Join us as we sit down with Doug Cahill and talk about Cybersecurity Integrations: The ROI Black Hole

PARTNER

CrowdStrike Falcon® Insight EDR

CrowdStrike | EDR

CrowdStrike is a leading cybersecurity company offering cloud-native endpoint protection, threat intelligence, identity security, and extended detection and response (XDR) capabilities through its Falcon platform.

Vendors looking to integrate CrowdStrike into their security products can use Synqly's normalized connector to access endpoint telemetry, detections, and threat data from the Falcon platform. Integrate CrowdStrike to power detection, response, and asset workflows without per-product API development.

Configuration for CrowdStrike Falcon® Insight EDR.

[Configuration guide](https://docs.synqly.com/guides/provider-configuration/crowdstrike-edr-setup)

Integration Use Cases

gpp_maybe

Create IOCs

Creates a list of iocs that match the stix input for the EDR source.

list_alt_check

Delete IOCs

Deletes a list of iocs that match the input of ids in the query param

computer

Get Endpoint

Gets a single endpoint assets matching the UID from the token-linked EDR source.

remove_from_queue

Quarantine Endpoints

Connect or disconnect one or more endpoints assets to the network, allowing or disallowing connections.

notifications_active

Query Alerts

Returns a list of alerts that match the query from the token-linked EDR source.

database_search

Query Applications

Returns a list of applications matching the query from the token-linked EDR source.

event_list

Query EDR Events

Returns a list of EDR events that match the query from the token-linked EDR source.

devices

Query Endpoints

Returns a list of endpoint assets matching the query from the token-linked EDR source.

gpp_maybe

Query IOCs

Returns a list of iocs that match the query from the token-linked EDR source.

grading

Query Posture Score

Returns the posture score of the endpoint assets that match the query from the token-linked EDR source.

event_list

Query Threat Events

Returns a list of threats that match the query from the token-linked EDR source.

Integration Resources