Crowdstrike Falcon Integration
CrowdStrike detections in your SOC workflow, not a separate console.
What this integration does
CrowdStrike Falcon meets agentic SOC
CrowdStrike Falcon is the market-leading EDR platform. ManySignal ingests Falcon detections, process telemetry, and identity events via the Falcon Data Replicator and Event Stream API, enriches them with entity graph context, and correlates endpoint signals with cloud, identity, and network activity to reconstruct full attack chains.
Real-time detection ingestion via Falcon Event Stream API
Process tree and parent-child relationship analysis
Falcon Identity Protection signal ingestion
Data collected
- Falcon detection events with process tree
- Endpoint network connection logs
- CrowdStrike Identity Protection alerts
- Threat intelligence matches from CrowdStrike Falcon X
- Device and sensor health events
Actions supported
- Contain (isolate) host from the network via Falcon RTR
- Kill process on endpoint
- Delete malicious file via Falcon RTR
- Run custom RTR script on affected host
- Lift containment after remediation is confirmed
Getting started
Set up in minutes
- 1
Create a CrowdStrike API client
- 2
Configure the ManySignal connector
- 3
Enable Falcon Data Replicator (optional)
- 4
Configure response action scope
Crowdstrike Falcon Integration: frequently asked questions
Which CrowdStrike modules does ManySignal integrate with?
ManySignal integrates with Falcon Prevent (AV), Falcon Insight (EDR), Falcon Identity Protection, Falcon Intelligence, and Falcon Discover. Falcon Horizon (CSPM) findings are also ingested.
Can ManySignal correlate CrowdStrike and Okta events?
Yes. When a CrowdStrike detection involves a process running under a service account or domain user, ManySignal automatically correlates with that user's recent Okta authentication and privilege events.
Does real-time response require the RTR Admin scope?
Contain and lift-containment require Hosts Write. Script execution and file deletion require Real Time Response Admin. Read-only detection ingestion needs only Detections Read and Event Streams Read.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.