Skip to main content

CrowdStrike Endpoint Security

Endpoint Protection

The CrowdStrike Endpoint Security (ES) connector integrates with the CrowdStrike Falcon Spotlight and Devices modules, synchronizing endpoint devices, Spotlight vulnerabilities, and vulnerability definitions. Evaluation logic data is included inline with vulnerabilities via the evaluation_logic facet.


Data retrieved from CrowdStrike Endpoint Securityโ€‹

Connector ObjectRequiredMaps to Data Model
๐Ÿ–ฅ๏ธ DeviceYesHost
โš ๏ธ VulnerabilityYesVulnerability
๐Ÿ“– Vulnerability DefinitionYesVulnerability Definition

Model relationshipsโ€‹

note

For detailed steps on how to view the data retrieved from CrowdStrike Endpoint Security in the Brinqa Platform, see How to view your data.

note

As part of aligning with the broader suite of CrowdStrike solutions, the connector formerly known as CrowdStrike was renamed to CrowdStrike Endpoint Security in connector version 3.2.0.

note

Note: If the caller already provides a last_seen_within value in the FQL filter string, the connector does not override it.

note

Note: host_info.machine_domain is not a supported filter field for the Spotlight API. The field is present in the API response but cannot be used for server-side filtering. Attempting to filter by this field returns a 400 Bad Request: invalid filter error. This is a CrowdStrike API limitation.