CrowdStrike Falcon
Triage Falcon detections and respond to hosts conversationally - inventory sensors, isolate compromised machines, and run Real Time Response.
Dex connects to CrowdStrike Falcon so the security team can run endpoint detection and response from the conversation - inventory hosts and sensor status, triage detections through the unified Alerts API, network-contain (isolate) compromised machines and lift containment, and run Real Time Response diagnostic and remediation commands. Employees can check the protection state of their own device through Dex Go: is the sensor healthy, is the machine online, is it isolated, and what detections have fired. Available as an MSP global app - one shared parent credential, with each managed customer scoped by its member CID at the token level.
What Dex does with CrowdStrike Falcon
Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.
For admins (Dex Pro)
- Inventory hosts and read sensor status, OS version, agent version, last-seen, and containment state
- Triage detections through the unified Alerts API - filter by severity, status, tactic, technique, and host
- Update a detection's status (new, in_progress, reopened, closed), assign, tag, and comment
- Network-contain (isolate) a compromised host and lift containment - with approval
- Run Real Time Response diagnostic and remediation commands on a host - with approval
- Deploy as an MSP global app - one shared parent credential, each customer scoped by its member CID at the token level
For employees (self-service)
- Check whether the Falcon sensor is installed and healthy on your own device
- See whether your machine is online in Falcon and when it last checked in
- Find out if your device is network-isolated and why
- Review what detections have fired on your own device
Just ask Dex
Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.
Admin prompts
- >Show me new, high-severity detections from the last 24 hours
- >Find the host named "LAPTOP-01" and tell me its sensor status and containment state
- >Contain DESK-FIN-014 - we think it's compromised
- >Mark detection <composite_id> as in_progress and add a triage comment
- >Run a read-only RTR command to list running processes on SRV-APP-02
Employee prompts
- >Is the Falcon sensor healthy on my laptop?
- >Is my machine online in Falcon? When did it last check in?
- >Am I network-isolated right now, and why?
- >What detections have fired on my device?
Policy actions
Every action Dex can take on CrowdStrike Falcon is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.
| Action | What it does |
|---|---|
crowdstrike_check_device_status | Read status and sensor health for the user's own device |
crowdstrike_view_detections | View detections for the user's own device |
crowdstrike_update_detection_status | Change a detection's status (new, in_progress, closed) |
crowdstrike_contain_host | Network-contain (isolate) the user's own device |
crowdstrike_lift_containment | Lift network containment on the user's own device |
crowdstrike_rtr_command | Run an RTR diagnostic or remediation command on the user's own device |
How to configure CrowdStrike Falcon
Onboarding takes minutes. Dex validates your credentials before saving them.
Setup steps
- 1In the Falcon console, go to Support and resources > API clients and keys > Add to create an API client for Dex.
- 2Grant the client the scopes Dex needs: Hosts READ+WRITE (WRITE authorizes containment), Alerts READ+WRITE, and Real time response READ+WRITE. The RTR admin scope (runscript/put) is not needed.
- 3Copy the Client ID and Client Secret (the secret is shown once), and note your Falcon region (us-1, us-2, us-3, eu-1, us-gov-1, or us-gov-2).
- 4In Dex, enable the CrowdStrike Falcon integration and paste the region, Client ID, and Client Secret.
- 5Dex validates the credentials with a live read before saving. For MSPs, deploy as a global app and map each customer tenant to its member CID for per-tenant token-level scoping.
Credentials required
- cloud
- Falcon region slug (us-1, us-2, us-3, eu-1, us-gov-1, us-gov-2) or the full Falcon API host
- client_id
- OAuth2 API client id created under API clients and keys
- client_secret
- OAuth2 API client secret shown once when the API client is created
- member_cid
- Optional child tenant member CID (32-char lowercase hex) - when set, the token is minted scoped to that member CID for per-customer MSP isolation. Leave blank for the parent connection.
Requirements
- •A CrowdStrike Falcon subscription with an API client (OAuth2 client-credentials)
- •Scopes: Hosts READ+WRITE, Alerts READ+WRITE, Real time response READ+WRITE - the RTR admin tier (runscript/put) is out of scope
- •The correct Falcon region, since Falcon is region-partitioned and data on one cloud is unreachable from another
- •The legacy Detects API was decommissioned on 2025-09-30 - Dex triages detections through the unified Alerts API
- •For MSPs, deploy as a global app with per-customer scoping by member CID, enforced at the token level by CrowdStrike
Related integrations
- Device Management
Microsoft Intune
Manage Intune-enrolled devices, compliance, and apps from plain-language requests.
Learn more → - RMM & Endpoint
NinjaOne
Monitor and manage your NinjaOne fleet - device inventory, patch and antivirus status, alerts, and on-demand actions.
Learn more →
Device ManagementLansweeper
Bring your Lansweeper IT asset inventory into Dex so you can browse discovered assets in plain language.
Learn more →
See Dex run CrowdStrike Falcon
Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.