Myrmex connects on demand and reads (and acts) in real time — nothing from Falcon is stored on the Myrmex side.
What Myrmex Can Do
Detections & incidents
Read Falcon alerts and incidents live and triage them in Alerts.
Hosts & containment
Read the host inventory and, on approval, contain or release endpoints.
Real Time Response
Run RTR actions and manage custom IOCs/IOAs and policies with Hydra.
Vulnerabilities & sandbox
Pull Spotlight vulnerabilities and Falcon sandbox context to enrich investigations.
Before You Start
- A Falcon account with permission to create API clients (Falcon Administrator).
- Your Falcon cloud region / base URL.
- A Collector that can reach the Falcon API over outbound HTTPS.
Step 1 — Create the Credential in CrowdStrike Falcon
1
Open API clients and keys
In the Falcon console, go to Support and resources → Resources and tools → API clients and keys.
2
Create an API client
Click Add new API client. Give it a name and grant the API scopes Myrmex needs — Read scopes to query detections, incidents, hosts, Spotlight, and IOCs, and Write scopes for response (Real Time Response, host containment, IOC management, policies).
3
Copy the credentials
Copy the Client ID and Client Secret now — the secret is shown only once. Note your Falcon base URL.