Playbook for Endpoint Detection

  • Release version: Zurich
  • Updated July 31, 2025
  • 1 minute to read
  • This playbook provides systematic remediation steps to investigate malware alerts triggered on a host or endpoint (For example, a malicious file detection).

    When CrowdStrike alerts are triggered on a host or endpoint, you can use the Endpoint Detection playbook in the Flow Designer for guidance and help optimize the investigation of these malicious files.