- Getting Started
- Installation and Upgrade
- Robot Types
- Robot Components
- Licensing
- Connecting Robots to Orchestrator
- Processes and Activities
- Logging
- Specific Scenarios- Restarting Robot Components
- Windows Sessions
- Login Using Thales Luna Credential System
- Login Using NShield Key Storage Provider
- Redirecting Robots Through a Proxy Server
- Executing Tasks in a Minimized RDP Window
- Using Mapped Network Drives
- Stopping a Process
- Disable Stop Button
- Custom Package Folders and Network Paths
- CrowdStrike integration
- Robot Citrix Apps Virtualization
 
- Governance
- Troubleshooting- Unresponsive Robot Over RDP
- Duplicate Execution Logs
- Frequently Encountered Robot Errors
- Increased Process Execution Duration
- Enforced Package Signature Verification
- Message Too Large to Process
- Errors When Running as Administrator
- NuGet Packages Not Accessible After Migration
- User Access Control Prompt and UI Automation Activities
- .NET required during installation
- Assembly Cannot Be Loaded From Network Or Azure File Share
- Activities cannot find .NET Runtime
- CrowdStrike integration troubleshooting
 

Robot User Guide
The integration of UiPath Robot with the CrowdStrike Falcon endpoint protection platform has the following advantages:
- 
               Extended security posture for your organization - This means you can enhance the overall security framework of your organization. 
- 
               Business continuity for your robot workforce - This ensures your robot workforce continues to function without interruption. 
- 
               Improved visibility and analysis capabilities for your security team - The integration allows the security team to more easily monitor and analyze the actions of the robots. 
- 
               Seamless technical integration - This minimizing potential technical issues. 
The following demo shows how the integration provides an easy way to detect and selectively block any suspicious or malicious activity caused by the automation execution:
- Robot and Studio minimum version: 2022.10.17
- Latest supported version of CrowdStrike Falcon sensor
- 
                  (Optional) 2022.10 Orchestrator or Automation Cloud Orchestrator1The integration is automatically activated when both UiPath Robot and CrowdStrike Falcon sensor are installed on the machine. 1When the robot is connected to an Orchestrator older than 2021.10, theTenantName,TenantKey, andTenantIdfields are not sent to the CrowdStrike cloud console.
Data related to automation execution contains annotation metadata which is sent to the CrowdStrike Falcon sensor. From there, it is sent to the CrowdStrike management console where it can be reviewed by the security team. The integration is based on the following components, which are split between UiPath and CrowdStrike:
The Robot sends the following metadata to CrowdStrike Falcon:
- Orchestrator URL - The URL that the robot uses for the Orchestrator connection (e.g. https://cloud.uipath.com).
- Tenant Name - The tenant in the Orchestrator instance used by the robot.
- Folder Info - The folder in Orchestrator where the process is found.
- Package Name - The name of the package used by the robot to run the automation.
- Process Name - The name of the process run by the robot.
- Process Key (ID) - The process key (identifier).
- Machine Name - The machine name on which the automation is running on.
- Windows User - The Windows user under which the automation is running.
- User Name - The username under which the automation is running.
- User's Email - The Orchestrator user's email that runs the job.
- Job ID - The job id in Orchestrator for the running job.
- Job Start Date - The date when the job was started.
The integration status of your CrowdStrike Robot protection could be one of the following:
- 
                  Enabled - CrowdStrike protection is enabled; for machine templates, EDR protection is enabled on all host machines associated to that template. 
- 
                  N/A - CrowdStrike protection is not enabled or the status is not known. 
- 
                  Mixed (this status is only displayed for machine templates, and only on the Machines page) - CrowdStrike protection is enabled on some host machines connected to the template, and disabled on others, or the status is not available. 
To see the integration status, access the following places:
- 
                  Orchestrator, on the Tenant > Machines > Installed Versions & Logs page, check the EDR Protection column. It displays the status of your CrowdStrike Robot protection per machine or machine template over the last 30 days. 
- 
                  Assistant, hover over the tray icon.