CrowdStrike Falcon
Endpoint detections, incidents and host inventory.
Workspace connectionConnect endpoint, identity, cloud and network sources to give investigations and reporting the context they need.
Endpoint detections, incidents and host inventory.
Workspace connectionEndpoint threats, agents and activity for investigation context.
Workspace connectionEndpoint alerts, machines and vulnerability findings.
Workspace connectionEndpoint alerts, agent inventory and vulnerability findings.
Workspace connectionSecurity incidents and analytics-rule context from your Sentinel workspace.
Workspace connectionNotable events, saved searches and platform health context.
Workspace connectionSecurity alerts, detection rules and Elasticsearch cluster health.
Workspace connectionMicrosoft 365 identity, configuration, governance and security evidence.
Workspace connectionIdentity and access evidence from your Okta environment.
Workspace connectionWorkspace identity and governance collection.
Workspace connectionAuthentication and multifactor-access context.
Workspace connectionManaged-device posture and application workflows through your Microsoft connection.
Through Microsoft 365Email-security evidence for the wider security picture.
Workspace connectionEmail-protection context from your Mimecast environment.
Workspace connectionVulnerability and asset evidence for prioritisation.
Workspace connectionAsset and vulnerability-management evidence.
Workspace connectionInsight vulnerability context and assessment data.
Workspace connectionFirewall and network-security context.
Workspace connectionFortiGate network and firewall evidence.
Workspace connectionNetwork devices and security-event context.
Workspace connectionNetwork-controller integration through the provider framework.
Assisted setupOn-premises firewall telemetry and hardening audits through collector workflows.
Collector connectionCloud-security and configuration evidence from Amazon Web Services.
Workspace connectionAzure subscription and cloud-security context.
Workspace connectionCloud-platform evidence through your Google Cloud connection.
Workspace connectionAwareness and phishing-training context for people risk.
Workspace connectionSecurity-awareness collection and reporting context.
Workspace connectionIssue and service-delivery context from your Jira instance.
Workspace connectionIT service-management context from your ServiceNow instance.
Workspace connectionThreat-intelligence provider connection through the integration framework.
Assisted setupSubscribed threat-intelligence pulses and recent activity.
Assisted setupChannel-based alert delivery through a configured Slack bot.
Assisted setupNotification cards through a configured Teams webhook.
Assisted setupIncident escalation and on-call context through a configured provider.
Assisted setupHost inventory, health and on-premises evidence through the signed-agent workflows.
Collector connectionDomain, identity, group-policy and certificate-services auditing through on-premises collection.
Collector connectionPush-based network and security-event collection for supported log formats.
Collector connectionTry a product name or a broader category. We can also discuss a bespoke connection.
Tell us about your API, data source or on-premises system. We’ll scope a connection around the available interface, permissions and evidence you need.
Setup depends on source capabilities, licensing and the permissions you approve. The directory distinguishes workspace integrations, assisted setup, Microsoft-connected capabilities and collectors.
Tell us about your environment, your priorities and where you need support.