CrowdStrike Falcon - Get Detections by Case
This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook enables getting CrowdStrike Falcon detection (alerts) details based on the CrowdStrike case ID.
- Pack
- CrowdStrikeFalcon
- Tasks
- 7
Inputs
- CaseID — The ID of the CrowdStrike Case.
Outputs
- CrowdStrike.Detection.Behavior — CrowdStrike Detection Details.
- CrowdStrike.Detection.Device — CrowdStrike Detection Device Details.
- CrowdStrike.FoundDetections — Indicates whether detections were found.
Commands used
- cs-falcon-get-evidence-for-case
- cs-falcon-search-detection