category: Endpoint provider: CrowdStrike sectionorder: - Connect - Collect commonfields: id: CrowdstrikeFalcon version: -1 configuration: - defaultvalue: 'false' display: Use legacy API name: legacy_version type: 8 section: Connect advanced: true hidden: true additionalinfo: "Use the legacy version of the API, which refers to versions prior to the 'Next Generation Raptor release.'" - display: Server URL (e.g., https://api.crowdstrike.com) name: url type: 0 section: Connect required: true defaultvalue: https://api.crowdstrike.com - display: Client ID name: credentials type: 9 section: Connect required: false displaypassword: Secret - display: Client ID name: client_id type: 0 hidden: true section: Connect required: false - display: Secret name: secret type: 4 section: Connect required: false hidden: true - display: Source Reliability name: Reliability type: 15 defaultvalue: 'A+ - 3rd party enrichment' section: Collect required: false additionalinfo: Reliability of the source providing the intelligence data. Currently used for “CVE” reputation command. options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged advanced: true - display: Fetch incidents name: isFetch type: 8 section: Collect required: false defaultvalue: 'false' hidden: - marketplacev2 supportedModules: - "xsiam" - "agentix" - display: 'Incident Fetch types' defaultvalue: 'Endpoint Detection' name: fetch_incidents_or_detections type: 16 section: Collect required: false additionalinfo: |- Choose what incident types to fetch - You can choose any combination. Note: Records from the detection endpoint of the CrowdStrike Falcon UI could be of types: 'Endpoint Detection' and 'OFP Detection'. options: - IDP Detection - Endpoint Detection - Indicator of Misconfiguration - Indicator of Attack - Mobile Detection - On-Demand Scans Detection - OFP Detection - Third Party Detection - NGSIEM Detection - NGSIEM Automated Lead - NGSIEM Case - NGSIEM Incident (XDR Alert) - Recon notifications hidden: - marketplacev2 supportedModules: - "xsiam" - "agentix" - display: Incident type name: incidentType type: 13 section: Connect required: false hidden: - marketplacev2 supportedModules: - "xsiam" - "agentix" - display: First fetch timestamp (