deploying-edr-agent-with-crowdstrike

Featured

Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.

AI & Automation 16,326 stars 1981 forks Updated 2 weeks ago Apache-2.0

Install

View on GitHub

Quality Score: 97/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Deploying EDR Agent with CrowdStrike ## When to Use Use this skill when: - Deploying CrowdStrike Falcon sensors to Windows, macOS, or Linux endpoints - Configuring Falcon prevention and detection policies for different endpoint groups - Integrating CrowdStrike telemetry with SIEM (Splunk, Elastic, Sentinel) for correlated detection - Troubleshooting sensor connectivity, performance, or detection issues **Do not use** this skill for deploying other EDR solutions (Carbon Black, SentinelOne) or for Falcon cloud workload protection (use cloud-specific deployment guides). ## Prerequisites - CrowdStrike Falcon console access with Falcon Administrator role - Customer ID (CID) and Falcon sensor installer package - Administrative/root access on target endpoints - Network access: endpoints must reach CrowdStrike cloud (ts01-b.cloudsink.net on port 443) - Deployment tool: SCCM, Intune, GPO, Ansible, or manual installation ## Workflow ### Step 1: Obtain Falcon Sensor Installer and CID ``` 1. Log into Falcon Console: https://falcon.crowdstrike.com 2. Navigate: Host setup and management → Sensor downloads 3. Download the appropriate installer: - Windows: WindowsSensor_<version>.exe - macOS: FalconSensorMacOS_<version>.pkg - Linux: falcon-sensor_<version>_amd64.deb / .rpm 4. Copy the Customer ID (CID) from the Sensor downloads page - CID format: <32-char-hex>-<2-char-checksum> ``` ### Step 2: Deploy Falcon Sensor - Windows **Silent installation via command line**: ``...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
2 weeks ago
Language
Python
License
Apache-2.0

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

crowdstrike

Every CrowdStrike Falcon MSP operation, plus a Flight-Control-aware local store that answers fleet-wide questions across all your tenants at once - something no other Falcon tool (including the official MCP server) does. Trigger phrases: `check crowdstrike alerts across all tenants`, `show stale falcon sensors`, `critical vulnerabilities across my crowdstrike fleet`, `crowdstrike tenant scorecard`, `list falcon child CIDs`, `use crowdstrike-cli`, `run crowdstrike-cli`.

6 Updated today
Servosity
AI & Automation Featured

configuring-windows-defender-advanced-settings

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender settings, deploying enterprise-grade endpoint protection, or meeting compliance requirements for advanced malware defense. Activates for requests involving Windows Defender configuration, ASR rules, MDE tuning, or Microsoft endpoint security.

16,326 Updated 2 weeks ago
mukul975
DevOps & Infrastructure Featured

implementing-security-monitoring-with-datadog

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.

16,326 Updated 2 weeks ago
mukul975