CrowdStrike

**Important**

This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace).

CrowdStrike Falcon is a leading Endpoint Protection Platform (EPP) that helps organizations quickly detect, analyze, block, and contain malicious attacks on enterprise endpoints and servers. It provides real-time response, vulnerability assessment, and host containment, along with a CrowdStrike Falcon Intel threat intelligence feed to help organizations defend against adversary activity.

This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):

* [CrowdStrike Falcon Intel v2](https://xsoar.pan.dev/docs/reference/integrations/crowd-strike-falcon-intel-v2): CrowdStrike Threat intelligence service integration helps organizations defend themselves against adversary activity by investigating incidents, and accelerating alert triage and response. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CrowdstrikeFalcon](https://xsoar.pan.dev/docs/reference/integrations/crowdstrike-falcon): The CrowdStrike Falcon OAuth 2 API (formerly the Falcon Firehose API), enables fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.

To configure this connector, follow the steps outlined in the configuration wizard.