What Are CrowdStrike Integrations?
CrowdStrike integrations are the apps, connectors, APIs, and partner-built solutions that connect the CrowdStrike Falcon platform with the rest of an organization’s security and IT stack. Instead of operating Falcon as a standalone endpoint or cloud security tool, customers can connect it to SIEMs, SOAR platforms, ticketing systems, identity providers, vulnerability management tools, cloud platforms, SaaS applications, data lakes, and automation workflows.
CrowdStrike’s integration strategy is also part of a larger platform and ecosystem play. The company has been steadily moving Falcon from a single-product security platform into a broader security operating layer where third-party vendors, resellers, developers, and customers can build around CrowdStrike. The CrowdStrike Marketplace is central to this strategy: it gives customers a way to discover, try, buy, and deploy partner solutions that are compatible with Falcon, while giving partners a new distribution channel.
In this article:
- Understanding CrowdStrike Integrations
- How Integrations Extend the CrowdStrike Falcon Platform
- Common Types of CrowdStrike Integrations
- Spotlight on Crowdstrike Integrations that Make a Difference: Application Control, Identity and Access, ITSM
- How to Evaluate CrowdStrike Integration Partners
Understanding CrowdStrike Integrations
How the integrations work
Crowdstrike integrations work by using Falcon’s APIs, event streams, data-ingestion pipelines, and partner connectors to move security data in both directions. Falcon can send detections, audit events, threat intelligence, and endpoint telemetry into tools such as SIEMs, SOARs, ITSM platforms, or data lakes. It can also ingest third-party data into Falcon Next-Gen SIEM, where that data is normalized, correlated, enriched with CrowdStrike threat intelligence, and used for detection, investigation, and response.
Ecosystem and growth
The ecosystem has grown quickly. CrowdStrike originally positioned its store as a way to open the Falcon platform to third-party security applications and reduce the need for multiple agents and disconnected tools.
CrowdStrike said its Marketplace grew in its first year to more than 260 listings from 140 technology partners. For Falcon Next-Gen SIEM specifically, CrowdStrike says the platform supports more than 500 independent software vendor data sources, with integrations available through the Marketplace and CrowdStrike’s GitHub resources. CrowdStrike also maintains a large developer surface area, including APIs, SDKs, Terraform modules, Foundry apps, AI integrations, and Next-Gen SIEM parsers.
How CrowdStrike’s ecosystem compares
CrowdStrike is not the largest integration ecosystem in cybersecurity by raw count. Fortinet, for example, has publicly reported more than 3,000 integrations across more than 400 technology partners.
However, CrowdStrike’s ecosystem is significant because of where it sits: Falcon is designed as a cloud-native, AI-driven security platform with deep endpoint, identity, cloud, threat intelligence, and SIEM data. The value of its integrations is therefore not just the number of connectors, but the ability to bring outside tools and data into a unified security workflow, helping teams detect threats faster, automate response, reduce tool silos, and extend Falcon across the enterprise security stack.
How Integrations Extend the CrowdStrike Falcon Platform
CrowdStrike Falcon integrations help organizations extend the platform beyond endpoint protection by connecting it with security, IT, and business systems across the environment. Through the CrowdStrike Marketplace, APIs, and partner ecosystem, organizations can share data, automate workflows, improve visibility, and build custom processes.
Key benefits of Crowdstrike integrations include:
- Broader security ecosystem: Falcon integrates with tools for endpoint management, identity security, cloud security, threat intelligence, SIEM, SOAR, and vulnerability management, allowing security teams to exchange data and actions across platforms rather than operating Falcon as an isolated tool.
- Improved visibility and context: Integrations with SIEM and security operations platforms centralize Falcon alerts, telemetry, and threat intelligence alongside data from cloud services, identity systems, network infrastructure, and business applications, helping analysts investigate incidents more effectively.
- Automation and response workflows: Falcon Fusion SOAR and third-party integrations support automated workflows that can enrich alerts, create tickets, isolate endpoints, disable accounts, and initiate remediation actions with minimal manual intervention.
- Custom integrations and development: APIs and tools such as the FalconPy SDK enable organizations to build custom workflows for reporting, compliance, asset management, incident response, and other internal processes while simplifying interaction with Falcon APIs.
