Skip to content
Home logo
Corelight-update docs CrowdStrike
Type to start searching
    • Home
    • |
    • Policy configuration
    • Third-party integrations settings
    • QuickStart - new install
    • QuickStart - upgrade
    • Global configuration
    • Policy configuration
      • Policy sources
      • Policy inventory settings
      • Suricata configuration
      • Intel management
      • Input management
      • YARA management
      • Third-party integrations settings
        • Analyst1
        • Axonius
        • CrowdStrike
          • Falcon Exposure Management - Hosts & CVEs
          • Falcon Suricata Ruleset
          • Falcon Threat Intelligence
          • Falcon YARA ruleset
        • FireEye iSIGHT Threat Intelligence
        • Maxmind GeoIP
        • icannTLD Zeek script
        • Mandiant Threat Intelligence
        • MS Defender
        • MISP - Zeek export
        • AlienVault Open Threat Exchange
        • Zeek package management
        • SentinelOne
        • STIX/TAXII
        • Tenable
        • ThreatQ - Zeek export
    • References
    • Corelight-update Release Notes

    • Download PDF
    • Corelight Sensor docs
    • Corelight Support
    • corelight.com

    CrowdStrike¶

    CrowdStrike integration collects Hosts and Vulnerability data of systems, networks and applications using Falcon Exposure Management. Suricata Rulesets and Indicators are downloaded from CrowdStrike’s Falcon Threat Intelligence.

    See the following sections for more details on each integration:

    • Falcon Exposure Management - Hosts & CVEs
    • Falcon Suricata Ruleset
    • Falcon Threat Intelligence
    • Falcon YARA ruleset
    Previous Axonius
    Next Falcon Exposure Management - Hosts & CVEs
    © Copyright 2015–2025 Corelight. Last updated on 2025-04-15 16:17:43.494115.