CrowdStrike Falcon Endpoint Protection

CrowdStrike Falcon Endpoint Protection Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com
Categories Security - Threat Protection,Security - Automation (SOAR)
Version 3.3.6
Author Microsoft - support@microsoft.com
First Published 2022-06-01
Last Updated 2026-06-01
Solution Folder CrowdStrike Falcon Endpoint Protection
Marketplace Azure Marketplace · Rating: ★☆☆☆☆ 1.0/5 (1 ratings) · Popularity: 🟢 High (87%)
Pre-requisites Common Event Format

The CrowdStrike Falcon Endpoint Protection solution allows you to easily onboard CrowdStrike Falcon Endpoint Protection to Microsoft Sentinel. The data collected can be used to create custom dashboards, alerts, and improve investigation. This gives you more insight into your organization's endpoints and improves your security operation capabilities.

This solution contains multiple Data Connectors that help ingest Falcon Data Replicator logs, Adversary Intelligence & other more specific data from CrowdStrike. Carefully review the capabilities of each connector and configure/enable the most relevant connector based on specific requirements.

Contents

Pre-requisites

This solution depends on 1 other solution(s):

Solution
Common Event Format

Data Connectors

This solution provides 4 data connector(s) (plus 2 discovered⚠️):

Connectors from dependency solutions:

🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.

Tables Used

This solution uses 30 table(s):

Table Used By Connectors Used By Content
ASimAuditEventLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimAuthenticationEventLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimAuthenticationEventLogs_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimDnsActivityLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimFileEventLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimFileEventLogs_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimNetworkSessionLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimProcessEventLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimProcessEventLogs_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimRegistryEventLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimRegistryEventLogs_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimUserManagementActivityLogs CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
ASimUserManagementLogs_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) -
CommonSecurityLog Common Event Format (CEF) (dependency), Common Event Format (CEF) via AMA (dependency), [Deprecated] CrowdStrike Falcon Endpoint Protection via AMA, [Deprecated] CrowdStrike Falcon Endpoint Protection via Legacy Agent Analytics, Workbooks
CrowdStrikeAlerts CrowdStrike API Data Connector (via Codeless Connector Framework) -
CrowdStrikeCases CrowdStrike API Data Connector (via Codeless Connector Framework) -
CrowdStrikeDetections CrowdStrike API Data Connector (via Codeless Connector Framework) -
CrowdStrikeHosts CrowdStrike API Data Connector (via Codeless Connector Framework) -
CrowdStrikeVulnerabilities CrowdStrike API Data Connector (via Codeless Connector Framework) -
CrowdStrike_Additional_Events_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3), CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_Audit_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_Auth_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_DNS_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_File_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_Network_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_Process_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_Registry_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_Secondary_Data_CL CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3), CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
CrowdStrike_User_Events_CL CrowdStrike Falcon Data Replicator (User Managed AWS-S3) (via Codeless Connector Framework) -
ThreatIntelObjects CrowdStrike Falcon Adversary Intelligence -

Internal Tables

The following 1 table(s) are used internally by this solution's content items:

Table Used By Connectors Used By Content
ThreatIntelIndicators CrowdStrike Falcon Adversary Intelligence -

Content Items

This solution includes 10 content item(s) (9 in solution, 1 discovered 🔍):

Content Type Total In Solution Discovered
Parsers 4 3 1
Playbooks 3 3 -
Analytic Rules 2 2 -
Workbooks 1 1 -

Analytic Rules

Name Severity Tactics Tables Used
Common Event Format (CEF) via AMA - Critical Severity Detection High Execution, Impact CommonSecurityLog
Common Event Format (CEF) via AMA - Critical or High Severity Detections by User High Impact, DefenseEvasion -

Workbooks

Name Tables Used
CrowdStrikeFalconEndpointProtection CommonSecurityLog

Playbooks

Name Description Tables Used
Crowdstrike API authentication This is Crowdstrike base template which is used to generate access token and this is used in actual ... -
Endpoint enrichment - Crowdstrike When a new Microsoft Sentinel incident is created, this playbook gets triggered and performs below a... -
Isolate endpoint - Crowdstrike When a new Microsoft Sentinel incident is created, this playbook gets triggered and performs below a... -

Parsers

Name Description Tables Used
CrowdStrikeFalconEventStream - CommonSecurityLog (read)
CrowdStrikeReplicator - CrowdStrikeReplicatorV2 (read)
CrowdstrikeReplicatorLogs_CL (read)
CrowdStrikeReplicatorV2 - ASimAuditEventLogs (read)
ASimAuthenticationEventLogs (read)
ASimAuthenticationEventLogs_CL (read)
ASimDnsActivityLogs (read)
ASimFileEventLogs (read)
ASimFileEventLogs_CL (read)
ASimNetworkSessionLogs (read)
ASimProcessEventLogs (read)
ASimProcessEventLogs_CL (read)
ASimRegistryEventLogs (read)
ASimRegistryEventLogs_CL (read)
ASimUserManagementActivityLogs (read)
ASimUserManagementLogs_CL (read)
CrowdStrike_Additional_Events_CL (read)
CrowdStrike_Secondary_Data_CL (read)
CrowdStrikeReplicator_future ⚠️ - -

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Additional Documentation

📄 Source: CrowdStrike Falcon Endpoint Protection/README.md

CrowdStrike Data Connectors

Table of Contents


Overview

Microsoft Sentinel provides multiple CrowdStrike data connectors for ingesting security, telemetry, and threat intelligence data from CrowdStrike Falcon.

