In n8n, click the "Add workflow" button in the Workflows tab to create a new workflow. Add the starting point – a trigger on when your workflow should run: an app event, a schedule, a webhook call, another workflow, an AI chat, or a manual trigger. Sometimes, the HTTP Request node might already serve as your starting point.
Create custom CrowdStrike and VirusTotal workflows by choosing triggers and actions. Nodes come with global operations and settings, as well as app-specific parameters that can be configured. You can also use the HTTP Request node to query data from any app or service with a REST API.
GetDeviceDetails
Retrieve device details for a specific host.
QueryDevicesByFilter
Query devices by filter.
PerformDeviceAction
Perform a device action such as 'Contain' or 'Lift Containment'.
GetDeviceSnapshots
Get snapshots of device status.
GetDeviceDetailsById
Retrieve device details for a specific host by device ID.
GetAlerts
Retrieve a list of alerts.
GetAlertDetails
Retrieve details of a specific alert.
AcknowledgeAlert
Acknowledge a specific alert.
UpdateAlert
Update details of a specific alert.
DeleteAlert
Delete a specific alert.
QueryDetections
Retrieve detections based on provided query parameters.
GetDetectionDetails
Retrieve details for a specific detection.
UpdateDetection
Update details of a specific detection.
AcknowledgeDetection
Acknowledge a specific detection.
DeleteDetection
Delete a specific detection.
GetUsers
Retrieve a list of users.
GetUserDetails
Retrieve details of a specific user.
CreateUser
Create a new user.
UpdateUser
Update details of a specific user.
DeleteUser
Delete a specific user.
To set up CrowdStrike integration, add the HTTP Request node to your workflow canvas and authenticate it using a predefined credential type. This allows you to perform custom operations, without additional authentication setup. The HTTP Request node makes custom API calls to CrowdStrike to query the data you need using the URLs you provide.
Take a look at the CrowdStrike official documentation to get a full list of all API endpoints
GetFileReport
Retrieve the latest report on a file.
ScanFile
Send a file for scanning.
GetFileBehaviours
Retrieve a file's behaviors observed during sandbox execution.
GetFileComments
Retrieve comments on a file.
AddFileComment
Post a comment on a file.
GetURLReport
Retrieve the latest report on a URL.
ScanURL
Send a URL for scanning.
GetURLComments
Retrieve comments on a URL.
AddURLComment
Post a comment on a URL.
GetURLVotes
Retrieve votes on a URL.
GetDomainReport
Retrieve the latest report on a domain.
GetDomainComments
Retrieve comments on a domain.
AddDomainComment
Post a comment on a domain.
GetDomainResolutions
Retrieve the resolutions of a domain.
GetDomainSiblings
Retrieve the siblings of a domain.
GetIPAddressReport
Retrieve the latest report on an IP address.
GetIPAddressComments
Retrieve comments on an IP address.
AddIPAddressComment
Post a comment on an IP address.
GetIPAddressResolutions
Retrieve the resolutions of an IP address.
GetIPAddressHistorical
Retrieve the historical data of an IP address.
To set up VirusTotal integration, add the HTTP Request node to your workflow canvas and authenticate it using a predefined credential type. This allows you to perform custom operations, without additional authentication setup. The HTTP Request node makes custom API calls to VirusTotal to query the data you need using the URLs you provide.
Take a look at the VirusTotal official documentation to get a full list of all API endpoints
The world's most popular workflow automation platform for technical teams including
Build complex workflows, really fast