Skip to main content

Overview

The Crowdstrike integration enables ThreatAware to collect data from Crowdstrike, providing enhanced visibility and security controls.
Connection Method: API Setup Time: ~5 minutes Access Required: Administrator account

Setup instructions

Authorization/setup steps

  1. Log in to CrowdStrike Falcon Console:
  2. Generate API Client:
    • Navigate to Support > API Clients and Keys in the Falcon Console.
    • Click Add new API client, name it ThreatAware Integration, and configure the required permissions:
      • Hosts: Read
      • Detection: Read
      • Additional permissions based on ThreatAware’s requirements.
    • Click Save to generate the Client ID and Client Secret. Copy these details as they will not be shown again.
  3. Input API Credentials in ThreatAware:
    • Open ThreatAware, go to Integrations, and select CrowdStrike.
    • Enter the Client ID and Client Secret in their respective fields.
  • For specific permissions and further details, refer to the CrowdStrike API Documentation.
  • Ensure API credentials are securely stored, as they allow access to sensitive data within your CrowdStrike environment.

Input details

  • Client ID: ID generated for API access in CrowdStrike.
  • Client Secret: Secret key associated with the Client ID.

Verification and troubleshooting

  • Verification: Confirm the Integration Status in ThreatAware shows as Active once the setup is complete.
  • Troubleshooting:
    • Invalid Credentials: Ensure the Client ID and Client Secret are correct and that the required permissions are granted.
    • Permission Issues: Revisit the API Clients and Keys in CrowdStrike to confirm appropriate access levels.