CrowdStrike DeleteIOC

CrowdStrike DeleteIOC

Certified
Enterprise Edition

Delete a CrowdStrike Falcon custom indicator of compromise

Deletes a custom IOC either by iocId, or in bulk by FQL filter. Exactly one of iocId or filter must be set.

yaml
type: io.kestra.plugin.ee.crowdstrike.ioc.DeleteIOC

Delete a single indicator by ID

yaml
id: delete_ioc
namespace: company.team

tasks:
  - id: delete_ioc
    type: io.kestra.plugin.ee.crowdstrike.ioc.DeleteIOC
    clientId: "{{ secret('CROWDSTRIKE_CLIENT_ID') }}"
    clientSecret: "{{ secret('CROWDSTRIKE_CLIENT_SECRET') }}"
    iocId: "4f8b9c1a2d3e4f5061728394a5b6c7d"
Properties

API client ID

Client ID of a CrowdStrike API client with the scopes required by the tasks and triggers being used.

API client secret

Client secret of the CrowdStrike API client. Exchanged for a short-lived OAuth2 Bearer token on every task run and trigger poll; never logged.

Defaulthttps://api.crowdstrike.com

CrowdStrike API base URL

Base URL of the CrowdStrike Falcon API for your cloud region (for example: https://api.crowdstrike.com for US-1, https://api.us-2.crowdstrike.com for US-2, https://api.eu-1.crowdstrike.com for EU-1, or https://api.laggar.gcw.crowdstrike.com for US-GOV-1). Defaults to the US-1 endpoint. Using the wrong region for your tenant results in 403 Forbidden responses.

FQL filter

CrowdStrike Falcon Query Language expression selecting the IOCs to delete in bulk. Mutually exclusive with iocId.

IOC ID

ID of a single custom IOC to delete. Mutually exclusive with filter.

Number of IOCs deleted