---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# CrowdStrike Falcon EDR integration

# CrowdStrike Falcon EDR integration {#ariaid-title1}

Release version: Australia  
Updated August 15, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Configure CrowdStrike Falcon EDR integration to enable continuous endpoint monitoring and receive real-time security alerts based on Threat Intelligence data from TISC.

Use the CrowdStrike Falcon EDR integration to add observables from TISC to a watchlist that monitors for security events and generates alerts. You add observables as part of enrichment during an investigation.

The integration supports the Domain, IPv4, IPv6, MD5, and SHA256 observable types. Observables that are marked as AllowList aren't sent.

When you send an observable, you select the action that CrowdStrike EDR applies to it: no action, detection only, block, or block with the detection hidden. The block actions apply only to the MD5 and SHA256 observable types.

Each observable is sent with an expiration. You configure whether the expiration comes from the observable in TISC or from the expiration period that is configured for the observable type.

The IOC source that is recorded in CrowdStrike for observables sent from TISC is TISC Intelligence.
* **[Configure Crowdstrike Falcon EDR integration](https://www.servicenow.com/docs/3r0MDmYboaP6APRM6~ubYw)**   
  Download and configure the CrowdStrike Falcon EDR integration to enable endpoint detection and response capabilities in your ServiceNow instance.
* **[Send observables to EDR](https://www.servicenow.com/docs/PTQ4SufBYW4nvNI~oRtXIA)**   
  Send observables to the EDR security tool.

