CrowdStrike Falcon

Identity & securityClient credentials

Investigate and respond in CrowdStrike Falcon: search hosts, contain them, triage alerts, find vulnerabilities and manage IOCs.

13 actions

ActionEffectData handledScope
crowdstrike_search_hostsSearches hosts by FQL filter (hostname, platform, IP, status and more) and returns full host recordsreadPersonal data
crowdstrike_get_hostsReturns host details for up to 100 host (agent) idsreadPersonal data
crowdstrike_get_host_online_stateReturns whether each host is online, offline or unknownreadGeneral
crowdstrike_perform_host_actionNetwork-contains a host or lifts containment, or hides or unhides itwriteGeneral
crowdstrike_update_host_tagsAdds or removes Falcon grouping tags (FalconGroupingTags/<name>) on hostswriteGeneral
crowdstrike_list_host_groupsLists host groups with their type and assignment rule, by FQL filterreadGeneral
crowdstrike_list_alertsReturns full alerts matching an FQL filter, newest first by default, with an after token for the next pagereadPersonal data
crowdstrike_search_alert_idsReturns the composite ids of alerts matching an FQL filter or free-text search, with offset pagingreadGeneral
crowdstrike_get_alertsReturns alerts by composite idreadPersonal data
crowdstrike_update_alertsChanges the status of alerts, assigns or unassigns them, comments, or adds and removes tagswriteGeneral
crowdstrike_search_vulnerabilitiesSearches Spotlight vulnerabilities by FQL filter, with host, CVE and remediation details on requestreadGeneral
crowdstrike_search_iocsLists custom indicators of compromise (hashes, domains, IPs) by FQL filterreadGeneral
crowdstrike_create_iocCreates a custom indicator of compromise that Falcon detects or blockswriteGeneral