Skip to main content
Security / SIEM

CrowdStrike Falcon

Falcon EDR detections become security-classified incidents, and Falcon-managed devices enrich CMDB CIs. Real-Time Response host isolation is declared on the roadmap but is not available in this release.

InboundData residency: US
Request a demo

What it does

  • Detection events → incident, with Falcon's 0–100 severity mapped to platform severity and a tenant-configurable floor for auto-opening a ticket (default 30)
  • Detection disposition drives the security classification: a confirmed true positive is at least confirmed_threat (breach at the top of the severity band)
  • Falcon-managed devices enrich CMDB CIs (or create a Workstation CI when the endpoint isn't already managed by Intune)
  • Signed inbound webhook plus a 5-minute poll fallback
  • RTR host-isolate / lift-containment is declared in the manifest for the health page's roadmap view. It is gated, not executable: every attempt is rejected in this release, deferred to a future release behind per-action consent and a dedicated permission
  • SentinelOne detections can be normalized through this same adapter shape via a config flag — not a separately branded integration

Data residency

Defaults to US (Falcon US-1/US-2/GovCloud). Pinning the Falcon EU-1 cloud in config resolves the integration to EU residency instead — the only per-tenant lever that changes it.

Event mappings

External eventMaps toWhat happens
DetectionSummaryEventincidentA Falcon EDR detection becomes a security-classified incident
EppDetectionSummaryEventincidentNext-gen Falcon EPP detection summary; same incident mapping
deviceciFalcon-managed device → CMDB CI enrichment (or a Workstation CI)

What you configure

  • Falcon cloud region (US-1, US-2, EU-1, or GovCloud) — selects both the API endpoint and data residency
  • OAuth client ID
  • Client secret (stored as a secret)
  • Webhook signing secret (only if using the signed inbound path)
  • SentinelOne mode toggle
  • Minimum severity to auto-open an incident (default 30 of 100)

OAuth scopes requested

  • detects:read
  • devices:read
  • incidents:read

Setup overview

Register an OAuth2 API client scoped to detects:read, devices:read, incidents:read. Pick your Falcon cloud region — EU-1 if you need EU residency — and store the client secret. Host isolation is not available in this release.

Related features

See TENSOR running on your own estate.

30 minutes, screen-shared, no slides. Bring the process you are least sure we handle and we will start there.