Skip to content

CrowdStrike

Integrate your Incident Register with CrowdStrike Falcon. This integration imports alerts from NGSiem, CWPP, and EPP as Incident records. Alerts are aggregated by correlation ID before being synced.

  • Source: EDR
  • Opened By: “CrowdStrike Integration”

The integration can be enabled directly from your Adversarial tenant via Settings > Integrations. The necessary details to connect your CrowdStrike environment are the API Client ID and Client Secret, which must have read permissions for alerts and incidents.

CrowdStrike integration configuration

CrowdStrike alert statuses are mapped to Adversarial incident statuses:

CrowdStrike StatusAdversarial Status
newNew
in_progress / assignedIn Progress
closedClosed
(unrecognized)New

CrowdStrike alert severity maps to Adversarial incident severity. All severity levels are imported.

CrowdStrike SeverityAdversarial Severity
CriticalSEV-1
HighSEV-2
MediumSEV-3
LowSEV-4
InformationalSEV-5
CrowdStrike FieldAdversarial FieldNotes
nameTitle
descriptionDescriptionEnriched with product context and MITRE info during aggregation
created_dateCreated Date
created_dateDetected Date
timestampOccurred DateFalls back to created_date if missing
seconds_to_triagedResponded DateComputed as created_date + seconds_to_triaged
seconds_to_resolvedContained DateComputed as created_date + seconds_to_resolved
(static)SourceAlways “EDR”