CrowdStrike
Visualize Crowdstrike endpoint agents and protected devices, map agents to devices and their respective owners, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
- Release Notes
Installation
You will need to create an API client in the CrowdStrike Falcon console. See the CrowdStrike API Clients and Configuration documentation for details.
When creating the API client, grant (at minimum) read access to the following scopes:
- Hosts
- Prevention Policies
Additional scopes are required to enable optional ingestion steps:
- Alerts
- Apps (Falcon Discover applications)
- Cloud Security API Assets (Compliance Controls)
- Cloud Security API Detections (IOM Findings)
- Cloud Security AWS Registration (CSPM)
- Cloud Security Azure Registration (CSPM)
- Device control policies
- External Assets (EASM Findings)
- Falcon Container Image (Container Security, Serverless Vulnerabilities)
- Firewall management
- Kubernetes Protection (Container–host relationships)
- SaaS Security (Falcon Shield)
- Spotlight Vulnerabilities (Vulnerabilities, Remediations, EASM Findings)
- User management
- Zero Trust Assessment
To install the CrowdStrike integration in JupiterOne, navigate to the Integrations tab and select CrowdStrike. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the CrowdStrike account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
An optional Description to help identify the integration instance.
-
A Polling Interval for how frequently data is refreshed. Leave this as
DISABLEDto trigger runs manually. -
Your CrowdStrike API client ID and API client secret to authenticate with the Falcon API.
-
An optional Availability Zone for API calls. Leave blank to use the main endpoint (
api.crowdstrike.com). For example, enteringus-2routes requests toapi.us-2.crowdstrike.com.
Click Create once all values are provided to start the integration.
The CrowdStrike integration only ingests applications that have vulnerabilities. Applications without vulnerabilities will not appear in JupiterOne.
Data Volume Configuration
Ingestion Windows
Define how far back in time data is collected during each ingestion run. Each data type has its own configurable window.
| Field | Description | Default | Options |
|---|---|---|---|
| Device Ingestion Window | Days to look back for devices by last-seen date. | 50 | 7, 15, 30, 50, 60, 90, 180, 275, 365 |
| Vulnerabilities Ingestion Window | Days to look back for updated vulnerabilities. | 90 | 90, 180, 275, 365 |
| Alerts Ingestion Window | Days to look back for updated alerts. | 90 | 90, 180, 275, 365 |
| Applications Ingestion Window | Days to look back for last-used applications. | 90 | 90, 180, 275, 365 |
| Containers Ingestion Window | Days to look back for containers by first-seen date. | 50 | 7, 15, 30, 50, 60, 90, 180, 275, 365 |
| Container Image Vulnerabilities Ingestion Window | Days to look back for container image vulnerabilities by first-seen date. | 365 | 90, 180, 275, 365 |
| EASM Findings Ingestion Window | Days to look back for EASM findings by created date. | 90 | 7, 15, 30, 50, 60, 90, 180, 275, 365 |
| Serverless Vulnerabilities Ingestion Window | Days to look back for serverless vulnerabilities. | 90 | 90, 180, 275, 365 |
| Serverless Vulnerabilities Page Size | Maximum number of serverless vulnerabilities fetched per API request. Must be a whole number between 1 and 500. | (not set) | — |
Data Filtering Options
| Field | Description | Default | Options |
|---|---|---|---|
| Included Vulnerability Severities | Vulnerability severity levels to ingest. Configure this field or Included Vulnerability Exprt Ratings — not both simultaneously. | Critical, High, Medium, Unknown | Critical, High, Medium, Low, None, Unknown |
