Dex
CrowdStrike Falcon logo
Security & Backup

CrowdStrike Falcon

Triage Falcon detections and respond to hosts conversationally - inventory sensors, isolate compromised machines, and run Real Time Response.

Dex connects to CrowdStrike Falcon so the security team can run endpoint detection and response from the conversation - inventory hosts and sensor status, triage detections through the unified Alerts API, network-contain (isolate) compromised machines and lift containment, and run Real Time Response diagnostic and remediation commands. Employees can check the protection state of their own device through Dex Go: is the sensor healthy, is the machine online, is it isolated, and what detections have fired. Available as an MSP global app - one shared parent credential, with each managed customer scoped by its member CID at the token level.

What Dex does with CrowdStrike Falcon

Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.

A

For admins (Dex Pro)

  • Inventory hosts and read sensor status, OS version, agent version, last-seen, and containment state
  • Triage detections through the unified Alerts API - filter by severity, status, tactic, technique, and host
  • Update a detection's status (new, in_progress, reopened, closed), assign, tag, and comment
  • Network-contain (isolate) a compromised host and lift containment - with approval
  • Run Real Time Response diagnostic and remediation commands on a host - with approval
  • Deploy as an MSP global app - one shared parent credential, each customer scoped by its member CID at the token level
E

For employees (self-service)

  • Check whether the Falcon sensor is installed and healthy on your own device
  • See whether your machine is online in Falcon and when it last checked in
  • Find out if your device is network-isolated and why
  • Review what detections have fired on your own device

Just ask Dex

Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.

Admin prompts

  • >Show me new, high-severity detections from the last 24 hours
  • >Find the host named "LAPTOP-01" and tell me its sensor status and containment state
  • >Contain DESK-FIN-014 - we think it's compromised
  • >Mark detection <composite_id> as in_progress and add a triage comment
  • >Run a read-only RTR command to list running processes on SRV-APP-02

Employee prompts

  • >Is the Falcon sensor healthy on my laptop?
  • >Is my machine online in Falcon? When did it last check in?
  • >Am I network-isolated right now, and why?
  • >What detections have fired on my device?

Policy actions

Every action Dex can take on CrowdStrike Falcon is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.

ActionWhat it does
crowdstrike_check_device_statusRead status and sensor health for the user's own device
crowdstrike_view_detectionsView detections for the user's own device
crowdstrike_update_detection_statusChange a detection's status (new, in_progress, closed)
crowdstrike_contain_hostNetwork-contain (isolate) the user's own device
crowdstrike_lift_containmentLift network containment on the user's own device
crowdstrike_rtr_commandRun an RTR diagnostic or remediation command on the user's own device

How to configure CrowdStrike Falcon

Onboarding takes minutes. Dex validates your credentials before saving them.

Setup steps

  1. 1
    In the Falcon console, go to Support and resources > API clients and keys > Add to create an API client for Dex.
  2. 2
    Grant the client the scopes Dex needs: Hosts READ+WRITE (WRITE authorizes containment), Alerts READ+WRITE, and Real time response READ+WRITE. The RTR admin scope (runscript/put) is not needed.
  3. 3
    Copy the Client ID and Client Secret (the secret is shown once), and note your Falcon region (us-1, us-2, us-3, eu-1, us-gov-1, or us-gov-2).
  4. 4
    In Dex, enable the CrowdStrike Falcon integration and paste the region, Client ID, and Client Secret.
  5. 5
    Dex validates the credentials with a live read before saving. For MSPs, deploy as a global app and map each customer tenant to its member CID for per-tenant token-level scoping.

Credentials required

cloud
Falcon region slug (us-1, us-2, us-3, eu-1, us-gov-1, us-gov-2) or the full Falcon API host
client_id
OAuth2 API client id created under API clients and keys
client_secret
OAuth2 API client secret shown once when the API client is created
member_cid
Optional child tenant member CID (32-char lowercase hex) - when set, the token is minted scoped to that member CID for per-customer MSP isolation. Leave blank for the parent connection.

Requirements

  • A CrowdStrike Falcon subscription with an API client (OAuth2 client-credentials)
  • Scopes: Hosts READ+WRITE, Alerts READ+WRITE, Real time response READ+WRITE - the RTR admin tier (runscript/put) is out of scope
  • The correct Falcon region, since Falcon is region-partitioned and data on one cloud is unreachable from another
  • The legacy Detects API was decommissioned on 2025-09-30 - Dex triages detections through the unified Alerts API
  • For MSPs, deploy as a global app with per-customer scoping by member CID, enforced at the token level by CrowdStrike

See Dex run CrowdStrike Falcon

Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.