Security Operations CrowdStrike Falcon Intelligence integration release notes
Summarize
Summary of Security Operations CrowdStrike Falcon Intelligence integration release notes
The Security Operations CrowdStrike Falcon Intelligence integration enhances threat detection and response capabilities within ServiceNow by connecting with CrowdStrike’s threat intelligence platform. The release notes document version updates, new features, fixes, and security improvements that enable customers to maintain an up-to-date and secure integration.
Show less
Key Features
- Query Range ACLs (v10.8.2): Added access control lists to restrict query ranges for enhanced security in CrowdStrike Intel queries.
- Improved Threat Lookup (v10.8.1): Enhanced CrowdStrike Indicators API use by incorporating indicator types into threat lookups, boosting malicious confidence accuracy.
- Strict Read-Only Fields (v10.8.0): Upgraded dictionary-level read-only fields to strict enforcement across all interfaces and scripts, preventing unauthorized changes and improving data integrity.
- Workflow Migration (v10.7.0): Threat lookup workflows have been migrated to ServiceNow Flow Designer for streamlined automation and better maintainability.
- Threat Lookup Automation Controls (v10.5.0): Introduced filtering to limit automated threat lookups on observables within a configurable time window and a finding calculator to map third-party results to supported system findings.
- Authentication Update (v10.3.1): Transitioned to OAuth2 authentication requiring API Client ID and Secret setup for improved security during integration configuration.
- Key Management Support (v10.3.3): Integration supports Key Management Framework for managing encryption keys related to password fields.
- Additional API and Security Enhancements: Added CrowdStrike user string in outbound calls, expanded API permissions, and implemented improved password-related policies.
Practical Impact for ServiceNow Customers
These updates ensure that customers can securely and efficiently leverage CrowdStrike threat intelligence within their ServiceNow Security Operations workflows. Strict enforcement of read-only fields and OAuth2 authentication enhance security posture, while workflow migration and automation controls improve operational efficiency and accuracy in threat detection. Customers upgrading from older versions should note configuration changes, particularly the need to reconfigure authentication with OAuth2.
Version history for the Security Operations CrowdStrike Falcon Intelligence integration on the ServiceNow Store.
Version history
- Version 10.8.2 - June 2026
- New: Added query range ACLS for CrowdStrike Intel.
- Version 10.8.1 - March 2026
- Fixed: The CrowdStrike Indicators API now incorporates indicator types in threat lookup, resulting in improved malicious confidence.
- Version 10.8.0 - December 2025
- New: Upgraded all dictionary-level read-only fields to Strict Read-Only to improve security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
- Version 10.7.0 - August 2024
- Changed: Migrated Threat lookup workflow to flow designer.
- Version 10.5.2 - March 2024
- Fixed: Run threat lookup action for CrowdStrike Falcon Intelligence indicators now updates the results without the indicators.
- Version 10.5.1 - February 2023
- New: Added type changes to support the Security Incident Response workspace.
- Version 10.5.0 - November 2022
-
- New:
- Introducing a filter that allows running automated threat lookup on an observable only once within a configured duration. Any re-runs for the same observable will be skipped until the configured duration/period has passed.
- Introducing a threat lookup finding calculator, which calculates the findings based on the responses received. For third-party integrations that provide the computed results, the threat lookup finding calculator maps the results to supported findings in the system.
- New:
- Version 10.4.1 - October 2021
-
- New:
- Add Crowdstrike User string in outbound HTTP calls
- Added 'IOC Manager APIs' read and write permissions as required for the corresponding API key
- Fixed: Added additional password-related policies
- New:
- Version 10.3.3 - December 2020
- Changed: With Key Management Framework plugin, developers will have an ability to manage keys used for Password2 fields through crypto module definition.
- Version 10.3.1 - October 2020
- Changed: The integration now supports OAUTH2 authentication. This update requires the user to enter the API Client ID and the API Client Secret to authenticate and complete the configuration. If you are upgrading the integration from a previous version, then you must delete the existing configuration and set up a new configuration. The new integration supports OAUTH2 authentication. This update requires you to enter the API Client ID and the API Client Secret to authenticate and complete the configuration.
- Version 10.0.0 - September 2020
- New: Implementation Flow to support the new capability framework (v2.0)
- Version 10.0.0 - March 2020
- New: Implementation Flow to support the new capability framework (v2.0)