EDR / XDR integration
Automate CrowdStrike Falcon EDR / XDR with plain language
Read the Falcon sensor inventory, detections and incidents, and network-contain a host that VernacSecure SuperBot™ finds compromised.
What you can do
CrowdStrike Falcon — Insight EDR / OAuth2 REST API
- List host sensors with OS, hostname and last-seen
- Read detections and incidents
- Network-contain or lift containment on a host
Connection: bearer authentication against https://api.crowdstrike.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Isolate the laptop with the latest critical detection in CrowdStrike Falcon”
Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.
Read actions
- Fetch hosts — Lists device IDs known to Falcon.
- Fetch detections — Lists recent detections.
- Fetch incidents — Lists incidents raised by Falcon.
- Fetch vulnerabilities — Lists Spotlight vulnerabilities.
Write actions
- Contain host — Network-contains the named device ID.
Related edr automation pages
Bitdefender GravityZone · Broadcom Symantec Endpoint Security · Check Point Harmony Endpoint · Cisco Secure Endpoint · Cybereason Defense Platform · ESET Inspect