Common Types of CrowdStrike Integrations
CrowdStrike offers a large set of integrations that help customers connect the Falcon platform with the tools they already use across security, IT, identity, cloud, collaboration, productivity, development, and business operations.
For Falcon Shield specifically, CrowdStrike lists many SaaS and technology integrations. These integrations are designed to help organizations connect critical SaaS apps, uncover misconfigurations, enforce governance, and route SaaS security data into broader security workflows such as SIEMs, vulnerability platforms, and response tools.
Identity, Access, Endpoint, and Device Management
| Integration | Basic purpose |
|---|---|
| Airlock Digital | Application control, allowlisting, and preventative endpoint protection |
| 1Password | Password and secrets management |
| Auth0 | Identity and authentication |
| Cisco Duo | Multi-factor authentication and identity security |
| CyberArk | Privileged access management |
| Google Endpoint Management | Endpoint and device management |
| Infinipoint | Device identity and security posture |
| Intune | Microsoft endpoint management |
| Jamf Cloud | Apple device management |
| JumpCloud | Identity, device, and access management |
| Kandji | Apple device management |
| LastPass | Password management |
| MobileIron | Mobile device management |
| Okta | Identity and access management |
| OneLogin | Identity and single sign-on |
| PingOne | Identity and access management |
| SailPoint | Identity governance |
| SimpleMDM | Apple mobile device management |
| VMware Workspace ONE | Unified endpoint management |
| Zoho ManageEngine Endpoint Central | Endpoint management |
| Zoho Mobile Device Management | Mobile device management |
Security, Risk, Vulnerability, and Infrastructure Protection
| Integration | Basic purpose |
|---|---|
| Akamai | Web, CDN, and application security |
| Automox | Endpoint patching and automation |
| Black Kite | Third-party cyber risk management |
| Cisco Meraki | Network management and security |
| Cisco Secure Endpoint | Endpoint security |
| Cisco Umbrella | DNS and cloud security |
| Cloudflare | Network, application, and cloud security |
| Cohesity | Data protection and resilience |
| Commvault | Backup and cyber resilience |
| Druva | SaaS and cloud data protection |
| FleetDM | Device visibility and endpoint management |
| Mimecast Email Security | Email security |
| Netskope | SSE, CASB, and cloud security |
| Prisma Access | Secure access service edge |
| Prisma Cloud | Cloud security posture and workload protection |
| Qualys | Vulnerability management |
| Qwiet | Application security |
| Rapid7 InsightVM | Vulnerability management |
| Rubrik | Data security and backup |
| RunZero | Asset inventory and exposure management |
| Snyk | Developer and application security |
| Sophos | Endpoint and security operations |
| Sysdig | Cloud and container security |
| Tenable.io | Vulnerability management |
| Trend Micro | Endpoint and cloud security |
| Wiz | Cloud security |
| Zscaler | Zero trust and secure access |
SIEM, Observability, Data, Analytics, and Reporting
| Integration | Basic purpose |
|---|---|
| ArcGIS | Geographic data and mapping |
| Atlas Mongo DB | Database and cloud data platform |
| Databricks | Data lakehouse and analytics |
| Datadog | Observability and monitoring |
| dbt Cloud | Data transformation |
| Dynatrace | Observability and application monitoring |
| Fabric | Data and analytics platform |
| Fivetran | Data movement and pipelines |
| GCP | Cloud platform |
| Google Analytics | Web and product analytics |
| Logz.io | Observability and log analytics |
| Looker | Business intelligence |
| New Relic | Observability and monitoring |
| Snowflake | Cloud data platform |
| Sumo Logic | Log analytics and SIEM-style observability |
| Tableau | Business intelligence and dashboards |
DevOps, Engineering, Cloud, and Automation
| Integration | Basic purpose |
|---|---|
| Abstract | Design workflow and version control |
| Azure DevOps | DevOps planning and pipelines |
| Bitbucket | Source code management |
| Chrome Extensions | Browser extension visibility |
| Chrome Web Store | Browser extension ecosystem |
| Fastly | Edge cloud and CDN |
| GitHub | Source code management and DevOps |
| GitLab | Source code management and DevOps |
| Gitpod | Cloud development environments |
| Harness.io | Software delivery and CI/CD |
| Jfrog | Software supply chain and artifact management |
| LaunchDarkly | Feature management |
