robot
2024.10
true
Admin Guide
Last updated 2024年10月21日

CrowdStrike 集成

The integration of UiPath Robot with the CrowdStrike Falcon endpoint protection platform has the following advantages:

  • Extended security posture for your organization - This means you can enhance the overall security framework of your organization.

  • Business continuity for your robot workforce - This ensures your robot workforce continues to function without interruption.

  • Improved visibility and analysis capabilities for your security team - The integration allows the security team to more easily monitor and analyze the actions of the robots.

  • Seamless technical integration - This minimizing potential technical issues.

演示

The following demo shows how the integration provides an easy way to detect and selectively block any suspicious or malicious activity caused by the automation execution:

Prerequisites for activation

  • 2021.10 Robot 和 Studio
  • 6.33 版本的 CrowdStrike Falcon 传感器
  • (可选)2021.10 Orchestrator 或 Automation Cloud Orchestrator 1

    当计算机上同时安装 UiPath Robot 和 CrowdStrike Falcon 传感器时,系统会自动激活该集成。

    1 当机器人连接到版本低于 2021.10 的 Orchestrator 时,系统不会将 TenantNameTenantKeyTenantId 字段发送到 CrowdStrike 云控制台。

Integration architecture

Data related to automation execution contains annotation metadata which is sent to the CrowdStrike Falcon sensor. From there, it is sent to the CrowdStrike management console where it can be reviewed by the security team. The integration is based on the following components, which are split between UiPath and CrowdStrike:



元数据

The Robot sends the following metadata to CrowdStrike Falcon:

  • Orchestrator URL - The URL that the robot uses for the Orchestrator connection (e.g. https://cloud.uipath.com).
  • Tenant Name - The tenant in the Orchestrator instance used by the robot.
  • Folder Info - The folder in Orchestrator where the process is found.
  • Package Name - The name of the package used by the robot to run the automation.
  • Process Name - The name of the process run by the robot.
  • Process Key (ID) - The process key (identifier).
  • Machine Name - The machine name on which the automation is running on.
  • Windows 用户 - 运行自动化的 Windows 用户。
  • 用户名 - 运行自动化的用户名。
  • User's Email - The Orchestrator user's email that runs the job.
  • Job ID - The job id in Orchestrator for the running job.
  • Job Start Date - The date when the job was started.
This metadata provides CrowdStrike Falcon with necessary context and hints about how and where the automations run, aiding in assessing and analyzing security measures.

Integration status

The integration status of your CrowdStrike Robot protection could be one of the following:

  • “已启用 ” - 已启用 CrowdStrike 保护;对于计算机模板,将在与该模板关联的所有主机上启用 EDR 保护。

  • N/A - CrowdStrike 保护未启用或状态未知。

  • 混合 (此状态仅针对计算机模板显示,并且仅在“ 计算机 ” 页面上显示)- 在连接到模板的某些主机上启用 CrowdStrike 保护,在其他主机上禁用,或者状态不可用。

To see the integration status, access the following places:

  • Orchestrator, on the Tenant > Machines > Installed Versions & Logs page, check the EDR Protection column. It displays the status of your CrowdStrike Robot protection per machine or machine template over the last 30 days.

  • Assistant, hover over the tray icon.

CrowdStrike documentation

根据您使用的 CrowdStrike 帐户,您可以访问四个文档 URL 之一:

  1. US-1
  2. US-2
  3. EU-1
  4. US-GOV-1

此页面有帮助吗?

获取您需要的帮助
了解 RPA - 自动化课程
UiPath Community 论坛
Uipath Logo White
信任与安全
© 2005-2024 UiPath。保留所有权利。