For the complete documentation index, see llms.txt. This page is also available as Markdown.

CrowdStrike

Automate threat response and endpoint security management with CrowdStrike Falcon integration

About CrowdStrike

CrowdStrike Falcon is a cloud-native endpoint protection platform that provides advanced threat detection, prevention, and response capabilities. Connecting CrowdStrike to Harmony enables automated threat response, intelligent security monitoring, and AI-powered incident resolution for your endpoint security operations.

What the CrowdStrike integration enables

Capability
Description

Threat Detection

Monitor and respond to security threats across all endpoints

Device Monitoring

Track CrowdStrike agent status and protection state

Real-Time Alerts

Receive and route security alerts to appropriate teams

Prerequisites

  • CrowdStrike Falcon Subscription: Active subscription with API access

  • Admin Credentials: Falcon Administrator or API Client Manager role

  • Harmony Account: Active Harmony workspace

Connect CrowdStrike to Harmony

Step 1: Create OAuth2 API Client in CrowdStrike

  1. Log in to CrowdStrike Falcon console

  2. Navigate to Support > API Clients and Keys

  3. Click Add new API Client

  4. Configure client:

    • Client Name: "Harmony Integration"

    • Description: "Integration with Harmony IT operations platform"

  5. Select API Scopes:

    • Hosts: Read

    • Hosts Groups: Read

    • Sensor Update Policies: Read

    • Alerts: Read

    • Incidents: Read

    • Prevention Policies: Read

    • Response Policies: Read

    • Real Time Response: Read

    • Sensor Usage: Read

    • User Management: Read

  6. Click Add and copy the Client ID, Client Secret, and Base URL

Step 2: Navigate to Integrations

  1. Log in to your Harmony dashboard

  2. Go to Settings > Integrations

  3. Find CrowdStrike under EDR and click Connect

Navigate to CrowdStrike integration in Harmony dashboard

Step 3: Enter API Credentials

  1. Enter your Base URL (e.g., https://api.crowdstrike.com)

  2. Enter your Client ID

  3. Enter your Client Secret

  4. Click Connect

Enter CrowdStrike credentials to connect

What Harmony Syncs

From CrowdStrike:

  • Security detections with severity and details

  • Security incidents and investigation data

  • Device status and Falcon agent health

  • Host information and network details

  • Containment state of devices

  • Prevention policies and compliance status

  • Threat intelligence and IOCs

  • Real-time security alerts

Use Cases

Automated Threat Response

Immediate containment and response to critical security threats

Security Incident Management

Sync CrowdStrike detections with IT support tickets for tracking

Device Compliance Monitoring

Track Falcon agent health and automatically resolve common issues

User-Friendly Security Alerts

Translate technical security alerts into clear user communications

Last updated

Was this helpful?