Skip to content
A Python program to connect to the CrowdStrike QueryAPI, retrieve the latest detections and create an alert in TheHive Project
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
CrowdStrike
LICENSE
README.md
code_of_conduct.md
config.py
cs2th.py

README.md

CrowdStrike2TH

A Python program to connect to the CrowdStrike QueryAPI, retrieve the latest detections and create an alert in TheHive

TODO

  • Add option to only create alerts for medium, high or critical incidents.
  • Add option to only create alerts for intel incidents.
  • Add markdown parser to enrich observable descriptions.
  • Add log parser to generate debug logs.
  • Add option to create cases instead of alerts.
You can’t perform that action at this time.