| Included Vulnerability Exprt Ratings | ExPRT ratings to use as a vulnerability filter instead of severity levels. When set, severity-based filters are ignored. | (not set) | Critical, High, Medium, Low, Unknown |
| Include Closed Vulnerabilities | When enabled, ingests vulnerabilities that are marked as closed in CrowdStrike. | Disabled | — |
| Included Alerts Severities | Alert severity levels to ingest. | Critical, High, Medium | Critical, High, Medium, Low, Informational |
| Ingest suspicious applications only | When enabled, only applications flagged as suspicious in CrowdStrike are ingested. | Disabled | — |
| CSPM Cloud Providers | Cloud providers to monitor for CSPM findings, cloud accounts, and IOM findings. If nothing is selected, CSPM data is not ingested. | (not set) | AWS, Azure |
| IOM Severity Filter | IOM finding severity levels to ingest. | Critical | Critical, High, Medium, Informational |
| Compliance Control Severities | Compliance control severity levels to ingest. | Critical, High | Critical, High, Medium, Informational, Unknown |
| Included EASM Finding Severities | EASM finding severity levels to ingest. | Critical, High | Critical, High, Medium, Low, Unknown |
| Included Image Vulnerability Severities | Container image vulnerability severity levels to ingest. | Critical, High | Critical, High, Medium, Low, Unknown |
| Serverless Cloud Providers | Cloud providers to ingest serverless vulnerabilities for. | AWS | AWS, GCP, Azure |
| Included Serverless Vulnerability Severities | Serverless vulnerability severity levels to ingest. | Critical, High | Critical, High, Medium, Low, None, Unknown |
Multi-Tenant (MSSP) Configuration
CrowdStrike Flight Control allows a parent account to manage multiple child CIDs. To enable multi-tenant ingestion:
- Enable Configure Child CIDs.
- Enter the Parent CID — the CID of the parent CrowdStrike account.
When configured, JupiterOne automatically creates a separate integration instance for each child CID discovered under the parent account.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
OAuth Scopes
OAuth scopes that must be granted to the application or service principal.
Show OAuth Scopes (15)
alerts:readassets:readcloud-security-assets:readcspm-registration:readdevice-control-policies:readdiscover:readfalcon-container-image:readfirewall-policies:readhosts:readkubernetes-protection:readprevention-policies:readsaas-security:readspotlight-vulnerabilities:readuser-management:readzero-trust-assessment:read
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (33)
/alerts/combined/alerts/v1/cloud-connect-cspm-aws/entities/account/v1/cloud-connect-cspm-azure/entities/account/v1/cloud-security-assets/combined/compliance-controls/by-account-region-and-resource-type/v1/container-security/combined/containers/v1/container-security/combined/image-assessment/images/v1/container-security/combined/images/export/v1/container-security/combined/vulnerabilities/v1/detects/entities/iom/v2/detects/queries/iom/v2/devices/entities/devices/v2/devices/queries/devices-hidden/v1/devices/queries/devices-scroll/v1/discover/combined/applications/v1/fem/entities/external-assets/v1/fem/queries/external-assets/v1/lambdas/combined/vulnerabilities/sarif/v1/policy/combined/device-control/v1/policy/combined/firewall/v1/policy/combined/prevention/v1/policy/queries/device-control-members/v1/policy/queries/firewall-members/v1/policy/queries/prevention-members/v1/saas-security/entities/alerts/v3/saas-security/entities/apps/v3/saas-security/entities/integrations/v3/settings/entities/policy/v1/spotlight/combined/vulnerabilities/v1/spotlight/entities/remediations/v2/user-management/entities/users/GET/v1/user-management/queries/users/v1/zero-trust-assessment/entities/assessments/v1/zero-trust-assessment/queries/assessments/v1
