Skip to main content
Search for processes associated with a custom IOC. The following permission is required to run this action:
  • IOC Management: Read and Write.
  • IOCs (Indicators of Compromise): Read.
Note: An error with 404 response code may occur if no devices are found for the indicator, or if the host has aged out.
External DocumentationTo learn more, visit the CrowdStrike documentation.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

Get Processes by Ioc with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop