EDR / XDR integration

Automate CrowdStrike Falcon EDR / XDR with plain language

Read the Falcon sensor inventory, detections and incidents, and network-contain a host that VernacSecure SuperBot™ finds compromised.

What you can do

CrowdStrike Falcon — Insight EDR / OAuth2 REST API

  • List host sensors with OS, hostname and last-seen
  • Read detections and incidents
  • Network-contain or lift containment on a host

Connection: bearer authentication against https://api.crowdstrike.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Isolate the laptop with the latest critical detection in CrowdStrike Falcon”

Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.

Get started free

Read actions
  • Fetch hosts — Lists device IDs known to Falcon.
  • Fetch detections — Lists recent detections.
  • Fetch incidents — Lists incidents raised by Falcon.
  • Fetch vulnerabilities — Lists Spotlight vulnerabilities.
Write actions
  • Contain host — Network-contains the named device ID.