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (15)
| Step | OAuth Scopes | Endpoints |
|---|---|---|
| Build Host to Container Image Relationships | kubernetes-protection:read | /container-security/combined/containers/v1 |
| Compliance Controls | cloud-security-assets:read | /cloud-security-assets/combined/compliance-controls/by-account-region-and-resource-type/v1 |
| Fetch Alerts | alerts:read | /alerts/combined/alerts/v1 |
| Fetch Applications | discover:read | /discover/combined/applications/v1 |
| Fetch Container Images Vulnerabilities | falcon-container-image:read | /container-security/combined/vulnerabilities/v1 |
| Fetch Device Control Policy Relationships | device-control-policies:read | /policy/combined/device-control/v1, /policy/queries/device-control-members/v1 |
| Fetch Device Policies | prevention-policies:read | /policy/queries/prevention-members/v1 |
| Fetch EASM Findings | spotlight-vulnerabilities:read, assets:read | /spotlight/combined/vulnerabilities/v1 |
| Fetch Falcon Shield Alerts | saas-security:read | /saas-security/entities/alerts/v3 |
| Fetch Falcon Shield Apps | saas-security:read | /saas-security/entities/apps/v3 |
| Fetch Firewall Policy Relationships | firewall-policies:read | /policy/combined/firewall/v1, /policy/queries/firewall-members/v1 |
| Fetch Remediations | spotlight-vulnerabilities:read | /spotlight/entities/remediations/v2 |
| Fetch Vulnerabilities | spotlight-vulnerabilities:read | /spotlight/combined/vulnerabilities/v1 |
| IOM Findings | cspm-registration:read | /detects/queries/iom/v2, /detects/entities/iom/v2 |
| IOM Rules | cspm-registration:read | /settings/entities/policy/v1 |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | crowdstrike_account | Account |
| Alert | crowdstrike_alert | Finding |
| Application | crowdstrike_detected_application | Application |
| AWS API Gateway Resource | crowdstrike_aws_api_gateway_resource | Resource |
| AWS API Gateway REST API | crowdstrike_aws_api_gateway_rest_api | Service |
| AWS Athena Work Group | crowdstrike_aws_athena_work_group | Service |
| AWS Auto Scaling Launch Configuration | crowdstrike_aws_autoscaling_launch_configuration | Configuration |
| AWS CloudFormation Stack | crowdstrike_aws_cloudformation_stack | Configuration |
| AWS CloudFront Domain | crowdstrike_aws_cloudfront_domain | Service |
| AWS CloudTrail | crowdstrike_aws_cloudtrail | Service |
| AWS CloudTrail Account | crowdstrike_aws_cloudtrail_account | Account |
| AWS CloudTrail Bucket | crowdstrike_aws_cloudtrail_bucket | Configuration |
| AWS CodeBuild Project | crowdstrike_aws_codebuild_project | Configuration |
| AWS Cognito User Pool | crowdstrike_aws_cognito_user_pool | Service |
| AWS Config Account | crowdstrike_aws_config_account | Configuration |
| AWS DynamoDB Table | crowdstrike_aws_dynamodb_table | DataStore, Database |
| AWS EBS Snapshot | crowdstrike_aws_ebs_snapshot | Image |
| AWS EBS Volume | crowdstrike_aws_ebs_volume | DataStore |
| AWS EC2 Instance | crowdstrike_aws_ec2_instance | Host |
| AWS EC2 Network Acl | crowdstrike_aws_ec2_network_acl | Firewall |
| AWS EC2 Security Group | crowdstrike_aws_ec2_security_group | Firewall |
| AWS ECR Repository | crowdstrike_aws_ecr_repository | CodeRepo |
| AWS ECS Task Definition | crowdstrike_aws_ecs_task_definition | Configuration |
| AWS EFS File System | crowdstrike_aws_efs_file_system | DataStore |
| AWS EKS Cluster | crowdstrike_aws_eks_cluster | Cluster |
| AWS ElastiCache Cluster | crowdstrike_aws_elasticache_cluster | DataStore, Database |
| AWS ELB Azure Tenant | crowdstrike_aws_elb_azure_tenant | Gateway |
| AWS ELB Load Balancer | crowdstrike_aws_elb_load_balancer | Gateway |
