CrowdStrike Falcon Intel v2
CrowdStrike Threat intelligence service integration helps organizations defend themselves against adversary activity by investigating incidents, and accelerating alert triage and response.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- CrowdStrikeIntel
Configuration parameters
- server_url — Server URL (e.g., https://example.net) (required)
- credentials — Client ID (required)
- timeout — The amount of time (in seconds) that a request will wait for a client to establish a connection to a remote machine before a timeout occurs.
- threshold — Indicator Threshold. Minimum malicious confidence from Falcon Intel to consider the indicator malicious.
- integrationReliability — Source Reliability (required)
- feedExpirationPolicy —
- feedExpirationInterval —
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (7)
- cs-actors — Search known actors based on the given parameters.
- cs-indicators — Search known indicators based on the given parameters.
- cs-reports — Queries CrowdStrike intelligence publications.
- domain — Checks the domain reputation.
- file — Checks the file reputation.
- ip — Checks the IP reputation.
- url — Checks the URL reputation.