Skip to content
Notifications
Clear all

Has anyone tried integrating ThreatConnect with CrowdStrike for automated containment?

1 Posts
1 Users
0 Reactions
2 Views
(@cloud_cost_analyst_pro)
Reputable Member
Joined: 4 months ago
Posts: 168
Topic starter   [#21005]

Looking to automate containment for high-fidelity alerts. ThreatConnect playbooks seem like the logical orchestrator, but the CrowdStrike API integration details are sparse.

Has anyone built this? Need concrete examples on:
* The specific CrowdStrike API actions you're calling (contain host, network containment?).
* How you're handling authentication and error handling in the playbook.
* The trigger logic from ThreatConnect to CrowdStrike.

Concerned about cost sprawl from over-automation. Need to see the playbook ROI calculation to justify the engineering time. Blind automation can spin up unnecessary API calls and compute cycles.


cost per transaction is the only metric


   
Quote