---
title: "Introduction"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDCrowdstrikeEDR/1564278788/Introduction"
format: markdown
---
This solution integrates **Infoblox Threat Defense™** with **CrowdStrike Endpoint Detection and Response (EDR)** to deliver automated, policy-driven threat response based on DNS threat intelligence (Threat Feeds and SOC Insights). CrowdStrike EDR continuously monitors endpoint activity to detect and respond to threats such as malware and ransomware, providing real-time visibility and advanced threat detection capabilities. By leveraging CrowdStrike’s API-driven architecture, Infoblox Threat Defense™ can programmatically initiate containment actions on endpoints that exhibit malicious behavior, as detected through DNS query analysis.

 

When a DNS query from an endpoint is flagged as **a threat** by Infoblox or leads to the generation of SOC Insights, an event is triggered that initiates an API call to CrowdStrike, isolating the endpoint or applying a restrictive policy. This event-driven containment mechanism significantly reduces response time and limits potential lateral movement of threats within the network. The solution also supports scheduled de-containment workflows, allowing endpoints to be automatically restored to normal operation after a predefined investigation period, thereby streamlining incident response and recovery.


**Infoblox Threat Defense  and SOC Insights + CrowdStrike Falcon Integration** 

**Automated Endpoint Containment for Malicious DNS and Security Events** 

This integration provides an end-to-end automated security workflow by combining: 

- **DNSlayer detection** (Infoblox Threat Defense)

- **Endpoint visibility and enforcement** (CrowdStrike Falcon)

- **Automated containment and controlled release**

- **Granular enforcement** (Global, Subnet, IP Space, Endpoint Groups)

- **Full protection for roaming users**