Icon depicting right-facing arrow
All integrations
SOAR
Integration

CrowdStrike Charlotte Agentic SOAR

Automate triage and response across your invisible attack surface with GreyNoise real-time edge intelligence in CrowdStrike Charlotte Agentic SOAR.

Integration overview

Charlotte Agentic SOAR combines structured workflows with agentic reasoning to drive machine-speed response. GreyNoise adds real-time intelligence to SOAR playbooks to enrich automated triage and response.

GreyNoise is headed to Fal.Con 2026! Learn how to connect with us >

How GreyNoise and CrowdStrike Charlotte Agentic SOAR work together

Three pre-built playbooks operationalize GreyNoise intelligence inside Charlotte Agentic SOAR workflows.

Early Warning for CVE Exploitation Spikes

Early Warning for CVE Exploitation Spikes

Overview

Individual organizations often do not see global exploitation spikes targeting their vendors until it is too late. A surge in scanning or exploitation against a particular CVE can be an early sign of a zero-day or novel exploitation of that vendor’s products, but these are invisible to the individual customers of that vendor. By the time a vendor publishes an advisory, exploitation may have already begun.

The GreyNoise solution

This playbook monitors GreyNoise threat intelligence for exploitation spikes against specific CVEs and is triggered when increased exploitation activity is detected. It queries GreyNoise for the malicious IP addresses associated with that exploitation, then generates a comprehensive case file with actionable threat intelligence for security teams. Configure a CVE activity spike feed in the GreyNoise console to define which CVE alerts are sent to CrowdStrike.

Because GreyNoise CVE exploitation events land inside Fusion SOAR, the rest of the response automates from there: case creation, vulnerability management ticketing, and blocklist updates for the IPs doing the exploiting. The result is an early warning when exploitation activity spikes against a CVE relevant to your tech stack.

See how it works
Detect Compromised Edge Devices

Detect Compromised Edge Devices

Overview

Most edge devices are embedded systems that cannot run an EDR agent. When these devices are compromised, they often scan the internet or call back to attacker-controlled C2 infrastructure without triggering any alerts. So you typically only find out when reported by external parties or in a post-incident investigation.

The GreyNoise solution

This playbook runs when GreyNoise observes your own IP ranges conducting unsolicited scanning, or when internal hosts connect to known callback infrastructure GreyNoise is tracking. Fusion SOAR ingests the alert, enriches with additional context, and creates a case severity and containment ticket. Issues stay tracked in a single case timeline through NG-SIEM's centralized case management

See how it works
IP Enrichment for Faster Triage and Response

IP Enrichment for Faster Triage and Response

Overview

Most SOCs still have analysts manually looking up IPs to determine whether an alert matters. The process is slow, repetitive, and leads to inconsistent triage decisions.

The GreyNoise solution

This playbook automatically enriches alerts in Fusion SOAR with GreyNoise classification, tags, and helps to determine the threat level. It then applies decision rules to recategorize case severity automatically.

An alert involving an IP GreyNoise has observed conducting active exploitation can be escalated. Enrichment is written to the case, so the rationale is visible to analysts and available to downstream workflows.

See how it works

Integration Details

Delivered As
Fusion SOAR App (GreyNoise SOAR Actions)
Includes
GreyNoise actions that can be added to workflows and run by analysts and SOAR playbooks
Works with
Charlotte Agentic SOAR
REQUIREMENTS
GreyNoise API key and supported, mapped telemetry
CATEGORY
SOAR
VENDOR
CrowdStrike
MAINTAINED BY
Joint (GreyNoise + Vendor)

Available in the CrowdStrike Falcon Unified Content Library

The GreyNoise Fusion SOAR App is available now in the CrowdStrike Falcon Falcon Unified Content Library. Install it to deploy the Fusion SOAR playbooks in your CrowdStrike environment.