This app integrates with CrowdStrike OAuth2 authentication standard to implement querying of endpoint security data
Supported Actions
- test connectivity: test connectivity
- on poll: on poll
- assign hosts: Assign one or more hosts to an existing static host group
- check status: Check detonation status using the resource ID
- create ioa rule: Create a new IOA rule within a rule group
- create ioa rule group: Create an empty IOA rule group
- create session: Initialize a new session with the Real Time Response cloud
- delete indicator: Delete an IOC
- delete ioa rule: Delete IOA rules from a rule group
- delete ioa rule group: Delete IOA rule groups
- delete session: Deletes a Real Time Response session
- detonate file: Upload a file to CrowdStrike and retrieve the analysis results
- detonate url: Detonate a URL in the CrowdStrike sandbox
- download report: Download the report of a detonated file or URL
- file reputation: Queries CrowdStrike for the file reputation info
- get command details: Retrieve results of an active responder command executed on a single host
- get system info: Queries CrowdStrike for the details of a device
- get device scroll: Get a list of device IDs using pagination
- get epp details: Get details for the given EPP alerts
- get indicator: Get the details for an indicator
- get process detail: Queries CrowdStrike for the details of a process
- get role: Get information about a specific role
- get session file: Get RTR extracted file contents for the specified session and sha256 and add it to the vault
- get user roles: Get user roles
- get zta data: Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID)
- hunt domain: Hunt for a domain across all hosts in the environment
- hunt file: Hunt for a file across all hosts in the environment
- hunt ip: Hunt for an IP across all hosts in the environment
- list alerts: Fetch the list of alerts
- list custom indicators: List the custom indicators
- list epp alerts: Fetch the list of EPP alerts
- list groups: Fetch the details of the host groups
- list ioa platforms: Get the platforms that support IOA rules
- list ioa rule groups: Get the configured IOA rule groups
- list ioa severities: Get the severity levels that can be assigned to IOA rules
- list ioa types: Get the IOA types and their parameters
- list processes: Lists the processes a specified IOC ran on for a specific device
- list put files: Queries for files uploaded to Crowdstrike for use with the RTR `put` command
- list roles: Get the list of roles
- list session files: Get a list of files for the specified RTR session
- list sessions: Lists the active RTR sessions
- make request: make request
- list users: Gets the list of users
- query device: Fetch the list of devices
- quarantine device: This action contains the host, which stops any network communications to locations other than the CrowdStrike cloud and IPs specified in the user's containment policy.
- remove hosts: Remove one or more hosts from an existing static host group
- resolve epp alerts: Update the status of the given EPP alerts
- run admin command: Execute an RTR administrator command on a single host
- run command: Execute an RTR command on a single host
- run query: Run a generic query against a CrowdStrike API query endpoint
- unquarantine device: This action lifts containment on the host, which returns its network communications to normal.
- url reputation: Queries CrowdStrike for the URL reputation info
- update epp alerts: Update the given EPP alerts
- update indicator: Update an IOC
- update ioa rule: Update an existing IOA rule
- update ioa rule group: Update an existing IOA rule group
- upload indicator: Upload an IOC
- upload put file: Upload a new put-file to use for the RTR `put` command