| Make | Workflow automation |
| Mend | Software composition and application security |
| MuleSoft | API and integration platform |
| Netlify | Web development and hosting |
| Postman | API development and testing |
| PowerApps | Low-code application development |
| Sentry.io | Application performance and error monitoring |
| Terraform | Infrastructure as code |
| Tines | Security automation |
| UiPath | Robotic process automation |
| Unqork | No-code application platform |
| Workato | Enterprise automation |
| Zapier | Workflow automation |
| WPEngine | Web hosting and WordPress platform |
Collaboration, Productivity, Documents, and Knowledge Management
| Integration | Basic purpose |
|---|---|
| Adobe Sign | E-signature |
| Adobe User Management | Adobe user and license management |
| Asana | Work management |
| Box | Cloud content management |
| Calendly | Scheduling |
| Canva | Design collaboration |
| Confluence | Knowledge management |
| Citrix ShareFile | Secure file sharing |
| Cybozu | Collaboration and business applications |
| Docebo | Learning management |
| DocuSign | E-signature |
| Document360 | Knowledge base software |
| Dropbox | Cloud file storage |
| Egnyte | Content governance and file sharing |
| Envoy | Workplace management |
| Figma | Design collaboration |
| Google Drive | Cloud file storage |
| Google Workspace | Productivity and collaboration suite |
| iManage | Document and knowledge management |
| Island Enterprise Browser | Enterprise browser |
| Jira | Issue and project tracking |
| Lucidchart | Diagramming |
| Microsoft 365 | Productivity and collaboration suite |
| Miro | Online whiteboarding |
| Monday | Work management |
| MoreApp | Digital forms |
| Mural | Visual collaboration |
| Notion | Workspace and knowledge management |
| Nulab Backlog | Project and issue tracking |
| OneDrive | Cloud file storage |
| PandaDoc | Document automation |
| SharePoint | Document management and intranet |
| Shortcut (formerly ClubHouse) | Software project management |
| Slack | Team messaging |
| Smartsheet | Work management |
| Smartsuite | Work management |
| Status Hero | Team status updates |
| Teams | Collaboration and messaging |
| Teamwork | Project management |
| Trello | Kanban project management |
| Webex | Meetings and collaboration |
| Wrike | Work management |
| Zoom | Video meetings and collaboration |
Sales, Marketing, Customer, HR, Finance, and Business Apps
| Integration | Basic purpose |
|---|---|
| Aha! | Product roadmap management |
| Apollo.io | Sales intelligence |
| Bamboo HR | Human resources management |
| Chorus | Sales conversation intelligence |
| Coupa | Spend management |
| Expensify | Expense management |
| Freshservice | IT service management |
| Gong | Revenue intelligence |
| Google Ads | Digital advertising |
| Greenhouse | Recruiting |
| Hibob | HR management |
| Hubspot | CRM and marketing |
| Intercom | Customer messaging |
| KnowBe4 | Security awareness training |
| Professional network and business platform | |
| Marketo | Marketing automation |
| Meta | Social and business platform |
| Meta Workplace | Workplace collaboration |
| NetSuite | ERP and business management |
| Outreach | Sales engagement |
| PagerDuty | Incident response and on-call management |
| Personio | HR management |
| Pipedrive | CRM |
| Salesforce | CRM |
| Salesforce Marketing Cloud | Marketing automation |
| SAP BTP | Business technology platform |
| SAP Concur | Travel and expense management |
| SAP S/4 Hana Cloud | Cloud ERP |
| SAP Success Factors | HR management |
| SendGrid | Email delivery |
| ServiceNow | IT service management |
| Veeva | Life sciences cloud applications |
| Vidyard | Video marketing and sales |
| Workday | HR, finance, and workforce management |
| Zendesk | Customer support |
AI, Data Science, and Emerging Technology
| Integration | Basic purpose |
|---|---|
| Anthropic | AI platform |
| ChatGPT Enterprise | Enterprise AI assistant |
| Hugging Face | AI and machine learning platform |
Spotlight on Crowdstrike Integrations that Make a Difference: Application Control, Identity and Access, ITSM
Application Control: Moving From Detection-Only to Prevention-First Security
Spotlight integration: Airlock Digital
Application control shifts the focus from detecting threats after they occur to preventing them from executing in the first place. By integrating application control with CrowdStrike Falcon, organizations can enforce policies that block unauthorized or unknown applications from running on endpoints.
