logo

NJP

CrowdStrike Falcon Sandbox Integration for Security Operations

CrowdStrike Falcon Sandbox Integration for Security Operations

by Service-now.com

Submit files or URLs to CrowdStrike Falcon Sandbox for malware and threat analysis.

0 installs 0 reviews v11.0.11 Scoped Application Free (integration tables[1] not counted) 1 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 34 -34
172 days of no change
2025-11-05 33 +1
13 days of no change
2025-10-22 32 +1
28 days of no change
2025-09-23 31 +1
21 days of no change
2025-09-01 30 +1
25 days of no change
2025-08-06 29 +1
71 days of no change
2025-05-26 28 +1
53 days of no change
2025-04-02 27 +1
28 days of no change
2025-03-04 26 +1
36 days of no change
2025-01-26 25 +1
87 days of no change
2024-10-30 24 +1

About

The CrowdStrike Falcon Sandbox for Security Operations integration allows you to submit files and URLs as part of the security incident response process to the CrowdStrike Falcon Sandbox and perform detailed malware analysis. The results of this malware analysis submission are retained as part of the security incident record and can be used for further incident resolution steps and automation workflow activities.

Key Features

This integration supports the following key capabilities:

1. Automate submission of files and URLs from user-reported phishing (URP), email messages, attachments, and other security incidents.
2. Option to manually submit or re-submit previously analyzed files and URLs for updated analysis.
3. Flexibility to create multiple submission configurations that automatically apply sandbox submission parameters such as operating system, scan type, and runtime options, making the submission process more efficient.
4. Threat lookup results and indicator history is available for files and URLs that have been analyzed multiple times.
5. Tagging ServiceNow incidents with submission processing status and threat-finding results.

Version History (2)
v11.0.11 2026-06-16 16:43:39
New: Introduced Query ACLs in CrowdStrike Falcon Sandbox.
v11.0.10 2024-09-10 14:27:47
Fixed:  The issue where the report summary was appended to the external link, causing the report to load a blank page.  
ID: 8d07df45f1b01010017f881ce9f49e77 · Published: Jun 2026 · Updated: Sep 09, 2026