Skip to content
CrowdStrike logo

CrowdStrike integration

Surface CrowdStrike Falcon endpoint inventory and enforce security policies directly inside service management workflows.

What it connects

  • Managed endpoints with Falcon agent version, OS, IP address, and hardware details
  • Falcon console users and administrator accounts for access-control audits
  • Host groups configured for policy assignment and organizational segmentation
  • Dynamic group memberships to track which devices belong to which policy tiers

What it automates

  • Isolate a compromised device from the network to prevent lateral movement and attack spread
  • Remove network containment to restore connectivity after incident resolution or validation
  • Organize endpoints into policy groups for coordinated security patching and threat response
  • Tag hosts with custom labels to mark devices under investigation or affected by active incidents

In practice

When a malicious process is detected on a critical-asset device, STLabs isolates the endpoint via network containment while auto-creating a security ticket for the SOC team to investigate.
A security audit identifies workstations missing a required security group; STLabs automatically assigns them to the correct policy tier and notifies the team of the compliance change.
After an analyst confirms a detection is a false positive, STLabs lifts the network containment and tags the host with an exclusion label to prevent duplicate future alerts.
STLabs pulls the full device inventory with agent versions and OS information to generate compliance reports showing which endpoints require urgent patching.

More Security & Compliance integrations

See how it connects.Every tool, one live map.

All integrations