# CrowdStrike

**Categories:** Security

Automate threat response and endpoint security management with CrowdStrike Falcon.

CrowdStrike Falcon is a cloud-native endpoint protection platform that provides advanced threat detection, prevention, and response capabilities. Connecting CrowdStrike to Harmony enables automated threat response, intelligent security monitoring, and AI-powered incident resolution for your endpoint security operations.

## Capabilities

- **Threat Detection**: Monitor and respond to security threats across all endpoints
- **Device Monitoring**: Track CrowdStrike agent status and protection state
- **Real-Time Alerts**: Receive and route security alerts to appropriate teams

## What Harmony does with CrowdStrike

Connecting CrowdStrike Falcon puts live endpoint threat posture inside Harmony's single agent inventory, so teams see which devices are at risk without opening the Falcon console. Detections, incidents, and agent health sit alongside every other signal Harmony tracks. When something needs action, teams can contain a device or route the incident from the same place they are already working.

## Data synced

- Security detections with severity levels and contextual details
- Falcon agent health and device protection status
- Real-time security alerts from endpoint activity
- Device containment states and host network details

## Actions available

- Isolate a compromised device to stop a threat from spreading
- Create an incident ticket from a critical detection and route it to the right team
- Surface at-risk devices so IT can act before issues escalate

## Real-world use cases

**Contain before it spreads**: A high-severity detection lands on an executive laptop. Harmony surfaces it in Slack and the security team isolates the device before the malware moves laterally.

**One view of coverage**: IT checks Harmony to confirm every device has a healthy Falcon agent, catching machines that dropped off protection without pulling a separate report.

**Faster triage**: A new alert fires overnight. Harmony routes it to the on-call responder with the device record attached, so triage starts without a console login.

## Related integrations

- [SentinelOne](/integrations/sentinelone)

- [Microsoft Defender for Endpoint](/integrations/microsoft-defender-for-endpoint)

- [Palo Alto Cortex](/integrations/paloaltocortex)

## FAQ

### What is CrowdStrike?

Bring CrowdStrike Falcon device threat posture into Harmony so IT and security teams can see and respond to risks in one place. Connecting CrowdStrike Falcon puts live endpoint threat posture inside Harmony's single agent inventory, so teams see which devices are at risk without opening the Falcon console.

### What data does Harmony sync from CrowdStrike?

Harmony's CrowdStrike integration syncs the following into a single agent inventory: security detections with severity levels and contextual details; falcon agent health and device protection status; real-time security alerts from endpoint activity; and device containment states and host network details.

### What can I do with CrowdStrike through Harmony?

Through the CrowdStrike integration, Harmony can isolate a compromised device to stop a threat from spreading; create an incident ticket from a critical detection and route it to the right team; and surface at-risk devices so IT can act before issues escalate.

### How does the CrowdStrike integration help security teams?

A high-severity detection lands on an executive laptop. Harmony surfaces it in Slack and the security team isolates the device before the malware moves laterally.

### What other integrations pair with CrowdStrike in Harmony?

CrowdStrike is commonly paired with SentinelOne (Security), Microsoft Defender for Endpoint (Security), and Palo Alto Cortex (Security) inside Harmony, giving IT one unified view across related systems.