SIEM & Log Sources
On the roadmapAI triage for CrowdStrike Falcon detections
Endpoint detection and threat intelligence.
Visit CrowdStrike ↗How Jutsu works with CrowdStrike
Stream CrowdStrike Falcon detections into Jutsu and let agents triage endpoint threats with full host context.
What you can do
- Ingest Falcon endpoint detections
- Enrich with device, user, and process context
- Drive containment playbooks on confirmed threats
How it will connect
Connect in minutes
Authenticate with your existing credentials: no agents to deploy, no data to migrate.
Jutsu investigates
AI SOC agents triage, enrich, and correlate every signal automatically, around the clock.
Act with confidence
Get analyst-grade verdicts and one-click response, with humans always in control.
What the CrowdStrike connector will do
The CrowdStrike connector is on Jutsu's roadmap and isn't available yet. As planned, it covers three steps:
Falcon detections in. CrowdStrike Falcon endpoint detections stream into Jutsu as alerts.
Host context. Each detection is enriched with device, user, and process context.
Containment. Confirmed threats can drive containment playbooks.
How Jutsu would triage a Falcon detection
Falcon detections would run through the same agent pipeline Jutsu uses for every source today.
- 1
Enrich. File hashes are checked against VirusTotal, MalwareBazaar, and Kaspersky OpenTIP, and IPs and domains against the rest of Jutsu's nine threat-intel providers.
- 2
Score. Jutsu assigns a 0–100 risk score, a verdict, and a confidence level, and maps the behavior to MITRE ATT&CK techniques.
- 3
Correlate. An endpoint detection is grouped with related alerts from your identity and log sources into one incident, so lateral movement shows up as a single campaign.
- 4
Decide. Benign detections close, confirmed threats can run a playbook, and uncertain ones become cases for your analysts.
Endpoint coverage today
Until the CrowdStrike connector ships, Jutsu's own agent collects endpoint telemetry. On Windows it ships Security and System event logs, plus Sysmon when installed. On macOS it collects the audit trail and command-line process activity.
CrowdStrike integration FAQ
Subscribe to our newsletter
Get the latest security tips, product updates, and news delivered to your inbox.