Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create indicators

Create and manage threat indicators that synchronize directly with CrowdStrike Falcon Insight, enabling consistent, up‑to‑date threat intelligence across your security environment.

Before you begin

Role required: sn_si.analyst

Procedure

  1. Navigate to Security Incidents > Show All Incidents.

  2. Select the security incident that contains the observables for which you want to create indicators in CrowdStrike Falcon Insight.

  3. Select Associated Observables related lists.

  4. Select the observables.

  5. From the Actions on selected rows, select Create Indicator in CrowdStrike.

  6. On the form, fill in the fields.

FieldDescription
Selected Observables

Observables that are affected. This action can be used to create indicators for multiple observables.Note: Indicators won't be created in CrowdStrike if the supported observable types are not mapped. Supported observable types include:

  • Domain
  • MD5
  • SHA-256
  • IPv4
  • IPv6
SourceIntegration profile configuration used to create the indicator.
DescriptionPurpose of the indicator.
PlatformsPlatforms where this indicator applies. Options include:- Windows - Mac - Linux - Android - iOS
ActionActions to be performed when the Indicator is discovered in the organization. Options include:- Detect - Prevent (hash only) - Prevent (hidden UI) (hash only) - Allow (hash only) - No Action
Mobile ActionAction applied on supported mobile platforms. Options include:- Detect - Prevent (hash only) - Allow (hash only) - No Action
SeveritySeverity assigned to the Indicator. Options include:- Low - Medium - High - Critical
ExpirationDate and time when the indicator will automatically expire
TagsCustom label to categorize/group indicators.
Apply GloballyOption to apply indicator to all the hosts.When cleared, the configuration applies only to selected host groups.
Host GroupsSpecify which CrowdStrike host groups should receive this configuration.
  1. Select Create Indicator

  2. Validate the activity and UI messages.

  3. Select CrowdStrike Indicator tab to view the results.