Skip to content

Real Time Response

Initiating and inspecting RTR sessions and for executing read-only RTR commands during host investigations

  • Real time response:read
  • Real time response:write

Required scopes: Real time response:read

Get the status and output chunk for an RTR command.

Required scopes: Real time response:read

Delete an RTR session.

Required scopes: Real time response:read

Execute a read-only RTR command on a single host.

This tool is intentionally limited to the read-only RTR endpoint for hunt and triage workflows. It does not expose admin or remediation command APIs.

Required scopes: Real time response:read

Retrieve detailed metadata for one or more RTR sessions.

Required scopes: Real time response:read

Initialize or reuse an RTR session for a single host.

Required scopes: Real time response:write

List files currently associated with an RTR session.

Required scopes: Real time response:read

Refresh an RTR session timeout for a single host.

Required scopes: Real time response:read

Search RTR sessions and return full session details.

  • falcon://rtr/sessions/search/fql-guide: Contains the guide for the filter param of the falcon_search_rtr_sessions tool.