CrowdStrike is a leading cybersecurity company offering cloud-native endpoint protection, threat intelligence, identity security, and extended detection and response (XDR) capabilities through its Falcon platform.
Vendors looking to integrate CrowdStrike into their security products can use Synqly's normalized connector to access endpoint telemetry, detections, and threat data from the Falcon platform. Integrate CrowdStrike to power detection, response, and asset workflows without per-product API development.
Configuration for CrowdStrike Falcon® Insight EDR.
[Configuration guide](https://docs.synqly.com/guides/provider-configuration/crowdstrike-edr-setup)
Integration Use Cases
Create IOCs
Creates a list of iocs that match the stix input for the EDR source.
Delete IOCs
Deletes a list of iocs that match the input of ids in the query param
Get Endpoint
Gets a single endpoint assets matching the UID from the token-linked EDR source.
Quarantine Endpoints
Connect or disconnect one or more endpoints assets to the network, allowing or disallowing connections.
Query Alerts
Returns a list of alerts that match the query from the token-linked EDR source.
Query Applications
Returns a list of applications matching the query from the token-linked EDR source.
Query EDR Events
Returns a list of EDR events that match the query from the token-linked EDR source.
Query Endpoints
Returns a list of endpoint assets matching the query from the token-linked EDR source.
Query IOCs
Returns a list of iocs that match the query from the token-linked EDR source.
Query Posture Score
Returns the posture score of the endpoint assets that match the query from the token-linked EDR source.
Query Threat Events
Returns a list of threats that match the query from the token-linked EDR source.