CrowdStrike is our main EDR and I want to start automating some of the response actions we take based on detections, things like isolating a host or pulling process details. I’ve heard Tines has good support for CrowdStrike but I’m not sure where to start. What’s the smoothest path to getting the two connected?
Tines has dedicated CrowdStrike integrations which you can see here. Authentication uses CrowdStrike’s OAuth 2.0 client credentials flow. You store your client ID and secret as Tines credentials, and the platform handles token requests and refreshes automatically from there.
Tines also has lots of examples with CrowdStrike in its Story Library, which is another easy starting point. The library includes pre-built actions and templates covering common use cases like isolating hosts, searching detections, and pulling endpoint details. You can import these directly and adapt them rather than building from scratch.