| AWS Event Bridge Event Bus | crowdstrike_aws_eventbridge_event_bus | Queue |
| AWS IAM Account | crowdstrike_aws_iam_account | Configuration |
| AWS IAM Group | crowdstrike_aws_iam_group | UserGroup |
| AWS IAM Policy | crowdstrike_aws_iam_policy | AccessPolicy |
| AWS IAM Role | crowdstrike_aws_iam_role | AccessRole |
| AWS IAM S3 Policy | crowdstrike_aws_iam_s3_policy | AccessPolicy |
| AWS IAM User | crowdstrike_aws_iam_user | User |
| AWS Kinesis Stream | crowdstrike_aws_kinesis_stream | DataStore |
| AWS KMS Key | crowdstrike_aws_kms_key | CryptoKey, Key |
| AWS Lambda Disk | crowdstrike_aws_lambda_disk | Disk |
| AWS Lambda Function | crowdstrike_aws_lambda_function | Function |
| AWS NLB/ALB Load Balancer | crowdstrike_aws_nlb_alb_load_balancer | Gateway |
| AWS RDS Database | crowdstrike_aws_rds_database | DataStore, Database |
| AWS Route 53 Domain | crowdstrike_aws_route53_domain | Domain |
| AWS S3 Bucket | crowdstrike_aws_s3_bucket | DataStore |
| AWS SageMaker Workbench Instance | crowdstrike_aws_sagemaker_notebook_instance | Host |
| AWS Secrets Manager Secret | crowdstrike_aws_secrets_manager_secret | Secret |
| AWS SES | crowdstrike_aws_ses | Service |
| AWS SNS Topic | crowdstrike_aws_sns_topic | Queue |
| AWS SQS Queue | crowdstrike_aws_sqs_queue | Queue |
| AWS SSM Parameter | crowdstrike_aws_ssm_parameter | Configuration |
| AWS VPC | crowdstrike_aws_vpc | Network |
| AWS VPC Bucket | crowdstrike_aws_vpc_bucket | Network |
| AWS VPC Endpoint | crowdstrike_aws_vpc_endpoint | Gateway |
| AWS VPC Route Table | crowdstrike_aws_vpc_route_table | Configuration |
| AWS VPC Subnet | crowdstrike_aws_vpc_subnet | Network |
| AWS WAF VPC Endpoint | crowdstrike_aws_waf_vpc_endpoint | Firewall |
| Azure AD Domain Service | crowdstrike_azure_ad_domain_service | Service |
| Azure App Service | crowdstrike_azure_app_service | Service |
| Azure App Service | crowdstrike_azure_web_app | Application |
| Azure CDN Profile | crowdstrike_azure_cdn_profile | Service |
| Azure Container Apps | crowdstrike_azure_container_app | Service |
| Azure Cosmos DB | crowdstrike_azure_cosmosdb_account | Account, Service |
| Azure Event Hub | crowdstrike_azure_event_hub | Service |
| Azure Firewall | crowdstrike_azure_firewall | Firewall |
| Azure Key Vault | crowdstrike_azure_key_vault | KeyStore |
| Azure Kubernetes Cluster | crowdstrike_azure_kubernetes_cluster | Cluster |
| Azure Managed Disk | crowdstrike_azure_managed_disk | DataStore, Disk |
| Azure MySQL Server | crowdstrike_azure_mysql_server | Database, DataStore, Host |
| Azure Security Group | crowdstrike_azure_security_group | Firewall |
| Azure Storage Account | crowdstrike_azure_storage_account | DataStore, Service |
| Azure Subscription | crowdstrike_azure_subscription | Account |
| Azure Virtual Machine | crowdstrike_azure_vm | Host |
| Azure Virtual Network | crowdstrike_azure_vnet | Network |
| Cloud Account | crowdstrike_cloud_account | Account |
| Cloud Entity | crowdstrike_cloud_entity | Entity |
| Compliance Control | crowdstrike_compliance_control | ControlPolicy |
| Container Image | crowdstrike_container_image | Image |
| Device | crowdstrike_host | Host |
| Device Control Policy | crowdstrike_device_control_policy | ControlPolicy |
| Device Sensor Agent | crowdstrike_sensor | HostAgent |
| Discover Application | crowdstrike_discover_application | Application |
| EASM Finding | crowdstrike_easm_finding | Finding |
| External Asset | crowdstrike_external_asset | Resource |
| Falcon Shield Alert | crowdstrike_falcon_shield_alert | Finding |
| Falcon Shield App | crowdstrike_falcon_shield_app | Application, NHI |
| Falcon Shield Integration | crowdstrike_falcon_shield_integration | Configuration, Account |
| Firewall Policy | crowdstrike_firewall_policy | ControlPolicy |
