rinoxRinox
pushpythonscheduledhand-curated

CrowdStrike Falcon → Cortex XSOAR (Palo Alto)

Create XSOAR incidents from CrowdStrike Falcon detections every 10 minutes

Polls CrowdStrike for new detections every 10 minutes and opens matching incidents in Cortex XSOAR with device, tactic, and technique preserved.

crowdstrikexsoardetectiongenericmoderate
Use case

Create new Cortex XSOAR incidents from CrowdStrike Falcon detections every 10 minutes, preserve tactic+technique+device context, dedupe by composite_id

No code yet. Click below to run the Rinox pipeline. The result is saved to this library entry — every future visitor gets it instantly.

Generate this integrationCustomize firstSign-in + free-tier limit apply

Useful?

Used by 0 teams · Viewed 4 times · Last validated 5/17/2026