Technical Specs
External Calls
https://api.crowdstrike.com/incidents/entities/incidents/v1Data Classification
generalMFA Timeout
—Enforcement
Rust / fail-closedcrowdstrike.get_incidentRetrieves full incident details from CrowdStrike Falcon including associated detections, hosts, and tactics used.
External Calls
https://api.crowdstrike.com/incidents/entities/incidents/v1Data Classification
generalMFA Timeout
—Enforcement
Rust / fail-closedAdd this snippet to your agent manifest file to enable this tool.
{
"tools": [
{
"name": "crowdstrike.get_incident",
"version": "1"
}
]
}5 agents currently use this tool
All calls are logged to the tamper evident audit chain
Use this tool in your agent. Sign in to add it to a new or existing agent.
Via CLI
agentsight tool add \
--name crowdstrike.get_incident \
--version 1