| Image Vulnerability | crowdstrike_image_vulnerability | Finding, Vulnerability |
| Image Vulnerability | crowdstrike_image_vulnerability | Finding |
| IOM Finding | crowdstrike_iom_finding | Finding |
| IOM Rule | crowdstrike_iom_rule | Rule |
| Prevention Policy | crowdstrike_prevention_policy | ControlPolicy |
| Prevention Policy Setting | crowdstrike_prevention_policy_setting | Configuration |
| Remediation | crowdstrike_remediation | Record |
| Serverless Vulnerability | crowdstrike_serverless_vulnerability | Finding, Vulnerability |
| Service | crowdstrike_endpoint_protection | Service |
| User | crowdstrike_user | User |
| Vulnerability | crowdstrike_vulnerability | Finding, Vulnerability |
| Vulnerability | crowdstrike_vulnerability | Finding |
| Zero Trust Assessment | crowdstrike_zero_trust_assessment | Assessment |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
crowdstrike_account | HAS | crowdstrike_endpoint_protection |
crowdstrike_account | HAS | crowdstrike_sensor |
crowdstrike_account | HAS | crowdstrike_container_image |
crowdstrike_account | HAS | crowdstrike_user |
crowdstrike_account | HAS | crowdstrike_remediation |
crowdstrike_account | HAS | crowdstrike_cloud_account |
crowdstrike_account | HAS | crowdstrike_external_asset |
crowdstrike_account | HAS | crowdstrike_serverless_vulnerability |
crowdstrike_account | HAS | crowdstrike_falcon_shield_integration |
crowdstrike_cloud_account | HAS | crowdstrike_compliance_control |
crowdstrike_cloud_account | HAS | crowdstrike_cloud_entity |
crowdstrike_cloud_entity | HAS | crowdstrike_iom_finding |
crowdstrike_compliance_control | HAS | crowdstrike_iom_rule |
crowdstrike_container_image | EXPLOITS | crowdstrike_vulnerability |
crowdstrike_detected_application | HAS | crowdstrike_vulnerability |
crowdstrike_external_asset | HAS | crowdstrike_easm_finding |
crowdstrike_falcon_shield_integration | HAS | crowdstrike_falcon_shield_app |
crowdstrike_falcon_shield_integration | HAS | crowdstrike_falcon_shield_alert |
crowdstrike_host | HAS | crowdstrike_vulnerability |
crowdstrike_host | USES | crowdstrike_container_image |
crowdstrike_iom_rule | IDENTIFIED | crowdstrike_iom_finding |
crowdstrike_prevention_policy | ENFORCES | crowdstrike_endpoint_protection |
crowdstrike_prevention_policy | HAS | crowdstrike_prevention_policy_setting |
crowdstrike_sensor | PROTECTS | crowdstrike_host |
crowdstrike_sensor | ASSIGNED | crowdstrike_prevention_policy |
crowdstrike_sensor | IDENTIFIED | crowdstrike_vulnerability |
crowdstrike_sensor | HAS | crowdstrike_zero_trust_assessment |
crowdstrike_sensor | ASSIGNED | crowdstrike_device_control_policy |
crowdstrike_sensor | ASSIGNED | crowdstrike_firewall_policy |
crowdstrike_sensor | INSTALLED | crowdstrike_discover_application |
crowdstrike_sensor | HAS | crowdstrike_alert |
Mapped Relationships
The following mapped relationships are created:
Source Entity _type | Relationship _class | Target Entity _type | Direction |
|---|---|---|---|
crowdstrike_sensor | ASSIGNED | crowdstrike_device_control_policy | FORWARD |
crowdstrike_sensor | ASSIGNED | crowdstrike_firewall_policy | FORWARD |
crowdstrike_serverless_vulnerability | HAS | aws_lambda_function | REVERSE |
crowdstrike_serverless_vulnerability | HAS | google_cloud_function | REVERSE |
crowdstrike_serverless_vulnerability | HAS | azure_function_app | REVERSE |
crowdstrike_vulnerability | IS | cve | FORWARD |
Crowdstrike Account
crowdstrike_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
cid | string |
Crowdstrike Alert
crowdstrike_alert inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
aggregateId | string | ||
childProcessIds | array of strings | ||
cid | string | ||
cmdline | string | ||
compositeId | string | ||
createdOn | number | ||
dataDomains | array of strings | ||
description | string | ||
detectedOn | number | ||
deviceExternalIp | string | ||
deviceHostname | string | ||
deviceId | string | ||
deviceLocalIp | string | ||
deviceMacAddress | string | ||
deviceOsVersion | string | ||
devicePlatformName | string | ||
deviceStatus | string | ||
falconHostLink | string | ||
filename | string | ||
filepath | string | ||
filesAccessed | array of strings | ||
id | string | ||
mitreAttack | array of strings | ||
objective | string | ||
parentCmdline | string | ||
parentFilename | string | ||
product | string | ||
scenario | string | ||
severityName | string | ||
sourceProducts | array of strings | ||
sourceVendors | array of strings | ||
status | string | ||
tactic | string | ||
tacticId | string | ||
technique | string | ||
techniqueId | string | ||
updatedOn | number | ||
userId | string | ||
userName | string | ||
userPrincipal | string |
Crowdstrike Cloud Account
crowdstrike_cloud_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
accountAlias * | string | null | ||
accountId * | string | ||
accountName * | string | null | ||
accountType * | string | null | ||
availableRegions * | array | null | ||
azureTenantId * | string | null | ||
cid * | string | null | ||
cloudformationUpdateUrl * | string | null | ||
cloudProvider * | string | ||
cloudtrailBucketName * | string | null | ||
cloudtrailRegion * | string | null | ||
dsprmRoleArn * | string | null | ||
enabledServices * | array | null | ||
endedOn * | number | null | ||
eventbusArn * | string | null | ||
eventbusName * | string | null | ||
externalId * | string | null | ||
falconClientId * | string | null | ||
healthyConditionsCount * | number | null | ||
iamRoleArn * | string | null | ||
intermediateRoleArn * | string | null | ||
isActive * | boolean | null | ||
isBehaviorAssessmentEnabled * | boolean | null | ||
isCloudRegistration * | boolean | null | ||
isCSPMEnabled * | boolean | null | ||
isCSPMLite * | boolean | null | ||
isCustomRolename * | boolean | null | ||
isD4CMigrated * | boolean | null | ||
isDSPMEnabled * | boolean | null | ||
isManaged * | boolean | null | ||
isMaster * | boolean | null | ||
isSensorManagementEnabled * | boolean | null | ||
isUsingExistingCloudtrail * | boolean | null | ||
isValid * | boolean | null | ||
lastScanOn * | number | null | ||
onboardedOn * | number | null | ||
operationalServicesCount * | number | null | ||
organizationId * | string | null | ||
region * | string | null | ||
remediationCloudformationUrl * | string | null | ||
s3Url * | string | null | ||
startedOn * | number | null | ||
status * | string | null | ||
totalConditionsCount * | number | null | ||
totalServicesCount * | number | null | ||
vendor * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Cloud Entity
crowdstrike_cloud_entity inherits from Entity
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
cloudProvider * | string | ||
lastScannedOn * | number | null | ||
region * | string | null | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
service * | string |
Crowdstrike Compliance Control
crowdstrike_compliance_control inherits from ControlPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
assessmentId * | string | ||
benchmarkId * | string | null | ||
benchmarkName * | string | null | ||
benchmarkVersion * | string | null | ||
cloudProvider * | string | ||
compliantResources * | number | null | ||
controlFramework * | string | null | ||
controlName * | string | null | ||
controlType * | string | null | ||
controlVersion * | string | null | ||
criticalNonCompliant * | number | null | ||
highNonCompliant * | number | null | ||
informationalNonCompliant * | number | null | ||
lastEvaluatedOn * | number | null | ||