This prevention-first approach reduces reliance on reactive detection and accelerates containment of new or unknown threats, including those that evade traditional antivirus solutions:
- Application control and allowlisting enables policy enforcement: Security teams can define which applications are permitted to run based on digital signatures, trusted publishers, or other approval criteria. When combined with Falcon telemetry and threat intelligence, these policies can be enforced quickly, reducing the attack surface and preventing malware, unauthorized tools, lateral movement, and other post-exploitation activities.
- Deny by Default security model: Application control is commonly deployed using a Deny by Default approach, where applications are blocked unless they have been explicitly approved. By defining trusted software rather than attempting to identify every malicious file, organizations reduce their reliance on signatures, reputation services, and detection engines while eliminating many potential attack paths.
- Gradual implementation with Falcon visibility: CrowdStrike Falcon enables organizations to manage Deny by Default policies alongside endpoint visibility and threat intelligence. Security teams can monitor application usage, identify commonly used software, build trusted application lists, and transition to enforcement in stages to minimize operational disruption while maintaining visibility into policy violations.
- Ransomware prevention: Application control helps prevent ransomware by blocking malicious executables and restricting the use of system tools that attackers often abuse to encrypt files. Only approved applications and processes are allowed to execute, reducing the likelihood of successful ransomware attacks.
- Protection against Living off the Land (LOTL) techniques: Attackers frequently use native utilities such as PowerShell and WMI to evade detection. Application control policies can restrict access to these tools so they are available only to authorized users or processes. Falcon telemetry can then be used to detect, investigate, and respond to unauthorized execution attempts.
Identity and Access Context: Connecting Endpoint Risk to User Access Decisions
Spotlight integration: Auth0
Identity integrations help security teams connect endpoint security with the users, accounts, and access decisions behind each session. In modern attacks, the endpoint is often only one part of the story: attackers may use stolen credentials, compromised sessions, unmanaged devices, or risky access patterns to move through the environment. By integrating CrowdStrike Falcon with identity providers and access management platforms, organizations can bring user and device context into the same workflow.
This makes identity integrations especially useful for Zero Trust programs, remote work security, and investigations where the key question is not only “what happened on the device?” but also “who was using it, what did they access, and should that access continue?”
- User and device context improves access decisions: Identity integrations can combine information about the user, the device, and the security posture of the endpoint. This helps organizations make more informed access decisions, such as allowing access from a trusted and healthy device while challenging, restricting, or blocking access from a risky one.
- Faster response to identity-based threats: When identity actions are connected to Falcon workflows, security teams can respond to suspicious activity more quickly. For example, automated workflows can help reset passwords, terminate sessions, or trigger additional identity controls when Falcon detects suspicious behavior tied to a user or device.
- Reduced gap between identity and endpoint teams: Identity teams and endpoint security teams often work in separate tools. Integrations help close that gap by connecting account activity, access posture, and endpoint telemetry. This gives analysts a clearer view of whether a security event is isolated to a machine or connected to broader account compromise.
- Support for Zero Trust enforcement: Identity integrations support Zero Trust by helping organizations continuously evaluate trust instead of assuming that a successful login is enough. Access can be influenced by device health, endpoint risk, user behavior, and real-time security signals.
- Better investigations and auditability: When identity and endpoint data are connected, investigations become easier to reconstruct. Analysts can see which user was associated with an endpoint, what access decisions were made, and whether additional controls were triggered during the incident.
ITSM and Incident Response Automation: Turning Falcon Alerts Into Operational Action
Spotlight integration: PagerDuty
IT service management and incident response integrations help security teams move from detection to coordinated remediation. When CrowdStrike Falcon identifies a threat, the alert still needs to become operational work: someone has to investigate it, assign ownership, track progress, document actions, and close the loop. ITSM integrations help connect Falcon detections with the systems many organizations already use to manage incidents, service requests, and remediation tasks.
This makes ITSM automation a strong complement to application control. Application control helps prevent unauthorized execution, while ITSM and response integrations help organizations manage the alerts, exceptions, approvals, and remediation workflows that follow.
- Automatic ticket creation: Falcon alerts, detections, or identity incidents can be routed into ITSM systems so incidents are created automatically. This reduces manual work and helps ensure that important security events are not lost in email, chat, or dashboard-only workflows.
