foundry-sample-ngsiem-importer
Threat Intel Import to NG-SIEM sample Foundry app
https://github.com/crowdstrike/foundry-tutorial-enrich-incidents
Learn how to use the Foundry CLI to create a Foundry app that enriches Falcon incidents with third-party data. This app adds third-party data on the Next-Gen SIEM incident details page of the Falcon console.
https://github.com/crowdstrike/foundry-tutorial-threat-hunting
Create a threat hunting dashboard and set it as your app's home page. Schedule an email to regularly provide the security team with a list of hosts exhibiting suspicious DNS activity.
https://github.com/crowdstrike/foundry-tutorial-quickstart
A basic "Hello World" app with Foundry
https://github.com/crowdstrike/foundry-tutorial-fusion-soar
Use Falcon Foundry to create a custom workflow action available in Falcon Fusion SOAR. The workflow action uses REST APIs to work with data.
foundry-sample-detection-translation
Detection translation and context sample Foundry app
https://github.com/crowdstrike/foundry-sample-servicenow-itsm
ServiceNow ITSM and SIR sample Foundry app
https://github.com/crowdstrike/foundry-sample-servicenow-idp
ServiceNow CMDB Ingest For Identity Protection sample Foundry app
https://github.com/crowdstrike/foundry-sample-idp-notifications
Falcon IdP Domain and Connector Monitoring sample Foundry app
https://github.com/crowdstrike/foundry-tutorial-extension-builder
In this tutorial, you will create a Foundry app that enriches Falcon detections with third-party data. The app uses VirusTotal to scan the IP address associated with a detection and displays the data on the Next-Gen SIEM endpoint detection details page of the Falcon console.