Security Operations CrowdStrike Falcon Intelligence integration release notes

  • Release version: Store
  • Updated June 11, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Security Operations CrowdStrike Falcon Intelligence integration release notes

    The Security Operations CrowdStrike Falcon Intelligence integration enhances threat detection and response capabilities within ServiceNow by connecting with CrowdStrike’s threat intelligence platform. The release notes document version updates, new features, fixes, and security improvements that enable customers to maintain an up-to-date and secure integration.

    Show full answer Show less

    Key Features

    • Query Range ACLs (v10.8.2): Added access control lists to restrict query ranges for enhanced security in CrowdStrike Intel queries.
    • Improved Threat Lookup (v10.8.1): Enhanced CrowdStrike Indicators API use by incorporating indicator types into threat lookups, boosting malicious confidence accuracy.
    • Strict Read-Only Fields (v10.8.0): Upgraded dictionary-level read-only fields to strict enforcement across all interfaces and scripts, preventing unauthorized changes and improving data integrity.
    • Workflow Migration (v10.7.0): Threat lookup workflows have been migrated to ServiceNow Flow Designer for streamlined automation and better maintainability.
    • Threat Lookup Automation Controls (v10.5.0): Introduced filtering to limit automated threat lookups on observables within a configurable time window and a finding calculator to map third-party results to supported system findings.
    • Authentication Update (v10.3.1): Transitioned to OAuth2 authentication requiring API Client ID and Secret setup for improved security during integration configuration.
    • Key Management Support (v10.3.3): Integration supports Key Management Framework for managing encryption keys related to password fields.
    • Additional API and Security Enhancements: Added CrowdStrike user string in outbound calls, expanded API permissions, and implemented improved password-related policies.

    Practical Impact for ServiceNow Customers

    These updates ensure that customers can securely and efficiently leverage CrowdStrike threat intelligence within their ServiceNow Security Operations workflows. Strict enforcement of read-only fields and OAuth2 authentication enhance security posture, while workflow migration and automation controls improve operational efficiency and accuracy in threat detection. Customers upgrading from older versions should note configuration changes, particularly the need to reconfigure authentication with OAuth2.

    Version history for the Security Operations CrowdStrike Falcon Intelligence integration on the ServiceNow Store.

    Important:
    For details on system requirements and family compatibility, view the application listing on the ServiceNow Store website.

    Version history

    Version 10.8.2 - June 2026
    New: Added query range ACLS for CrowdStrike Intel.
    Version 10.8.1 - March 2026
    Fixed: The CrowdStrike Indicators API now incorporates indicator types in threat lookup, resulting in improved malicious confidence.
    Version 10.8.0 - December 2025
    New: Upgraded all dictionary-level read-only fields to Strict Read-Only to improve security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
    Version 10.7.0 - August 2024
    Changed: Migrated Threat lookup workflow to flow designer.
    Version 10.5.2 - March 2024
    Fixed: Run threat lookup action for CrowdStrike Falcon Intelligence indicators now updates the results without the indicators.
    Version 10.5.1 - February 2023
    New: Added type changes to support the Security Incident Response workspace.
    Version 10.5.0 - November 2022
    • New:
      • Introducing a filter that allows running automated threat lookup on an observable only once within a configured duration. Any re-runs for the same observable will be skipped until the configured duration/period has passed.
      • Introducing a threat lookup finding calculator, which calculates the findings based on the responses received. For third-party integrations that provide the computed results, the threat lookup finding calculator maps the results to supported findings in the system.
    Version 10.4.1 - October 2021
    • New:
      • Add Crowdstrike User string in outbound HTTP calls
      • Added 'IOC Manager APIs' read and write permissions as required for the corresponding API key
    • Fixed: Added additional password-related policies
    Version 10.3.3 - December 2020
    Changed: With Key Management Framework plugin, developers will have an ability to manage keys used for Password2 fields through crypto module definition.
    Version 10.3.1 - October 2020
    Changed: The integration now supports OAUTH2 authentication. This update requires the user to enter the API Client ID and the API Client Secret to authenticate and complete the configuration. If you are upgrading the integration from a previous version, then you must delete the existing configuration and set up a new configuration. The new integration supports OAUTH2 authentication. This update requires you to enter the API Client ID and the API Client Secret to authenticate and complete the configuration.
    Version 10.0.0 - September 2020
    New: Implementation Flow to support the new capability framework (v2.0)
    Version 10.0.0 - March 2020
    New: Implementation Flow to support the new capability framework (v2.0)