- Clear ownership and tracking: Once a Falcon detection becomes a ticket, teams can assign an owner, set priority, add evidence, track remediation, and document resolution. This is especially useful for larger organizations where security, IT, endpoint, and identity teams may all need to coordinate.
- Faster remediation workflows: ITSM integrations can help security teams move faster by connecting detection data with remediation processes. For example, an endpoint alert can trigger a ticket for IT to isolate, patch, reimage, or review a device, while security analysts continue their investigation in Falcon.
- Better collaboration between security and IT: Security tools identify risk, but IT teams often own the systems that need to be fixed. ITSM integrations create a shared operational workflow so both teams can work from the same incident record instead of switching between disconnected tools.
- Improved reporting and compliance: Ticket-based workflows also improve reporting. Organizations can show when an alert was created, who handled it, what remediation steps were taken, and when the issue was resolved. This creates a stronger audit trail for internal governance, compliance, and post-incident review.
How to Evaluate CrowdStrike Integration Partners
Security Value
When evaluating CrowdStrike integration partners, the first consideration should be the security value the integration adds to the Falcon environment. A strong integration should improve detection, prevention, investigation, or response outcomes rather than simply exchanging data between systems.
Organizations should look for partners that help security teams reduce risk in practical ways, such as enriching Falcon detections with additional context, automating containment actions, improving vulnerability prioritization, or strengthening controls around identity, endpoints, cloud workloads, or applications.
Operational Fit
Operational fit is another factor because an integration must work within the organization’s existing security processes, tools, and staffing model. A useful integration should reduce complexity rather than add another system that analysts must manually monitor or maintain.
Security teams should evaluate how easily the integration fits into current workflows, including alert triage, ticketing, incident response, vulnerability remediation, compliance reporting, and executive dashboards.
Policy Control and Flexibility
Policy control and flexibility are important for integrations that influence endpoint behavior, application execution, identity access, or automated response actions. Organizations should evaluate whether the integration allows granular policy configuration based on users, groups, devices, applications, risk levels, locations, or business units. This helps security teams apply stricter controls in high-risk environments while allowing more flexible policies where business operations require them.
Marketplace Availability and Vendor Alignment
Marketplace availability is a practical indicator of whether an integration is supported, discoverable, and intended to work with the CrowdStrike Falcon platform. Integrations listed in the CrowdStrike Marketplace are easier for organizations to evaluate because they are presented as part of the CrowdStrike partner ecosystem. Marketplace availability can also simplify discovery, procurement conversations, and validation of supported use cases.
Vendor alignment is equally important. Organizations should assess whether the partner’s roadmap, security philosophy, support model, and technical approach align with their CrowdStrike strategy. A good partner should complement Falcon’s capabilities rather than duplicate them or create conflicting workflows.
How to Combine Application Control With CrowdStrike Falcon Using Airlock Digital
Airlock Digital integrates with CrowdStrike Falcon to combine the proactive protection of application control and allowlisting with CrowdStrike's advanced threat detection and response. Together, application control and EDR deliver a robust, Defense-in-Depth security strategy, preventing malicious applications from executing while enabling rapid response to potential threats across IT, OT, and cloud environments.
Key capabilities of Airlock Digital + CrowdStrike:
- Native integration: Airlock Digital's proactive application control is combined with CrowdStrike's endpoint detection and response, so organizations can block and respond to threats seamlessly from a single, unified security posture.
- Event correlation: Allowlisting events are correlated with CrowdStrike telemetry, giving security teams a comprehensive view of endpoint activity and deeper visibility into what is executing on each device.
- Streamlined agent management: Teams can deploy and manage Airlock Digital agents directly through the CrowdStrike Falcon console, making rapid implementation of a Deny by Default security posture a reality.
- Reduced alert volume: By proactively preventing the execution of all untrusted code, Airlock Digital reduces the volume of alerts and the number of incidents that require investigation and response.
- Streamlined incident response: Because Airlock Digital prevents all unauthorized file and application execution, fewer incidents occur in the first place, freeing analysts to focus on genuine threats.
- Compliance support: Centralized logging and reporting across both platforms simplifies regulatory adherence and strengthens audit readiness.
Discover how proactive application control and EDR work better together: learn more about the Airlock Digital integration for CrowdStrike.