Skip to content

crowdstrikeCaseActivitySummary

Compact case-level actor summary across the alerts that compose a CrowdStrike incident.

Arguments

Argument Type Description
detectionIds (required) [String!]! CrowdStrike detection IDs composing the case.

Returns

CrowdstrikeCaseActivitySummary

Sample

query CrowdstrikeCaseActivitySummary($detectionIds: [String!]!) {
  crowdstrikeCaseActivitySummary(detectionIds: $detectionIds) {
    impactedIdentityProviders
    latestActionTime
    recoveryUrl
    totalActors
    totalRelatedActions
    totalTargetEntities
    totalViolations
  }
}
{
  "detectionIds": [
    "example-string"
  ]
}
{
  "data": {
    "crowdstrikeCaseActivitySummary": {
      "impactedIdentityProviders": [
        "example-string"
      ],
      "latestActionTime": "2024-01-01T00:00:00.000Z",
      "recoveryUrl": "example-string",
      "totalActors": 0,
      "totalRelatedActions": 0,
      "totalTargetEntities": 0
    }
  }
}