mediumNonCompliant * | number | null | ||
nonCompliantResources * | number | null | ||
region * | string | ||
resourceProvider * | string | null | ||
resourceType * | string | null | ||
resourceTypeName * | string | null | ||
ruleIds * | array | null | ||
ruleNames * | array | null | ||
ruleOrigins * | array | null | ||
rulePolicyIds * | array | null | ||
service * | string | null | ||
serviceCategory * | string | null | ||
severities * | array | null | ||
totalResources * | number | null |
Crowdstrike Container Image
crowdstrike_container_image inherits from Image
| Property | Type | Description | Specifications |
|---|---|---|---|
cid | string | ||
digest | string | ||
imageId | string | ||
lastSeen | number | ||
registry | string | ||
repository | string | ||
tag | string |
Crowdstrike Detected Application
crowdstrike_detected_application inherits from Application
| Property | Type | Description | Specifications |
|---|---|---|---|
dataProvider | string | Source that produced the detection, e.g. "Falcon sensor" or "Falcon EASM". | |
evaluationLogicId * | string | ID of the Spotlight evaluation logic that matched the application on the host. | |
installPath | string | Filesystem path where the application was detected on the host, when available. | |
open * | boolean | Whether the application still has an open vulnerability sub-status. | |
productName | string | Normalized product name without version (e.g. "Firefox"). | |
remediationIds | array of strings | ||
vendor | string | Normalized vendor of the application (e.g. "Mozilla"). | |
version | string | Installed version of the application. For macOS software this is parsed from the Spotlight evaluation logic; for other platforms it is taken from the affected product name. |
Crowdstrike Device Control Policy
crowdstrike_device_control_policy inherits from ControlPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
cid * | string | ||
createdBy * | string | ||
description * | string | ||
enabled * | boolean | ||
id * | string | ||
modifiedBy * | string | ||
name * | string | ||
platformName * | string | ||
settingsClasses * | array of strings | ||
settingsEndUserNotification * | string | ||
settingsEnforcementMode * | string |
Crowdstrike Discover Application
crowdstrike_discover_application inherits from Application
| Property | Type | Description | Specifications |
|---|---|---|---|
architectures | array of strings | ||
category | string | ||
firstSeenOn | number | ||
installedOn | number | ||
isNormalized | boolean | ||
isSuspicious | boolean | ||
lastUpdatedOn | number | ||
lastUsedOn | number | ||
vendor | string | ||
version | string | ||
versioningScheme | string |
Crowdstrike Easm Finding
crowdstrike_easm_finding inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
actors * | array | null | ||
aid * | string | ||
assetCriticality * | string | null | ||
baseScore * | number | null | ||
cid * | string | ||
cisaDueDate * | string | null | ||
closedOn * | number | null | ||
exploitabilityScore * | number | null | ||
exploitStatus * | number | null | ||
exprtRating * | string | null | ||
hostname * | string | null | ||
id * | string | ||
impactScore * | number | null | ||
instanceId * | string | null | ||
isCisaKev * | boolean | null | ||
isInternetExposed * | boolean | null | ||
isSuppressed * | boolean | null | ||
localIp * | string | null | ||
osVersion * | string | null | ||
platform * | string | null | ||
productName * | string | null | ||
productVersion * | string | null | ||
publishedOn * | number | null | ||
remediationLevel * | string | null | ||
servicePorts * | array | null | ||
serviceProvider * | string | null | ||
suppressionReason * | string | null | ||
vendor * | string | null | ||
vendorAdvisory * | array | null | ||
