Identity Security Insights 26.09
Insights send detections straight to CrowdStrike Next-Gen SIEM
Insights finds the identity threats; now it can put them wherever your team is watching. With the new CrowdStrike Falcon integration, you can forward Insights detections and recommendations directly into Falcon Next-Gen SIEM, putting identity threats alongside the rest of your security telemetry – no swivel-chairing between consoles.
What you get with this integration
- Identity threats in your SIEM workflow: Detections and recommendations flow from Insights into Falcon Next-Gen SIEM, so your team can triage identity risk with the same tooling, correlation, and workflows they already use for everything else.
- Rich incident context, not just alerts: Each event carries severity, incident type, affected entities, source address and location, timestamps, and a direct link back to the incident in Insights – enough to triage in Falcon and pivot into Insights only when you need the deep dive.
- Curated signal, not a firehose: Insights forwards its analyzed detections rather than raw event streams, keeping your SIEM ingest focused on findings that matter.
- Verify before you rely on it: Built-in test functionality lets you confirm the connection is delivering events correctly before you wire it into your response process.
ImportantSetup requires admin access to both Insights and CrowdStrike Falcon with Next-Gen SIEM enabled, plus a one-time configuration of a parser and HTTP Event Connector in CrowdStrike.
For more information, see the CrowdStrike Falcon documentation for the walkthrough.
Scripted setup for the Google Cloud Platform connector
One command now replaces the console walkthrough. The connector form now generates a setup command tailored to your configuration and a Python script to run it with. Download the script, run it in Google Cloud Shell, and it builds everything the connector needs in one confirmed pass.
What you get with this update
- One script instead of a step-by-step buildout: The script creates the connector project, enables the required APIs, creates the service account, and binds the organization-level read roles. The parts of GCP onboarding with the most room for a missed API or a mistyped role binding.
- Built from your selections: The command is assembled from what you've entered on the form – your organization ID, plus flags for Google Workspace, Gemini AI agents (formerly shown as Vertex AI), and agent model details. The script provisions exactly the access those capabilities need and nothing more.
- New projects stop breaking your scans: Setup grants the connector a narrowly scoped custom role that lets it enable its required APIs on each project it discovers, including projects created long after setup. The script also includes verify, update, and cleanup commands, and stays available from the connector's settings page.
ImportantRun the script in Google Cloud Shell as a principal with organization-level access. Generating the service account key and Google Workspace domain-wide delegation remain manual steps. See the updated GCP connector documentation for the full flow.
For more information, see Google Cloud Platform.
More accurate privilege scoring for ServiceNow
Privilege scores for ServiceNow entitlements now reflect real-world risk much more precisely. Routine ITSM, workflow, and CMDB permissions no longer inflate into the High tier, while read access to credentials and secrets is weighted more heavily so High privilege on a ServiceNow identity now genuinely means elevated risk. The result is a significant reduction in entitlements rated High, letting you focus remediation on the identities that actually warrant it.