Black Hat 2026: Book a meeting and enter to win $1k for a Kid's Team, Club, or Program.

PARTNER

CrowdStrike Falcon® Insight EDR

CrowdStrike | EDR

About CrowdStrike

CrowdStrike is a global cybersecurity leader and pioneer of cloud-native endpoint protection, widely regarded as one of the most trusted names in threat intelligence, endpoint detection and response, and adversary-focused security operations. With its AI-powered platform and elite Falcon Intelligence capabilities, CrowdStrike is a foundational security partner for enterprises defending against nation-state actors and sophisticated cybercriminal groups. Teams looking to integrate with CrowdStrike or build a CrowdStrike integration can use Synqly to access normalized endpoint detection, threat intelligence, and incident data through a standardized security connector.

About the CrowdStrike Falcon® Insight EDR Integration

CrowdStrike Falcon® Insight EDR is CrowdStrike’s cloud-native endpoint detection and response solution, combining real-time threat prevention, behavioral AI, and automated response across enterprise endpoints. As Synqly’s Sink provider, Falcon Insight EDR enables security platforms to stream security event data and telemetry from Synqly-connected tools into CrowdStrike’s Falcon platform for unified threat analysis. Integrate with CrowdStrike Falcon Insight EDR to route security events from your connected tools into the Falcon ecosystem, enabling correlation with endpoint telemetry and enriched threat investigation.

Integration Use Cases

gpp_maybe

Create IOCs

Creates a list of iocs that match the stix input for the EDR source.

edit_note

Create Threat Note

Creates a note for a threat.

list_alt_check

Delete IOCs

Deletes a list of iocs that match the input of ids in the query param

terminal

Execute Command

Runs a provider-backed command on the endpoint identified by `{uid}` and returns normalized stdout and stderr without exposing provider session details.

computer

Get Endpoint

Gets a single endpoint assets matching the UID from the token-linked EDR source.

note_stack

Get Threat Notes

Returns a list of notes for a threat.

remove_from_queue

Quarantine Endpoints

Connect or disconnect one or more endpoints assets to the network, allowing or disallowing connections.

notifications_active

Query Alerts

Returns a list of alerts that match the query from the token-linked EDR source.

database_search

Query Applications

Returns a list of applications matching the query from the token-linked EDR source.

event_list

Query EDR Events

Returns a list of EDR events that match the query from the token-linked EDR source.

devices

Query Endpoints

Returns a list of endpoint assets matching the query from the token-linked EDR source.

gpp_maybe

Query IOCs

Returns a list of iocs that match the query from the token-linked EDR source.

grading

Query Posture Score

Returns the posture score of the endpoint assets that match the query from the token-linked EDR source.

event_list

Query Threat Events

Returns a list of threats that match the query from the token-linked EDR source.

file_download

Retrieve File

Retrieves a file from the endpoint identified by `{uid}` and returns the provider artifact as a binary file response.

Integration Resources

  • Platform
  • Integrations
  • Resources
  • About
  • Blog