CrowdStrike integration
Surface CrowdStrike Falcon endpoint inventory and enforce security policies directly inside service management workflows.
What it connects
- Managed endpoints with Falcon agent version, OS, IP address, and hardware details
- Falcon console users and administrator accounts for access-control audits
- Host groups configured for policy assignment and organizational segmentation
- Dynamic group memberships to track which devices belong to which policy tiers
What it automates
- Isolate a compromised device from the network to prevent lateral movement and attack spread
- Remove network containment to restore connectivity after incident resolution or validation
- Organize endpoints into policy groups for coordinated security patching and threat response
- Tag hosts with custom labels to mark devices under investigation or affected by active incidents
In practice
When a malicious process is detected on a critical-asset device, STLabs isolates the endpoint via network containment while auto-creating a security ticket for the SOC team to investigate.
A security audit identifies workstations missing a required security group; STLabs automatically assigns them to the correct policy tier and notifies the team of the compliance change.
After an analyst confirms a detection is a false positive, STLabs lifts the network containment and tags the host with an exclusion label to prevent duplicate future alerts.
STLabs pulls the full device inventory with agent versions and OS information to generate compliance reports showing which endpoints require urgent patching.