CrowdStrike - Incident Actions
  • 02 Apr 2025
  • 1 Minute to read
  • Dark
    Light
  • PDF

CrowdStrike - Incident Actions

  • Dark
    Light
  • PDF

Article summary

CrowdStrike - Incident Actions

Description

CrowdStrike's Incident Actions is a playbook that provides a streamlined and efficient way to respond to security incidents. It allows organizations to quickly detect, investigate, and respond to threats in real time. This playbook leverages the power of the CrowdStrike Falcon platform to provide a comprehensive set of security incident response capabilities. With Incident Actions, organizations can quickly identify, investigate, and respond to threats, and take proactive steps to prevent future incidents. The playbook includes features such as automated incident response workflows, automated threat intelligence analysis, and automated alerting and notification. Additionally, Incident Actions allows organizations to customize their security incident response processes to meet their specific needs. With Incident Actions, organizations can quickly and effectively respond to security incidents, and ensure that their systems remain secure and protected.

Trigger Request

  • HTTP Post Request

  • Headers:

KeyValue
Content-Typeapplication/json
  • Json body parameters:
ParametersTypeDescription
access_tokenstringAccess token for the CrowdStrike API. Can be achieved by calling to CrowdStrike_Base_Token flow.
action_parametersarrayPlease provide the description of this parameter.
idsarrayPlease provide the description of this parameter.

Supported CDC Versions

  • 2.8

Was this article helpful?