CrowdStrike
Coming soon ProCloud EDR
The cloud-EDR you don't run — its detections, your case lifecycle.
CrowdStrike homepage ↗The cloud-EDR you don't have to run. Falcon's Event Streams API delivers detection telemetry without you owning the data plane — your sovereignty is intact at the SOC layer.
What it watches
- Falcon detections across the full kill chain (exec, persistence, privesc, evasion, C2)
- Endpoint process + network telemetry via Event Streams
- Identity-protection + credential-theft signals
- Custom IOA/IOC matches
- Containment + remediation events
MITRE ATT&CK coverage
Tactics this connector gives CyberCLI visibility into.
What it helps you catch
What you'd see in CyberCLI
illustrativeFalcon: credential theft (LSASS access) on FIN-SRV-02
- host
- FIN-SRV-02
- technique
- T1003.001 LSASS Memory
- tactic
- Credential Access
- falcon
- Critical
Routed to Warden (triage) → Knight (detection) → Marshal (response)
Suggested Contain host via Falcon (needs approval)
⛓ every step hash-chained · replayable
Close more of the kill chain
CrowdStrike covers 12 of 14 ATT&CK tactics. Pair it with these to widen coverage:
How to connect
CrowdStrike is on the connector roadmap but not yet bundled. The plan above describes what we'll ingest + how it maps to MITRE; install instructions land when the connector pack ships.
Tell us you'd use it → Pro tier customers get priority on connector prioritisation.
Hybrid. Detection telemetry comes from Falcon's cloud via API; triage, correlation, and audit happen in your sovereign SOC — your data plane stays intact at the decision layer.