CrowdStrike Falcon Insight Integration for Security Operations release notes
Summarize
Summary of CrowdStrike Falcon Insight Integration for Security Operations release notes
The CrowdStrike Falcon Insight Integration for Security Operations enhances ServiceNow's security capabilities by providing continuous endpoint visibility, detection, response, and forensics. This integration enables Configuration Item (CI) enrichment and host isolation directly within the Security Operations environment, helping security teams detect and prevent breaches effectively.
Show less
Key Features and Updates
- CI Enrichment and Host Isolation: The integration offers comprehensive endpoint data and the ability to isolate hosts for containment.
- Block Request Capability (v1.5.2, March 2026): Security analysts can block SHA256/MD5 hashes directly from security incidents.
- Strict Read-Only Enforcement (v1.4.0, December 2025): All dictionary-level read-only fields were upgraded to strict read-only to enhance security and prevent unauthorized changes across UI, scripts, and integrations.
- Workflow Modernization (v1.3.0, November 2024): Migrated traditional workflows to Flow Designer flows for improved automation and management.
- Additional Modules and Capabilities (v1.1.3, October 2021): Introduced CrowdStrike Approvals, Notification Configuration, Default Settings, 'Get File' and 'RTR actions,' and support for Linux endpoints.
- API and Performance Improvements: Upgrades to the CrowdStrike device API and fixes for sighting search errors ensure reliable data retrieval and improved logging.
- Compatibility and Framework Updates: Migrated to the capability framework and updated parent app versions to comply with platform mandates.
Fixes and Enhancements
- Resolved UI validation errors and access issues for analysts querying tables.
- Fixed upgrade issues related to the capability framework ensuring all profiles copy during upgrades.
- Addressed bugs affecting file retrieval accuracy, sighting search functionality, and UI action behavior when multiple capabilities are enabled.
- Improved OS detection for MacOS and optimized CrowdStrike flow performance.
Practical Benefits for ServiceNow Customers
By integrating CrowdStrike Falcon Insight with ServiceNow Security Operations, customers gain enhanced endpoint visibility and response capabilities within their existing security workflows. The continual updates and fixes ensure a secure, reliable, and streamlined experience, allowing security analysts to act swiftly on threats, enrich security incidents with detailed endpoint data, and enforce stronger security policies directly from the ServiceNow platform.
Version history for the CrowdStrike Falcon Insight Integration for Security Operations on the ServiceNow Store.
Version history
- Version 1.5.6 - July 2026
- Fixed: Missing field names in Workspace UI validation errors for the CrowdStrike Create Indicators dialog.
- Version 1.5.3 - June 2026
- Fixed: Access issues for Security Analyst while querying tables.
- Version 1.5.2 - March 2026
- New: Added the block request capability - enabling analysts to block SHA256/MD5 hashes from Security incident.
- Version 1.4.1 - January 2026
- Fixed: Fixed an issue where the Initialise Batch ID action returned no choice values for the Status field in the output.
- Version 1.4.0 - December 2025
- New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
- Version 1.3.1 - May 2025
- Fixed: Various bugs have been addressed and resolved as part of this release.
- Version 1.3.0 - November 2024
- Changed: Migrated Workflows to Flow Designer flows.
- Version 1.2.3 - November 2023
- Fixed: When the customer upgrades to the latest capability framework version, previously only one profile gets copied, but now all the profiles will get copied.
- Version 1.2.1 - June 2023
-
Fixed: Upgrade issue post migration to capability framework.
- Version 1.1.10 - May 2023
- Changed: Migrated to capability framework.
- Version 1.1.8 - February 2023
-
- Changed: Crowdstrike device API upgrade.
- Fixed:
- Sighting search is not working and displays a 404 error from the API.
- Clean up of worknotes.
- Version 1.1.7 - November 2022
-
- Changed: Utah Mandate: Update snc-app-parent version to 5.0.0.77
- Fixed:
- CrowdStrike's Get file retrieves the wrong file from the system.
- Improve the logging for CrowdStrike Falcon Insight.
- Version 1.1.6 - June 2022
-
- Fixed:
- CrowdStrike Falcon Insight Sighting Search is not working in the latest platform versions.
- If both Agent Client Collector capabilities and CrowdStrike Falcon Insight capabilities are active, an incorrect window can open when clicking UI action.
- Fixed:
- Version 1.1.3 - October 2021
-
- New:
- Added new modules: Crowdstrike Approvals, Crowdstrike Notification Configuration, and Crowdstrike Default Setting
- New capabilities 'Get File' and 'RTR actions' are available
- Added support for Linux endpoints for CI submissions
- In the Crowdstrike Additional Actions module:
- Admin can create a new record for custom script with all fields editable
- Analyst can create a new record with some restricted access
- Fixed:
- Fixed OS determination while 'Get Logged on Users' is run against a MacOS
- Improved performance for CrowdStrike flows
- New:
- Version 1.0.2 - February 2021
-
- New:
- Falcon Insight delivers continuous, comprehensive endpoint visibility that spans detection, response and forensics to ensure nothing is missed and potential breaches are stopped.
- CrowdStrike Falcon Insight Integration for Security Operations provides CI enrichment and host isolation capabilities.
- New: