Endpoint Detection and Response (EDR) Integration
CrowdStrike detections on your phone
PocketSOC connects to CrowdStrike Falcon through a customer-created OAuth2 API client. SOC analysts can view Falcon detections, assign or close alerts, and isolate or lift isolation on hosts — all from iOS or Android. Authentication uses scoped API credentials that you manage in the Falcon console, so access can be rotated or revoked at any time.
It is 2 a.m. and Falcon raises a critical detection. Your phone gets the push, you open the full detail — process tree, command line, affected host, severity score — and decide whether it is real. If it is, you isolate the host from where you are standing. No laptop, no VPN, no console login.
Supported actions for CrowdStrike
- View Falcon detections with severity, host, and process context
- Assign and close detections from the mobile app
- Isolate compromised hosts using Falcon Real-Time Response
- Lift host isolation once an investigation is complete
- Filter alerts by severity threshold and host tag
- Receive push notifications for new high-severity detections
Authentication and credentials
CrowdStrike Falcon uses an OAuth2 API client that you create in the Falcon console under API Clients & Keys. For viewing — which is free — read scopes are sufficient: Alerts (read), Hosts (read), and User Management (read). Add write scopes on Alerts and Hosts only if you use Pro response actions such as closing detections or isolating hosts. PocketSOC does not use Personal Access Tokens — CrowdStrike does not issue PATs for the Falcon API. Credentials are stored in iOS Keychain or Android Keystore on each device, never written to logs.
How PocketSOC authenticates to security platforms · Where credentials are stored · Trust Center
Connect CrowdStrike in about 2 minutes
Create a read-only OAuth2 API client in the Falcon console under API clients & keys, paste the Client ID and Secret into PocketSOC, and you are connected. Viewing is free, and read scopes are all you need to start — add write scopes later only if you adopt Pro response actions.
- In Falcon Console, go to API Clients & Keys → Create OAuth2 API Client
- Grant read scopes: Alerts (read), Hosts (read), User Management (read) — add write scopes only when you enable Pro response actions
- Copy Client ID and Client Secret
- In PocketSOC, choose your Falcon region (US-1, US-2, EU-1, or US-GOV-1)
- Paste credentials and connect
See the full Quick Start guide for Organization-mode setup with the PocketSOC Portal.
Free vs Pro
Free — unlimited viewing
- Unlimited viewing of Falcon detections
- Full detection detail — severity, host, user, and command line context
- Process graphs built from Falcon detection data
- Cross-vendor correlation across your connected platforms
- Your first connected vendor profile
Pro — take action
$9.99/month or $99.99/year, with a 7-day free trial.
- Isolate hosts and lift isolation
- Assign, close, and set disposition on detections
- Cross-vendor containment
- Push notifications for new detections
- Additional vendor connections
See full pricing and plans including Organization mode for teams.
Your credentials stay on your device
In Personal Use mode, your CrowdStrike API credentials are stored in the device Keychain and every API call goes directly from your phone to CrowdStrike's API. Requests never route through PocketSOC servers — there is no proxy or relay in the data path. Read how we verify that claim on the Security & Architecture page.
CrowdStrike integration FAQ
Which Falcon regions does PocketSOC support?
PocketSOC supports the four Falcon commercial and government regions: US-1, US-2, EU-1, and US-GOV-1. You select your region during setup; PocketSOC uses the matching Falcon API base URL for all requests.
Does PocketSOC support Real-Time Response (RTR)?
Not in the current version. PocketSOC supports host isolation and lift isolation through Falcon's containment APIs, but it does not start RTR sessions or run commands on endpoints. See the RTR FAQ entry for the future roadmap.
Can I rotate or revoke CrowdStrike credentials?
Yes. Because PocketSOC uses a customer-created OAuth2 API client, you can rotate the client secret or revoke the client entirely from the Falcon console at any time. PocketSOC will prompt for new credentials on the next request. See how PocketSOC authenticates.
Is PocketSOC affiliated with CrowdStrike?
No. PocketSOC is an independent third-party application developed by WeaveHub Technologies LLC. CrowdStrike does not endorse or operate PocketSOC. CrowdStrike® and Falcon® are trademarks of CrowdStrike Holdings, Inc. See the affiliation FAQ entry.
See the full PocketSOC FAQ covering all vendors and security topics.