
Aug 25, 2026
2.0.0
ThreatQ Versions >= 5.12.0
Crowdstrike Insight EDR
Overview
The CrowdStrike Insight EDR CDF for ThreatQ gives analysts the ability to ingest detection incidents from CrowdStrike.
The integration provides the following feeds:
- CrowdStrike Insight EDR - Detections - brings in aggregated detections, along with their behavioral events and related IOCs, into ThreatQ.
- CrowdStrike Insight EDR - Combined Detections - retrieves complete alert objects using cursor-based pagination for efficient processing of large result sets.
- CrowdStrike Insight EDR - Hosts - brings in aggregated detections, along with their behavioral events and related IOCs into ThreatQ.
The following object types are ingested from the feeds above:
- Assets
- Attack Patterns
- Events
- Incidents
- Indicators
- Filename
- File Path
- IP Address
- Username
- MD5
- SHA-256
- FQDN
- Registry Key