Save yourself the work of writing custom integrations for CrowdStrike and Currents and use n8n instead. Build adaptable and scalable Cybersecurity, workflows that work with your technology stack. All within a building experience you will love.

In n8n, click the "Add workflow" button in the Workflows tab to create a new workflow. Add the starting point – a trigger on when your workflow should run: an app event, a schedule, a webhook call, another workflow, an AI chat, or a manual trigger. Sometimes, the HTTP Request node might already serve as your starting point.
Create custom CrowdStrike and Currents workflows by choosing triggers and actions. Nodes come with global operations and settings, as well as app-specific parameters that can be configured. You can also use the HTTP Request node to query data from any app or service with a REST API.
GetDeviceDetails
Retrieve device details for a specific host.
QueryDevicesByFilter
Query devices by filter.
PerformDeviceAction
Perform a device action such as 'Contain' or 'Lift Containment'.
GetDeviceSnapshots
Get snapshots of device status.
GetDeviceDetailsById
Retrieve device details for a specific host by device ID.
GetAlerts
Retrieve a list of alerts.
GetAlertDetails
Retrieve details of a specific alert.
AcknowledgeAlert
Acknowledge a specific alert.
UpdateAlert
Update details of a specific alert.
DeleteAlert
Delete a specific alert.
QueryDetections
Retrieve detections based on provided query parameters.
GetDetectionDetails
Retrieve details for a specific detection.
UpdateDetection
Update details of a specific detection.
AcknowledgeDetection
Acknowledge a specific detection.
DeleteDetection
Delete a specific detection.
GetUsers
Retrieve a list of users.
GetUserDetails
Retrieve details of a specific user.
CreateUser
Create a new user.
UpdateUser
Update details of a specific user.
DeleteUser
Delete a specific user.
To set up CrowdStrike integration, add the HTTP Request node to your workflow canvas and authenticate it using a predefined credential type. This allows you to perform custom operations, without additional authentication setup. The HTTP Request node makes custom API calls to CrowdStrike to query the data you need using the URLs you provide.
Take a look at the CrowdStrike official documentation to get a full list of all API endpoints
Create
Create a new action for a project
Delete
Archive an action (soft delete)
Disable
Deactivate an active action
Enable
Reactivate a disabled action
Get
Get a single action by ID
Get Many
Get many actions for a project
Update
Update an existing action
Get
Get a spec file execution instance with full test results
Get
Get a project by ID
Get Many
Get many projects
Get Insights
Get project insights and metrics
Cancel
Cancel a run in progress
Cancel by GitHub CI
Cancel a run by GitHub Actions workflow run ID
Delete
Delete a run and all associated data
Find
Find a run by project and filters
Get
Get a run by ID
Get Many
Get many runs for a project
Reset
Reset failed specs for re-execution on specified machines
Generate
Generate a unique test signature
Get Many
Get aggregated spec file metrics for a project
Get Many
Get aggregated test metrics for a project
Get Many
Get historical test execution results for a specific test signature
The world's most popular workflow automation platform for technical teams including
Build complex workflows, really fast
