CrowdStrike Falcon (v2.12.9)

The CrowdStrike Falcon OAuth 2 API (formerly the Falcon Firehose API), enables fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Endpoint

Incident fields (61)

Integrations (1)

Layouts (1)

Playbooks (15)

Scripts (12)

README

Endpoint security is at the frontline to protect against malicious cybersecurity threats. It represents one of the first places organizations look to secure their enterprise networks.
As the volume and sophistication of cybersecurity threats have increased, so has the need for more advanced endpoint security solutions.
CrowdStrike Falcon is one of the leaders in the Endpoint Protection Platform (EPP) market, and the CrowdStrike Falcon content pack provides a holistic solution for protecting enterprise endpoints and servers from malicious attacks that can seriously impact your organization.
This pack is designed to quickly detect, analyze, block, and contain malicious attacks in progress. It also gives administrators visibility into advanced threats to speed detection and remediation response times.

What Does This Pack Do?

<~XSOAR>

<~XSOAR>

Before You Start

Make sure you have the following content packs:

Pack Configurations

To get up and running with this pack, you must get an API client ID and secret from CrowdStrike support.