CrowdStrike Falcon connector for Okou
Connect CrowdStrike Falcon to investigate alerts, search hosts, inspect custom IOCs, and query Falcon Intelligence data.
Data & infrastructure · OAuth 2.0 Access Token
Use CrowdStrike Falcon in Okou
CrowdStrike Falcon API for read-only alert investigation, host inventory, custom IOC lookup, and Falcon Intelligence queries.
Once connected, supported CrowdStrike Falcon actions can become steps in a reusable workflow alongside the other services your team uses. Run the workflow once, on a schedule, or when an event starts it.
What you can do with CrowdStrike Falcon
- Read Falcon alert identifiers, alert details, aggregates, and FQL-matched alert records.
- Read endpoint inventory, host details, online state, login history, and network-address history.
- Read Falcon Intelligence actor entities and MITRE ATT&CK relationships.
- Read custom IOC metadata, sightings, aggregates, and lookup values.
- Read Falcon Intelligence indicator entities and indicator searches.
- Read Falcon Intelligence adversary incidents, searches, and aggregates.
- Read Falcon Intelligence malware families and their MITRE ATT&CK relationships.
- Read Falcon Intelligence reports and report attachments.
How the CrowdStrike Falcon connector works
A connected service becomes one permissioned step in the work you hand off.
- 1
Connect CrowdStrike Falcon
Choose OAuth 2.0 Access Token.
- 2
Choose the work
Use only the supported actions your workflow needs.
- 3
Run it your way
Start it once, schedule it, or attach an event trigger.
Connect CrowdStrike Falcon securely
Use the connection method that fits your account and grant only the access the workflow needs.
- OAuth 2.0 Access Token
Connector access is controlled per service and per action, so a workflow does not need broader access than the work you ask it to do.
CrowdStrike Falcon connector questions
- What can Okou do with CrowdStrike Falcon?
- Connect CrowdStrike Falcon to investigate alerts, search hosts, inspect custom IOCs, and query Falcon Intelligence data. Documented actions include: Read Falcon alert identifiers, alert details, aggregates, and FQL-matched alert records. Read endpoint inventory, host details, online state, login history, and network-address history.
- How do I connect CrowdStrike Falcon to Okou?
- Connect CrowdStrike Falcon using OAuth 2.0 Access Token. The connection controls which supported actions a workflow can use.
- Can CrowdStrike Falcon run in an automated workflow?
- Yes. After it is connected, supported CrowdStrike Falcon actions can run in reusable Okou workflows on demand, on a schedule, or from an event trigger.
More data & infrastructure connectors
Explore other connectors in the same product category.
Crunchy Bridge
Connect your Crunchy Bridge account to inspect and manage hosted PostgreSQL clusters, teams, networks, backups, and database settings through the Bridge API.
Crossmint
Connect Crossmint to create and manage wallets, inspect balances and assets, submit and approve transactions and signatures, manage delegated signers, and transfer tokens.
Cryptlex
Connect Cryptlex to manage software licensing products, licenses, activations, entitlements, customers, releases, automation, and analytics through Web API v3.

