Skip to main content
Connect CrowdStrike Falcon so Myrmex can read detections and incidents, your host inventory, manage custom indicators, and — with approval — run response actions. Myrmex queries the Falcon REST API in real time using an OAuth2 API client, through a Collector.
Myrmex connects on demand and reads (and acts) in real time — nothing from Falcon is stored on the Myrmex side.

What Myrmex Can Do

Detections & incidents

Read Falcon alerts and incidents live and triage them in Alerts.

Hosts & containment

Read the host inventory and, on approval, contain or release endpoints.

Real Time Response

Run RTR actions and manage custom IOCs/IOAs and policies with Hydra.

Vulnerabilities & sandbox

Pull Spotlight vulnerabilities and Falcon sandbox context to enrich investigations.

Before You Start

  • A Falcon account with permission to create API clients (Falcon Administrator).
  • Your Falcon cloud region / base URL.
  • A Collector that can reach the Falcon API over outbound HTTPS.

Step 1 — Create the Credential in CrowdStrike Falcon

1

Open API clients and keys

In the Falcon console, go to Support and resources → Resources and tools → API clients and keys.
2

Create an API client

Click Add new API client. Give it a name and grant the API scopes Myrmex needs — Read scopes to query detections, incidents, hosts, Spotlight, and IOCs, and Write scopes for response (Real Time Response, host containment, IOC management, policies).
3

Copy the credentials

Copy the Client ID and Client Secret now — the secret is shown only once. Note your Falcon base URL.
Start with read-only scopes for analysis, and add write scopes only when you want the agents to take action.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → CrowdStrike Falcon, then fill in:

Connect

Click Connect to validate the OAuth2 client. Falcon then appears under Environment → Integrations, and you can triage its detections — queried live — in Alerts.