Cato Networks and CrowdStrike have integrated their cybersecurity platforms to combine in a single investigation flow the activity of the network, users, and corporate devices. The partnership connects the Cato SASE Platform with CrowdStrike Falcon and aims to reduce the time analysts spend reconstructing incidents from alerts spread across different tools.
The key points of the Cato and CrowdStrike integration in 30 seconds
- Cato and CrowdStrike link detections from devices with network traffic and activity.
- The integration covers incident investigation, asset inventory, and threat hunting.
- Cato XOps receives Falcon alerts and adds context about users, sessions, DNS queries, and lateral movements.
- Cato telemetry can also be sent to Falcon Next-Gen SIEM.
- The integrations are now available worldwide on CrowdStrike Marketplace.
This approach addresses a common challenge in security operations centers: a threat rarely shows all its signals in a single product. Endpoint protection may detect a suspicious process on a laptop, while the firewall, DNS service, or remote access platform logs connections that process tries to establish.
When these sources remain separate, analysts must switch between consoles, search for matches, and manually build the attack timeline. The connection between Cato and CrowdStrike seeks to automate part of this correlation without replacing the platforms each company already uses.
It’s not about product mergers or a completely new console. Instead, several technical integrations exchange information between Cato SASE, Cato XOps, Cato Asset Security, CrowdStrike Falcon Discover, and Falcon Next-Gen SIEM.
Falcon alerts receive network context
The first integration links CrowdStrike Falcon detections with Cato XOps, the platform that consolidates Cato’s network and security operations.
When Falcon detects suspicious activity on a device, Cato XOps can incorporate that alert and relate it to network data. This includes the associated user, open sessions, DNS queries, contacted destinations, used applications, and possible lateral movements within internal systems.
This context helps answer questions that an isolated endpoint alert cannot always resolve. A malicious process may have run on a device, but the analyst also needs to know if it communicated with an external server, reached other devices, or attempted to access corporate services.
The listing published on CrowdStrike Marketplace states that Cato XOps can build an investigation sequence around the detection, showing the affected device, connections made, and incident progression. The goal is to quickly verify the scope of the attack and decide on appropriate measures.
Cato already had an integration through CrowdStrike’s API. Detections are retrieved and grouped into security stories that can be reviewed from the XOps workspace. According to Cato’s technical documentation, these stories are generated shortly after the original Falcon alert appears.
This integration does not automatically confirm an alert as an incident. Correlation adds information and can improve priority, but teams still need to review behavior, assess impact, and determine the appropriate response.
A more comprehensive device inventory
The second part of the collaboration focuses on inventory and security posture of assets.
Cato Asset Security analyzes devices visible on the network, while CrowdStrike Falcon Discover provides information on endpoints managed via its agent. Combining these sources allows relating network observations with data Falcon knows about each system.
An organization may have corporate computers, servers, mobile devices, printers, IoT devices, and temporarily connected equipment at a location. Some have security agents installed; others are only visible through the traffic they generate.
Cross-referencing both sources makes it easier to distinguish known from unmanaged devices, identify unprotected systems, and verify if attributes recorded in different platforms match.
Cato’s documentation states that the device management connector uses the Falcon Discover API to enrich the inventory. Configuration requires a Falcon Discover license and corresponding Cato security capabilities for IoT and operational technology environments.
This is important because “available” does not necessarily mean included in any contract. The integrations are accessible, but each feature may depend on licensed modules, permissions, and modules enabled by the customer.
The enriched inventory can also be used to enforce access policies. A company could treat a properly protected corporate laptop differently from an unmanaged device or a server without updated agents.
Cato telemetry reaches Falcon Next-Gen SIEM
The third integration works in the opposite direction. Cato sends network telemetry to CrowdStrike Falcon Next-Gen SIEM, where analysts can search for threats and create detection rules alongside other security sources.
A security information and event management system, or SIEM, aggregates logs from multiple products. Its usefulness depends on both data volume and the ability to normalize, relate, and turn data into actionable investigations.
In this case, Falcon can receive signals generated by Cato’s SASE infrastructure, including network activities, DNS queries, and security controls. Analysts can use this data to verify what happened before or after an endpoint alert and detect behaviors that might be missed from a single source.
For example, a search might locate multiple devices contacting the same suspicious domain, even if only one triggered an alert initially. It could also reveal attempts to access enterprise apps from related locations or identities involved in an incident.
The value of this integration depends on managing data volume, retention, and cost. Corporate networks generate many events, but not all telemetry has the same operational relevance.
Organizations must decide what signals to keep, for how long, and at what level of detail. Sending all logs can improve visibility but also increase storage consumption, ingestion costs, and security team noise.
SASE and endpoint protection cover different parts of the attack
Cato and CrowdStrike come from different areas of the cybersecurity market.
Cato offers a SASE platform, short for Secure Access Service Edge. This model combines network connectivity with security functions delivered from cloud infrastructure, including remote access, SD-WAN, web filtering, firewalls, and identity-based access controls.
CrowdStrike primarily focuses on endpoint protection, extended detection and response (XDR), and threat analysis. Its agent monitors activity within computers and servers to detect processes, files, identities, and behaviors that are suspicious.
Both perspectives are complementary. The endpoint shows what happens inside the device, while the network reveals what services it communicates with, data flow paths, and other targeted applications.
The integration aims to connect these layers without forcing organizations to replace any platform. Cato maintains its network and security functions, while CrowdStrike’s Falcon continues to protect endpoints, manage assets, and analyze events.
This collaboration also reflects an industry shift toward more integrated platforms. Vendors are increasingly adding SIEM, XDR, automation, and AI-driven analysis features, but customers still use multiple products.
Sharing signals can be as valuable as adding new tools. Sufficient context in an alert supports faster decision-making, whereas duplicated or unrelated alerts can increase workload.
Available worldwide with licensing conditions
Cato Networks states that the technical integrations are generally available to customers worldwide via CrowdStrike Marketplace.
Availability covers three main use cases: integrating Falcon alerts into Cato XOps, enriching inventory with Falcon Discover, and sending telemetry from Cato to Falcon Next-Gen SIEM.
Organizations should review which connectors they need, what API permissions to enable, and what license requirements each process entails. They must also define data sharing parameters and what actions security teams can perform from each platform.
While the announcement highlights response acceleration, it does not publish independent metrics on average investigation times, false positive reductions, or performance in large environments.
The actual benefit depends on rule quality, platform adoption levels, and internal SOC processes. Connecting two sources improves context but does not automatically fix issues like misclassified assets, excessive permissions, or incomplete response procedures.
FAQs
What have Cato Networks and CrowdStrike integrated?
They connected the Cato SASE Platform with various CrowdStrike Falcon components to relate endpoint and network data for incident investigations, asset inventories, and threat hunting.
Does the integration replace a SIEM?
Not necessarily. One function sends data from Cato to Falcon Next-Gen SIEM, while others enable alert investigation within Cato XOps. Companies may still operate other logging and analysis platforms.
What additional information does Cato add to a CrowdStrike alert?
Details about the user, device, network connections, DNS queries, sessions, contacted destinations, and possible lateral movements.
Are these features available for all customers?
The integrations are available globally but may require specific modules, licenses, connector configurations, and permissions depending on the organization’s setup.

