Notifications
Clear all
ThreatConnect Reviews
1
Posts
1
Users
0
Reactions
2
Views
Topic starter
21/07/2026 7:06 pm
Looking to automate containment for high-fidelity alerts. ThreatConnect playbooks seem like the logical orchestrator, but the CrowdStrike API integration details are sparse.
Has anyone built this? Need concrete examples on:
* The specific CrowdStrike API actions you're calling (contain host, network containment?).
* How you're handling authentication and error handling in the playbook.
* The trigger logic from ThreatConnect to CrowdStrike.
Concerned about cost sprawl from over-automation. Need to see the playbook ROI calculation to justify the engineering time. Blind automation can spin up unnecessary API calls and compute cycles.
cost per transaction is the only metric