See ARIA in Action
Back to list

CrowdStrike Detection & Policy Analysis: turn Falcon detections into risk decisions

VideosCrowdStrike Detection & Policy Analysis: turn Falcon detections into risk decisions

Introduction

Experience the Power of Configuration Intelligence for Falcon.

Connect X-Analytics to CrowdStrike Falcon, and this agent turns your detections into an updated threat profile and a prioritized list of policy changes, each with the risk it buys down.

Bob Vescio, Chief Innovation Officer of X-Analytics, walks through the CrowdStrike Detection & Policy Analysis agent in the X-Analytics AI Toolbox.

What it does

The CrowdStrike Detection & Policy Analysis agent is an AI agent in the X-Analytics AI Toolbox that reads your CrowdStrike Falcon detections, uses them to update your threat profile, and prioritizes the Falcon policy changes that reduce the most risk.

This is Configuration Intelligence for Falcon: a direct line from your detections to the policy settings that buy down the most risk.

It runs on a CrowdStrike Falcon connection, which you set up once (the X-Analytics customer support page has a short guide). Because Falcon is endpoint protection, it informs some of your threat categories rather than all of them, and the agent is clear about which ones it covers.

How it works

Connect X-Analytics to CrowdStrike Falcon, then start the agent. It moves through three steps:

  • Reads your detections. It pulls your Falcon detections, takes the Falcon severity, and uses CrowdStrike's MITRE ATT&CK mapping to align each detection to the matching X-Analytics threat category. You can flag any false positive so it does not inform your profile.
  • Updates your threat profile. With your approval, the detections adjust your threat values, so your exposure reflects what Falcon is seeing in your environment.
  • Prioritizes policy changes. It returns a ranked list of Falcon policy changes, ordered from critical to moderate detections, and shows the simulated exposure and the risk each change would buy down.

Re-run it whenever you want, weekly or monthly. Each run reflects your latest detections and points you to the policy settings that matter most. Convert any result to a shareable artifact when you want to pass it along.

What you walk away with

  • A threat profile informed by what Falcon is detecting in your environment.
  • A prioritized list of Falcon policy changes, ranked by detection severity.
  • The risk each change would buy down, so you know where to focus first.
  • A repeatable loop you can run as often as your detections change.

Frequently asked questions

What is the X-Analytics CrowdStrike Detection & Policy Analysis agent?


It is an AI agent in the X-Analytics AI Toolbox that reads your CrowdStrike Falcon detections, updates your threat profile from them, and prioritizes the Falcon policy changes that reduce the most risk.

What is Configuration Intelligence for Falcon?


It is the connection between your CrowdStrike Falcon detections and your Falcon policy configuration. X-Analytics reads what Falcon is detecting and tells you which policy changes reduce the most risk, ranked by priority.

What do I need to use it?


A CrowdStrike Falcon connection to X-Analytics.

Does Falcon inform all of my threat categories?


No. Because Falcon is endpoint protection, it informs some threat categories and not others, and the agent shows you exactly which ones its detections apply to.

Watch the full walkthrough

The video above walks through analyzing Falcon detections, updating the threat profile, and reviewing the prioritized policy changes and the risk each one reduces.

Questions about the agent? Reach out to your X-Analytics customer success team at customersuccess@x-analytics.com.

© 2026 X-Analytics. All rights reserved.