApplicationIconRef!]! The full voting set of icons reported for this Application across all installs. The resolver that backs iconUrl picks the highest-voted ref; this list exposes the underlying state for debugging and UI.
installs - ApplicationInstallConnection! All ApplicationInstall records for this Application across every endpoint in the organization.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • application query: Retrieves an Application by its graph object id: an organization-wide software product identity that ties together every install of that product…

Used by

Related types

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "name": "xyz789",
  "publisher": "abc123",
  "iconUrl": "abc123",
  "icons": [ApplicationIconRef],
  "installs": ApplicationInstallConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}