Skip to content

[Request] Crowdstrike additional third-party response actions #6365

Closed
@raqueltabuyo

Description

@raqueltabuyo

What can we change to make the docs better?

Description
We are adding new third-party actions to Crowdstrike response actions, which will allow users to execute remote commands using Crowdstrike agent through Elastic Security.

This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/third-party-actions.html

Background & resources
PRs:

Issues/metas: https://github.com/elastic/security-team/issues/10873
Point of contact: @caitlinbetz @tomsonpl @raqueltabuyo @ashokaditya @paul-tavares
Test environments:

Doc URL

This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/third-party-actions.html
Github issue link(s)/Other resources:
https://github.com/elastic/security-team/issues/10873

Which documentation set needs improvement?

ESS and serverless

Software version

ESS release
8.18

Serverless release
January 27, 2025

Feature differences
Feature will be the same in serverless/ESS

ESS release: 8.18

API docs impact
TBD

Prerequisites, privileges, feature flags
ESS & Serverless, Kibana privileges:

Security solution privilege: TBD

Actions and Connectors privilege:: EDR Connectors

Metadata

Metadata

Labels

Docset: ESSIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityEffort: MediumIssues that take moderate but not substantial time to completePriority: MediumIssues that have relevance, but aren't urgentTeam: EDR WorkflowsFormerly Defend Workflows, Onboarding and Lifecycle Managementv8.18.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions