What it does
Runs daily at midnight and fetches recent CrowdStrike detections. Each one is enriched with detail from the CrowdStrike API and checked in VirusTotal by file hash and indicator values. The workflow then creates a Jira issue with the combined details and posts a message in Slack.
Use cases
- 01Create a Jira ticket for each new CrowdStrike detection
- 02Add VirusTotal context to a detection before triage
- 03Notify the security channel in Slack about new detections
Connects
HTTP Request · Slack · Jira Software