CrowdStrike Falcon
What is CrowdStrike Falcon?
CrowdStrike Falcon is a cloud-native cybersecurity platform offering endpoint protection, threat intelligence, and immediate response capabilities. By integrating CrowdStrike Falcon with Konnectify, security operations teams can orchestrate incident response, automate host containment, manage host groups, and streamline alert handling without manual intervention.
New to CrowdStrike Falcon?
Set up cloud-delivered endpoint security, threat intelligence, and response controls.
Visit CrowdStrike →New to Konnectify?
Create your free account to build automated security workflows and threat response pipelines.
Sign up free →What you can automate:
- Instantly trigger incident response workflows when a new Falcon alert is generated.
- Isolate compromised endpoints by initiating network containment immediately during critical events.
- Orchestrate on-demand and scheduled vulnerability scans across specific host groups.
- Dynamically manage host group membership based on asset discovery or compliance status.
- Synchronize prevention policies with host groups to ensure consistent security baselines.
- Retrieve real-time sensor details and installation packages for deployment auditing.
API & Authentication
Secure Client Credentials Connection
CrowdStrike Falcon uses API Client Credentials (OAuth 2.0) to establish a secure, authenticated connection with Konnectify. You will generate a Client ID and Client Secret within your Falcon Console, which grants scoped access to specific Falcon APIs without sharing master login credentials. Additionally, you must specify your regional CrowdStrike Cloud environment (e.g., US-1, US-2, EU-1, or US-GOV-1) to route API requests correctly.
Ensure your Falcon API Client has read and write permissions enabled for: Alerts, Devices, Host groups, Prevention policies, and On-demand scans in the CrowdStrike Console. Missing scopes will cause corresponding actions to fail.
For detailed instructions, refer to the official CrowdStrike Developer Documentation.
How to Connect
You need a CrowdStrike Falcon account with Administrator permissions to generate API Clients, your regional Cloud environment name, your Client ID, and your Client Secret.
Add CrowdStrike Falcon to a Workflow
- Log in to your Konnectify workspace and open or create a workflow.
- Search for and select CrowdStrike Falcon from the app directory.
Authorize via Client Credentials
- Select your CrowdStrike Cloud environment (e.g., US-1, US-2, EU-1, US-GOV-1) from the dropdown.
- Enter your generated Falcon API Client ID and Client Secret.
- If you are an MSSP managing multiple tenants, enter the optional Member CID; otherwise, leave it blank.
- Click Connect to authorize the API connection securely.
Configure the Trigger or Action
- Select your desired trigger or action from the available options.
- Map the required input fields (such as Host AIDs, Host Group IDs, or Scan IDs) using variables from previous steps.
Configuration Alert: Double-check that the host group IDs and host AIDs mapped from previous steps match the target environment structure exactly to prevent execution errors.
Test the Workflow
- Click Test Step to send a sample payload through the integration.
- Verify the test results in the output console to ensure data is structured and mapped correctly.
Activate the Workflow
- Once tested successfully, toggle the workflow status to Active.
- Your automated security processes will now run automatically in the background.
Triggers 1
Triggers monitor your CrowdStrike Falcon environment for specific events. This integration uses polling to check for updates periodically and instantly pass new data into your workflow.
Actions 17
Actions are operations that Konnectify can execute inside CrowdStrike Falcon. Use these actions to automate response tasks, query endpoints, and enforce security policies.
Popular Automations
Isolate Compromised Endpoints on High Severity Alerts
Automatically request network containment in Falcon the moment a high-severity alert is detected to prevent lateral movement.
Sync Threat Alerts to IT Ticketing Systems
Fetch complete device records for any host triggering an alert, then route the enriched detail to your internal ticketing system.
Automate On-Demand Scans for Newly Grouped Hosts
When an asset is added to a high-risk host group, immediately initiate an on-demand Falcon scan to audit its security state.
Deploy and Audit Prevention Policies
Automatically update policy assignments for host groups when compliance requirements change, and verify the settings.
Frequently Asked Questions
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article