This document provides an overview of the available CrowdStrike data connectors and helps you easily determine which connector best fits your data ingestion requirements.

The following CrowdStrike data connectors are currently available:

  1. CrowdStrike API Data Connector (via Codeless Connector Framework)
  2. CrowdStrike Falcon Data Replicator (AWS S3) (via Codeless Connector Framework)
  3. CrowdStrike Falcon Adversary Intelligence

Available Data Connectors

1. CrowdStrike API Data Connector (via Codeless Connector Framework)

The CrowdStrike API Data Connector (via Codeless Connector Framework) collects data directly from CrowdStrike Falcon native APIs.

Use this connector when you need security-related information that is available through CrowdStrike APIs, including:

To learn more about the available CrowdStrike APIs and supported datasets, refer to the CrowdStrike API Reference documentation:

CrowdStrike API Reference https://developer.crowdstrike.com/api-reference/overview/

Configuration Requirements

Before configuring the Microsoft Sentinel connector:

  1. Create an API client in CrowdStrike Falcon.

  2. Collect the following information:

    • Client ID
    • Client Secret
    • API Endpoint
  3. Provide these values during connector configuration in Microsoft Sentinel.


2. CrowdStrike Falcon Data Replicator (AWS S3) (via Codeless Connector Framework)

The CrowdStrike Falcon Data Replicator (AWS S3) (via Codeless Connector Framework) connector collects telemetry data exported by CrowdStrike to Amazon S3 and ingests it into Microsoft Sentinel.

Use this connector when detailed endpoint telemetry is required, including:

These telemetry datasets are generally not available through CrowdStrike native APIs and are delivered through the Falcon Data Replicator (FDR) service.

Prerequisites

Before configuring the Microsoft Sentinel connector:

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.3.9 24-07-2026 Updated titles for both CrowdStrike Falcon Data Replicator connectors
3.3.8 24-07-2026 Updated CrowdStrike API Data Connector polling to use updated time instead of created time
3.3.7 13-07-2026 Updated CrowdStrike API Data Connector UI labels
3.3.6 28-05-2026 Added support of multiple domains to Crowdstrike API Data Connector
3.3.5 20-05-2026 Updated Analytic Rules (v1.0.5): improved descriptions, added MITRE ATT&CK tactics, and optimized KQL queries. Updated Workbook to remove hardcoded resource IDs. Added non-analytics tier queries to CrowdStrike Falcon Data Replicator (AWS S3) Data Connector to support Basic/Auxiliary plan tables (Usage-based fallback, 14h window).
3.3.4 30-04-2026 remove deprecated tag. CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) is not deprecated
3.3.3 13-04-2026 Deprecate CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) (using Azure Function)
3.3.2 16-03-2026 Update CrowdStrike API Data Connector to GA with adding rate limits to inner steps for Alerts and Detections data types
3.3.1 05-03-2026 Update CrowdStrike API Data Connector to fix Alerts and Detections data types
3.3.0 26-01-2026 Refresh CrowdStrike API Data Connector with Cases data type and multiple improvements
3.2.0 07-01-2026 Updated CrowdStrike Falcon Adversary Data Connector Change table name to be "ThreatIntelIndicators" instead of "ThreatIntelligenceIndicator"
3.1.9 17-12-2025 Updated CrowdStrike API Data Connector Enhance API configuration instructions with link
3.1.8 08-12-2025 Updated CrowdStrike API Data Connector to fix rate limit exceptions by introducing retry logic.
3.1.7 12-11-2025 Updated CrowdStrike API Data Connector to fix rate limit exceptions
3.1.6 23-10-2025 Updated CrowdStrike API Data Connector to fix deprecated detections API issues
3.1.5 22-08-2025 Updated CrowdStrike API Data Connector to fix duplicate logs issues
3.1.4 04-07-2025 Added new CCF Connector to the Solution CrowdStrike API Data Connector.
Removed Crowdstrike Falcon Data Replicator - Function App Data Connector.
Updated Connectors description.
3.1.3 24-06-2025 Removed "DEPRECATED" label from the Crowdstrike Falcon Data Replicator V2 - Data connector.
Updated Solution description.
3.1.2 03-06-2025 Crowdstrike Falcon S3 CCF connector moving to GA.
3.1.1 08-05-2025 Added preview tag to CCP Connector.
3.1.0 11-03-2025 Added new CCP Data Connector to the Solution.
3.0.10 15-01-2025 Resolve Workbook data type dependency issue.
3.0.9 12-11-2024 Removed deprecated Data Connectors.
Updated the python runtime version to 3.11 in Data Connector Function App.
3.0.8 10-07-2024 Deprecated Data Connector.
3.0.7 20-06-2024 Shortlinks updated for Data Connector CrowdStrike Falcon Indicators of Compromise.
3.0.6 06-06-2024 Renamed Data Connector CrowdStrike Falcon Indicators of Compromise to CrowdStrike Falcon Adversary Intelligence.
3.0.5 30-05-2024 Added new Function App Data Connector CrowdStrike Falcon Indicators of Compromise.
3.0.4 03-05-2024 Fixed Parser issue for Parser name and ParentID mismatch.
3.0.3 10-04-2024 Added Azure Deploy button for government portal deployments.
3.0.2 14-02-2024 Addition of new CrowdStrike Falcon Endpoint Protection AMA Data Connector.
3.0.1 31-01-2024 Data Connector[Crowdstrike Falcon Data Replicator V2] globally available.
3.0.0 28-07-2023 New Data Connector added.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index