Skip to content
CrowdStrike logo

CrowdStrike integration

Monitoring & Observability · 3 actions · API key auth

Integrate CrowdStrike Identity Protection into workflows to search sensors, fetch sensor details by device ID, and run sensor aggregate queries against the Falcon API.

The ModuleX CrowdStrike integration lets a ModuleX agent operate CrowdStrike on your behalf, working across sensors, sensor details and sensor aggregates, directly from a plain-English request, using your organization's own CrowdStrike credentials. No pre-built workflow is required: the agent picks the right CrowdStrike action for the task.

CrowdStrike is a monitoring & observability platform. ModuleX adds the agent layer: ask for an outcome and it selects and runs the right CrowdStrike action. Or, when you want a repeatable process, the composer assembles a CrowdStrike workflow for you, streaming the nodes onto the canvas as it builds.

Drive CrowdStrike in plain English

Type what you want. A ModuleX agent picks the right CrowdStrike action, or chains several, and runs it. No workflow to build.

  • Show me the sensors that match what I describe
    resolves toquery_sensors
  • Get CrowdStrike Identity Protection sensor details for one or more device IDs
    resolves toget_sensor_details
  • Get CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query body
    resolves toget_sensor_aggregates

What you can automate with CrowdStrike

  • Query your sensors from a plain-English questionquery_sensors
  • Look up a sensor detail on demandget_sensor_details
  • Get CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query bodyget_sensor_aggregates

CrowdStrike integration at a glance

Actions available3
AuthenticationAPI key
Uses your own credentialsYes
Works with the assistantYes
Works in the composerYes
Multi-step / tool-chainingYes
Technical referenceView docs
Integration version1.0.0
Last updatedJul 2026

All 3 CrowdStrike actions

Sensors1
query_sensors
Search CrowdStrike Identity Protection sensors by hostname, IP, or related fields using a Falcon Query Language filter.
Sensor Details1
get_sensor_details
Get CrowdStrike Identity Protection sensor details for one or more device IDs.
Sensor Aggregates1
get_sensor_aggregates
Get CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query body.

See full parameters and response schemas in the CrowdStrike integration docs

Two ways to use CrowdStrike in ModuleX

Ask the assistantType what you want done and a ModuleX agent picks the right CrowdStrike action and runs it. No workflow to build.
Compose a workflowNeed it to happen every time? Describe the process and the composer wires CrowdStrike into a repeatable workflow you can run on a schedule, from chat, or as an API.

Connecting CrowdStrike

API keyCrowdStrike uses API-key authentication. You provide your own CrowdStrike secret key; ModuleX encrypts it and scopes it to your organization, so your whole team can use CrowdStrike without re-authenticating.

Step-by-step setup in the CrowdStrike docs

Works with CrowdStrike

Agents often chain CrowdStrike with these. Connect them once and one agent can use all of them in a single task.

CrowdStrike + ModuleX FAQ

  • A ModuleX agent can run any of CrowdStrike's 3 actions, across sensors, sensor details and sensor aggregates, from a plain-English request, using your organization's own CrowdStrike credentials.

Put CrowdStrike to work in ModuleX.

Connect CrowdStrike once with your own credentials and let your agent run all 3 actions on demand.

Last updated: Jul 2026Browse all 179 integrations