0
1.1.0
Australia, Zurich, Yokohama
Integration
CrowdStrike NextGen SIEM Integration for Threat Intelligence Security Center (TISC) enables Cyber Threat Intelligence (CTI) analysts to search Falcon NextGen SIEM for sightings of observables such as IP addresses, domains, and file hashes directly from the Threat Intelligence Library, case artifacts, or an automated workflow, with matches captured as sighting records on the observable for real-world visibility into where an indicator has been seen across the environment.
- Search for observable sightings — Query CrowdStrike Falcon NextGen SIEM directly from the Threat Intelligence Library to find where indicators (IP addresses, domains, file hashes) have been seen across your environment.
- Automated indicator push to CrowdStrike — Continuously send critical observables from TISC to CrowdStrike NextGen SIEM as lookup tables for real-time detection and monitoring with customizable filters (threat score, confidence, tags, expiry).
- No manual query writing — TISC automatically constructs CrowdStrike queries from observable types and values—analysts get results without technical query knowledge.
- Workflow automation — Trigger sighting searches automatically via workflows or manually from cases, threat intelligence library, or analyst workbench.
New
- CrowdStrike Next-Gen SIEM integration enables analysts to search Falcon Next-Gen SIEM for observable sightings from the Threat Intelligence Library, case artifacts, or automated workflows. Matching results are saved as sighting records on the observable.
Not applicable for this application version.
Dependencies:
- Threat Intelligence Security Center (TISC)