Crowdstrike bidirectional integration (tech preview) [Request] #5446
Labels
Docset: ESS
Issues that apply to docs in the Stack release
Docset: Serverless
Issues for Serverless Security
Feature: Response actions
also includes response console
Team: EDR Workflows
Formerly Defend Workflows, Onboarding and Lifecycle Management
v8.15.0
Description
We are releasing our bidirectional capability with Crowdstrike, which will allow users to execute host isolation / release of a crowdstrike agent through elastic security. Functionalities include:
This is similar to the functionality (and docs) we previously added for Sentinel One: https://www.elastic.co/guide/en/security/current/response-actions-config.html (see also, S1 docs ticket: #4312)
Background & resources
Internal docs issue (additional context and discussion): https://github.com/elastic/security-docs-internal/issues/21
PRs: [EDR Workflows] Add Crowdstrike Response Actions client kibana#180197
Additional PRs
Issues/metas: EPIC: https://github.com/elastic/security-team/issues/6200, https://github.com/elastic/security-team/issues/8907, https://github.com/elastic/security-team/issues/9587
Additional issues
Point of contact: @tomsonpl @paul-tavares @caitlinbetz @dasansol92
Test environments:
Additional info
Which documentation set does this change impact? ESS and serverless
ESS release: 8.15
Serverless release: Week of July 1, 2024
Feature differences: n/a
API docs impact: @tomsonpl - can you provide?
Prerequisites, privileges, feature flags:
ESS:
Tasks & Pull Requests
The text was updated successfully, but these errors were encountered: