From f5674662368a79e0bd0f792e8e3d2812f73309fd Mon Sep 17 00:00:00 2001 From: "ruturaj.jain.ctr" Date: Thu, 13 Feb 2025 19:19:24 +0530 Subject: [PATCH 1/3] Added new action --- .../app-central/integrations/crowdstrike-falcon.md | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md b/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md index 312ffa1288..4520eb491e 100644 --- a/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md +++ b/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md @@ -7,8 +7,8 @@ import useBaseUrl from '@docusaurus/useBaseUrl'; crowdstrike-falcon -***Version: 1.12 -Updated: Nov 28, 2024*** +***Version: 1.13 +Updated: Feb 13, 2025*** The CrowdStrike Falcon integration allows you to pull and update Detections/Incidents, and search Incidents/Devices/Detections. @@ -23,6 +23,7 @@ The CrowdStrike Falcon integration allows you to pull and update Detections/Inci * **Get Incident Info** *(Enrichment)* - Get details for a specific Crowdstrike Incident. * **Get Indicators** *(Containment)* - Get Indicators By IDs. * **Get User ID By Mail** *(Enrichment)* - Search for a specific User ID with a given email address. +* **Get IDP Device Info** *(Enrichment)* - Search for sensors in your environment by hostname, IP, and other criteria. * **Incidents CrowdStrike Falcon Daemon** *(Daemon)* - Daemon to pull CrowdStrike Incidents. * **List Endpoints** *(Enrichment)* - Search for hosts in your environment by platform, hostname, IP. * **Search into Detections** *(Enrichment)* - Search for Detections that match a given query. @@ -63,3 +64,5 @@ EDR + Update Alerts + Search into Alerts + Alerts CrowdStrike Falcon Daemon +* February 13, 2025 (v1.13) - Added new action + + Get IDP Device Info From ec4f22ca642b08ef57d1cc9912201a7240c26e4b Mon Sep 17 00:00:00 2001 From: "ruturaj.jain.ctr" Date: Fri, 21 Feb 2025 14:10:53 +0530 Subject: [PATCH 2/3] modified description of action --- .../app-central/integrations/crowdstrike-falcon.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md b/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md index 4520eb491e..bf0d76d546 100644 --- a/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md +++ b/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md @@ -23,7 +23,7 @@ The CrowdStrike Falcon integration allows you to pull and update Detections/Inci * **Get Incident Info** *(Enrichment)* - Get details for a specific Crowdstrike Incident. * **Get Indicators** *(Containment)* - Get Indicators By IDs. * **Get User ID By Mail** *(Enrichment)* - Search for a specific User ID with a given email address. -* **Get IDP Device Info** *(Enrichment)* - Search for sensors in your environment by hostname, IP, and other criteria. +* **Get IDP Device Info** *(Enrichment)* - Retrieve detailed information about a devices from IDP. Requires IDP rights and relevant IDP-related API scopes. * **Incidents CrowdStrike Falcon Daemon** *(Daemon)* - Daemon to pull CrowdStrike Incidents. * **List Endpoints** *(Enrichment)* - Search for hosts in your environment by platform, hostname, IP. * **Search into Detections** *(Enrichment)* - Search for Detections that match a given query. From 0004d1d5d00f7c038aa493b75295b8af467ad9bf Mon Sep 17 00:00:00 2001 From: "ruturaj.jain.ctr" Date: Fri, 21 Feb 2025 14:11:57 +0530 Subject: [PATCH 3/3] modified date --- .../app-central/integrations/crowdstrike-falcon.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md b/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md index bf0d76d546..16b5ef73cd 100644 --- a/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md +++ b/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon.md @@ -8,7 +8,7 @@ import useBaseUrl from '@docusaurus/useBaseUrl'; crowdstrike-falcon ***Version: 1.13 -Updated: Feb 13, 2025*** +Updated: Feb 21, 2025*** The CrowdStrike Falcon integration allows you to pull and update Detections/Incidents, and search Incidents/Devices/Detections. @@ -64,5 +64,5 @@ EDR + Update Alerts + Search into Alerts + Alerts CrowdStrike Falcon Daemon -* February 13, 2025 (v1.13) - Added new action +* February 21, 2025 (v1.13) - Added new action + Get IDP Device Info