Skip to main content
Find the IDs of your indicator entities. The IDs can then be used to retrieve your indicator entity with the action Get Indicator Details, which includes the actual value of the indicator. The following permission is required to run this action:
  • IOC Management: Read and Write.
External DocumentationTo learn more, visit the CrowdStrike documentation.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

List Indicators with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop