Why manual triage no longer cuts it
Security teams are drowning in alerts. As AI accelerates both the volume and pace of attacks, the traditional approach of bouncing between consoles to manually investigate and contain threats introduces dangerous delays. Time spent on low-priority, repetitive tasks contributes directly to alert fatigue, pulling focus away from genuine, high-impact incidents. To defend effectively, modern SOCs need automation that can contain and remediate common threats at machine speed, before they escalate into full-blown business disruptions.
Connecting Cloudflare One with CrowdStrike Falcon Fusion SOAR
Cloudflare has announced a new integration between its One platform and CrowdStrike's Falcon Fusion SOAR. Building on the existing partnership between the two companies, this release brings two pre-built integrations to the CrowdStrike Content Library, aimed at organizations already running CrowdStrike Falcon Insight XDR or Falcon Next-Gen SIEM. The integrations target Zero Trust and Email Security, giving SOC teams new automated pathways to stop phishing, malware, and suspicious behavior with less manual overhead.
Ready-to-use workflows in the Content Library
While custom automations remain possible, these out-of-the-box integrations are designed for immediate deployment. Administrators can find them directly within the CrowdStrike Content Library, without needing to build or maintain connections from scratch.

Cloudflare within CrowdStrike Content Library
The actions available within CrowdStrike from these integrations include:
Email Security- Update Allow Policy - Search Email Messages- List Trusted Domains- List Protected Domains- List Blocked Senders- List Allow Policies - Get Trusted Domain- Get Message Details- Get Detection Details- Get Allow Policy - Delete Trusted Domain- Delete Allow Policy Delete Blocked Sender Create Trusted Domain Create Blocked Sender Create Allow Policy Get Blocked Sender | Zero Trust Access - Update Reusable Policy- Update Access Group- Revoke Application Tokens- Read Metadata For A Key- List Reusable Policies- List Access Groups- List Access Applications - List Access App Policies - Get Access Reusable Policy - Get Access Group- Get Access Application - Get Access App Policy - Delete Reusable Policy - Delete Access Group - Delete Access Application - Delete Access App Policy - Create Reusable Policy - Create Access Group- Create Access App Policy |
|---|
The integrations are meant to plug into Falcon Fusion SOAR's drag-and-drop editor, allowing teams to chain Cloudflare actions with signals from CrowdStrike or third-party tools to automate major portions of the SOC workflow. A representative flow might work like this:
- Cloudflare Email Security detects a phishing email.
- Falcon Fusion SOAR auto-retrieves detection details, blocks the sender, and updates allow/deny lists.
- Cloudflare Zero Trust revokes active session tokens for the affected account.
- If Falcon confirms the endpoint is compromised, the device is automatically isolated.
Such a workflow runs with minimal to no human intervention, reducing response times from minutes to seconds.

An example automated flow using Cloudflare
Sending logs into CrowdStrike
From the Cloudflare dashboard, customers can configure a Logpush job with CrowdStrike. Setting up a job with an "HTTP destination" lets teams route logs directly to Falcon Fusion SOAR.

To complete the setup, the CrowdStrike-provided HTTP endpoint is entered as the destination. The URL format is: ingest.us-2.crowdstrike.com/api/ingest/hec/<CRWDconnectionID>/v1/services/collector/raw.

CrowdStrike URL Location

Working Logpush to CrowdStrike
How the bidirectional response works
The integration is built on webhook and API connections between Cloudflare's SASE platform and CrowdStrike Falcon Fusion SOAR. The result is a two-way street for threat containment:
- Endpoint to network: When the Falcon platform detects an endpoint compromise, it triggers a workflow that calls Cloudflare's API. Cloudflare Access then enforces step-up authentication or revokes sessions across SaaS, private apps, and email.
- Network to endpoint: When Cloudflare observes suspicious behavior—like abnormal login patterns, anomalous traffic, or unsafe email activity—it pings Falcon Fusion SOAR, which responds by isolating the device and launching remediation playbooks.
This closed-loop design ensures threats are sealed off from both the network and the endpoint, with no analyst stuck in the middle.
Enabling the integration
Organizations running CrowdStrike Falcon Fusion SOAR alongside Cloudflare's SASE platform can activate the workflows today from the Cloudflare Dashboard or the CrowdStrike Falcon console (Zero Trust, Email Security), or by searching for Cloudflare in the content library. For teams needing more tailored response actions, both platforms support further extension via APIs and custom playbooks.



