CrowdStrike
CrowdStrike detects endpoint threats and holds the intelligence behind them. Antimetal reads detections and host data to tell a security event apart from an operational failure.
What Antimetal does with CrowdStrike
- Read endpoint detections and their severity
- Read incidents and affected hosts
- Query threat intelligence for a detected indicator
- Distinguish a security event from an operational failure
Connecting CrowdStrike
Go to Integrations in the Antimetal dashboard and find CrowdStrike.
Click Connect and follow the prompt. Depending on the tool this is either an OAuth handoff or a read-only credential you generate in CrowdStrike and paste into Antimetal.
Once CrowdStrike shows as connected, Antimetal begins pulling from it during investigations. No further configuration is required.
Permissions and access
Antimetal connects over MCP with read-only access and performs no write operations. The exact scopes depend on the credential you issue in the vendor tool — grant read access only.
All tenant data is processed in isolated environments. See security and compliance for details.
Need help?
Contact us via Slack or at support@antimetal.com.
