M ManySignal
MS
CS
Integration

Crowdstrike Falcon Integration

CrowdStrike detections in your SOC workflow, not a separate console.

What this integration does

CrowdStrike Falcon meets agentic SOC

CrowdStrike Falcon is the market-leading EDR platform. ManySignal ingests Falcon detections, process telemetry, and identity events via the Falcon Data Replicator and Event Stream API, enriches them with entity graph context, and correlates endpoint signals with cloud, identity, and network activity to reconstruct full attack chains.

Real-time detection ingestion via Falcon Event Stream API

Process tree and parent-child relationship analysis

Falcon Identity Protection signal ingestion

Data collected

  • Falcon detection events with process tree
  • Endpoint network connection logs
  • CrowdStrike Identity Protection alerts
  • Threat intelligence matches from CrowdStrike Falcon X
  • Device and sensor health events

Actions supported

  • Contain (isolate) host from the network via Falcon RTR
  • Kill process on endpoint
  • Delete malicious file via Falcon RTR
  • Run custom RTR script on affected host
  • Lift containment after remediation is confirmed

Getting started

Set up in minutes

  1. 1

    Create a CrowdStrike API client

  2. 2

    Configure the ManySignal connector

  3. 3

    Enable Falcon Data Replicator (optional)

  4. 4

    Configure response action scope

Crowdstrike Falcon Integration: frequently asked questions

Which CrowdStrike modules does ManySignal integrate with?

ManySignal integrates with Falcon Prevent (AV), Falcon Insight (EDR), Falcon Identity Protection, Falcon Intelligence, and Falcon Discover. Falcon Horizon (CSPM) findings are also ingested.

Can ManySignal correlate CrowdStrike and Okta events?

Yes. When a CrowdStrike detection involves a process running under a service account or domain user, ManySignal automatically correlates with that user's recent Okta authentication and privilege events.

Does real-time response require the RTR Admin scope?

Contain and lift-containment require Hosts Write. Script execution and file deletion require Real Time Response Admin. Read-only detection ingestion needs only Detections Read and Event Streams Read.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.