{"id":"1ed25524-fda6-4927-b37a-2e7fc57ff53c","task":"Query CrowdStrike Falcon Spotlight for vulnerability exposure data via the API","domain":"developer.crowdstrike.com","steps":["Create an OAuth2 API client scoped for Spotlight vulnerabilities (read) in the Falcon console and obtain a bearer token from the token endpoint.","Use the vulnerabilities search operation with an FQL filter (e.g. filtering by cve.id, severity, or host status) to page through matching vulnerability entities.","Retrieve full vulnerability details, including CVE metadata and exploit/priority rating, for specific vulnerability IDs.","Call the remediation details operation with remediation IDs referenced on vulnerabilities to get patch or configuration guidance.","Paginate using the API's continuation-token pattern for large environments rather than offset-based paging to avoid missing results as data changes."],"gotchas":["FQL filter syntax is CrowdStrike-specific and case-sensitive on field names; a malformed filter can silently return zero results rather than an explicit error.","Spotlight data reflects the last completed sensor-based assessment per host, so freshly onboarded or offline hosts can show incomplete vulnerability data."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/1ed25524-fda6-4927-b37a-2e7fc57ff53c"}