Security / SIEM
CrowdStrike Falcon
Falcon EDR detections become security-classified incidents, and Falcon-managed devices enrich CMDB CIs. Real-Time Response host isolation is declared on the roadmap but is not available in this release.
InboundData residency: US
Request a demoWhat it does
- Detection events → incident, with Falcon's 0–100 severity mapped to platform severity and a tenant-configurable floor for auto-opening a ticket (default 30)
- Detection disposition drives the security classification: a confirmed true positive is at least confirmed_threat (breach at the top of the severity band)
- Falcon-managed devices enrich CMDB CIs (or create a Workstation CI when the endpoint isn't already managed by Intune)
- Signed inbound webhook plus a 5-minute poll fallback
- RTR host-isolate / lift-containment is declared in the manifest for the health page's roadmap view. It is gated, not executable: every attempt is rejected in this release, deferred to a future release behind per-action consent and a dedicated permission
- SentinelOne detections can be normalized through this same adapter shape via a config flag — not a separately branded integration
Data residency
Defaults to US (Falcon US-1/US-2/GovCloud). Pinning the Falcon EU-1 cloud in config resolves the integration to EU residency instead — the only per-tenant lever that changes it.
Event mappings
| External event | Maps to | What happens |
|---|---|---|
| DetectionSummaryEvent | incident | A Falcon EDR detection becomes a security-classified incident |
| EppDetectionSummaryEvent | incident | Next-gen Falcon EPP detection summary; same incident mapping |
| device | ci | Falcon-managed device → CMDB CI enrichment (or a Workstation CI) |
What you configure
- Falcon cloud region (US-1, US-2, EU-1, or GovCloud) — selects both the API endpoint and data residency
- OAuth client ID
- Client secret (stored as a secret)
- Webhook signing secret (only if using the signed inbound path)
- SentinelOne mode toggle
- Minimum severity to auto-open an incident (default 30 of 100)
OAuth scopes requested
- detects:read
- devices:read
- incidents:read
Setup overview
Register an OAuth2 API client scoped to detects:read, devices:read, incidents:read. Pick your Falcon cloud region — EU-1 if you need EU residency — and store the client secret. Host isolation is not available in this release.
Related features
See TENSOR running on your own estate.
30 minutes, screen-shared, no slides. Bring the process you are least sure we handle and we will start there.