crowdstrike-falcon

Author CrowdStrike Falcon detections across Event Search, NG-SIEM, IOAs, Fusion, and RTR.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill crowdstrike-falcon
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: crowdstrike-falcon
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/crowdstrike-falcon
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill crowdstrike-falcon

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

CrowdStrike Falcon detection engineering across multiple surfaces (Event Search, Custom IOAs/IOCs, NG-SIEM, Fusion, and RTR) requires surface-specific syntax, field mappings, and governance to deliver consistent MDR detections.

Core Features & Use Cases

  • Surface identification guidance for Falcon Insight Event Search, Custom IOAs/IOCs, NG-SIEM, Fusion, and RTR to ensure you author against the correct target.
  • Comprehensive authoring discipline, sensor coverage notes, and best practices for cross-surface correlation and MDR alignment.
  • End-to-end workflows including detection-as-code patterns, cross-platform entity alignment, and integration with MDR governance and deployment pipelines.

Quick Start

Identify the Falcon surface you are targeting, then author rules with the appropriate surface dialect (FQL, CQL, IOA, or fusion) and reference the Field Reference for fields.

Frequently Asked Questions about crowdstrike-falcon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write CrowdStrike Falcon detection rules for NG-SIEM and Event Search?

Create Custom IOAs and IOCs in CrowdStrike Falcon by following structured authoring guidance that maps required fields and aligns detections with MITRE techniques. This ensures MDR-friendly and governance-compliant threat detection content.

What is the best way to align Falcon Fusion automations with MDR governance?

Align Falcon Fusion automations with MDR governance by using detection-as-code patterns and end-to-end workflows. These templates capture governance constraints and ensure cross-platform entity alignment within deployment pipelines.

Does this guidance support Real Time Response (RTR) workflows for detection engineering?

Yes, it supports Falcon RTR workflows by providing surface-specific authoring discipline and sensor coverage notes. This ensures rules authored for RTR maintain consistency with Event Search, Custom IOAs, and Fusion automations.

When do I need to use FQL versus CQL for Falcon detection content?

You need to use FQL or CQL based on the specific Falcon surface you are targeting. The Skill provides surface identification guidance to help you select the correct dialect for Event Search, NG-SIEM, or Custom IOAs.

Can I use this for cross-surface correlation across CrowdStrike Falcon?

Yes, you can use this for cross-surface correlation because it provides best practices for aligning entities across Event Search, NG-SIEM, and Fusion. This ensures consistent detection logic and MDR alignment across all Falcon surfaces.