Skip to main content
CrowdStrike OAuth API app icon

CrowdStrike OAuth API

This app integrates with CrowdStrike OAuth2 authentication standard to implement querying of endpoint security data

Built by Splunk LLC
soar product badge

Default Version 6.0.0
July 23, 2026
Compatibility
SOAR On-Prem, SOAR Cloud
Platform Version: 8.6
Rating

5

(1)

Log in to rate this app
Support
Splunk Supported
Ranking

#11

in Endpoint
This app integrates with CrowdStrike OAuth2 authentication standard to implement querying of endpoint security data

Supported Actions

  • test connectivity: test connectivity
  • on poll: on poll
  • assign hosts: Assign one or more hosts to an existing static host group
  • check status: Check detonation status using the resource ID
  • create ioa rule: Create a new IOA rule within a rule group
  • create ioa rule group: Create an empty IOA rule group
  • create session: Initialize a new session with the Real Time Response cloud
  • delete indicator: Delete an IOC
  • delete ioa rule: Delete IOA rules from a rule group
  • delete ioa rule group: Delete IOA rule groups
  • delete session: Deletes a Real Time Response session
  • detonate file: Upload a file to CrowdStrike and retrieve the analysis results
  • detonate url: Detonate a URL in the CrowdStrike sandbox
  • download report: Download the report of a detonated file or URL
  • file reputation: Queries CrowdStrike for the file reputation info
  • get command details: Retrieve results of an active responder command executed on a single host
  • get system info: Queries CrowdStrike for the details of a device
  • get device scroll: Get a list of device IDs using pagination
  • get epp details: Get details for the given EPP alerts
  • get indicator: Get the details for an indicator
  • get process detail: Queries CrowdStrike for the details of a process
  • get role: Get information about a specific role
  • get session file: Get RTR extracted file contents for the specified session and sha256 and add it to the vault
  • get user roles: Get user roles
  • get zta data: Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID)
  • hunt domain: Hunt for a domain across all hosts in the environment
  • hunt file: Hunt for a file across all hosts in the environment
  • hunt ip: Hunt for an IP across all hosts in the environment
  • list alerts: Fetch the list of alerts
  • list custom indicators: List the custom indicators
  • list epp alerts: Fetch the list of EPP alerts
  • list groups: Fetch the details of the host groups
  • list ioa platforms: Get the platforms that support IOA rules
  • list ioa rule groups: Get the configured IOA rule groups
  • list ioa severities: Get the severity levels that can be assigned to IOA rules
  • list ioa types: Get the IOA types and their parameters
  • list processes: Lists the processes a specified IOC ran on for a specific device
  • list put files: Queries for files uploaded to Crowdstrike for use with the RTR `put` command
  • list roles: Get the list of roles
  • list session files: Get a list of files for the specified RTR session
  • list sessions: Lists the active RTR sessions
  • make request: make request
  • list users: Gets the list of users
  • query device: Fetch the list of devices
  • quarantine device: This action contains the host, which stops any network communications to locations other than the CrowdStrike cloud and IPs specified in the user's containment policy.
  • remove hosts: Remove one or more hosts from an existing static host group
  • resolve epp alerts: Update the status of the given EPP alerts
  • run admin command: Execute an RTR administrator command on a single host
  • run command: Execute an RTR command on a single host
  • run query: Run a generic query against a CrowdStrike API query endpoint
  • unquarantine device: This action lifts containment on the host, which returns its network communications to normal.
  • url reputation: Queries CrowdStrike for the URL reputation info
  • update epp alerts: Update the given EPP alerts
  • update indicator: Update an IOC
  • update ioa rule: Update an existing IOA rule
  • update ioa rule group: Update an existing IOA rule group
  • upload indicator: Upload an IOC
  • upload put file: Upload a new put-file to use for the RTR `put` command

Categories

Endpoint

Created By

Splunk LLC

Type

connector

Downloads

30,459

Featured in Collection

Getting Started with Security

Resources

Log in to report this app listing