Playbook for Endpoint Detection
This playbook provides systematic remediation steps to investigate malware alerts triggered on a host or endpoint (For example, a malicious file detection).
When CrowdStrike alerts are triggered on a host or endpoint, you can use the Endpoint Detection playbook in the Flow Designer for guidance and help optimize the investigation of these malicious files.
- Set up the Endpoint Detection playbook
Use the following steps to set up the Endpoint Detection playbook. - Use the Endpoint Detection playbook
Use this playbook to investigate malware alerts triggered on a host or endpoint. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Endpoint Detection playbook.
Parent Topic:Flow-based Playbooks