vulnerabilityId * | string |
Crowdstrike Endpoint Protection
crowdstrike_endpoint_protection inherits from Service
Crowdstrike External Asset
crowdstrike_external_asset inherits from Resource
| Property | Type | Description | Specifications |
|---|---|---|---|
applicableActions * | array | null | ||
asn * | number | null | ||
assetType * | string | ||
awsRegion * | string | null | ||
cid * | string | ||
cloudProvider * | string | null | ||
confidence * | number | null | ||
countryCode * | string | null | ||
countryName * | string | null | ||
criticalityDescription * | string | null | ||
dataProviders * | array | null | ||
discoveredBy * | string | null | ||
dnsType * | string | null | ||
domainName * | string | null | ||
entityType * | string | null | ||
firstSeenOn * | number | null | ||
fqdn * | string | null | ||
hostingProviders * | array | null | ||
id * | string | ||
ipAddress * | string | null | ||
isAwsHosted * | boolean | null | ||
isAzureHosted * | boolean | null | ||
isGcpHosted * | boolean | null | ||
isInternetExposed * | boolean | null | ||
isp * | string | null | ||
isps * | array | null | ||
lastSeenOn * | number | null | ||
manual * | boolean | null | ||
parentDomain * | string | null | ||
perimeter * | string | null | ||
ptr * | string | null | ||
resolvedIps * | array | null | ||
serviceCount * | number | null | ||
servicePorts * | array | null | ||
serviceProtocols * | array | null | ||
status * | string | null | ||
subsidiaryIds * | array | null | ||
subsidiaryNames * | array | null | ||
timezone * | string | null |
Crowdstrike Falcon Shield Alert
crowdstrike_falcon_shield_alert inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId | string | ||
alertSource | string | ||
alertType | string | ||
detectedOn | number | ||
integrationId | string | ||
integrationName | string | ||
isArchived | boolean | ||
newAffectedCount | number | ||
securityCheckApiLink | string | ||
sourceId | string | ||
threatApiLink | string |
Crowdstrike Falcon Shield App
crowdstrike_falcon_shield_app inherits from Application, NHI
| Property | Type | Description | Specifications |
|---|---|---|---|
accessLevel | string | ||
accountId | string | ||
appDisplayName | string | ||
appId | string | ||
appStatus | string | ||
appStatusReason | string | ||
appType | string | ||
clientId | string | ||
integrationAlias | string | ||
integrationId | string | ||
integrationName | string | ||
lastActivityOn | number | ||
scopes | array of strings |
Crowdstrike Falcon Shield Integration
crowdstrike_falcon_shield_integration inherits from Configuration, Account
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId | string | ||
alias | string | ||
enabled | boolean | ||
integrationStatus | string | ||
lastRunOn | number | ||
saasId | string | ||
saasName | string |
Crowdstrike Firewall Policy
crowdstrike_firewall_policy inherits from ControlPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
channelVersion * | number | ||
cid * | string | ||
createdBy * | string | ||
description * | string | ||
enabled * | boolean | ||
id * | string | ||
modifiedBy * | string | ||
name * | string | ||
platformName * | string | ||
ruleSetId * | string |
Crowdstrike Host
crowdstrike_host inherits from Host
| Property | Type | Description | Specifications |
|---|---|---|---|
agentVersion | string | ||
appliedPolicyCount * | number | null | ||
biosManufacturer * | string | null | ||
biosVersion * | string | null | ||
chassisTypeDescription | string | ||
cid * | string | ||
cloudProvider * | string | null | Canonical, lowercased cloud provider ('aws', 'azure', 'gcp', 'oci') derived from the raw serviceProvider so it matches the cloudProvider on CrowdStrike findings/CSPM entities. Null for non-cloud devices. | |
defaultGatewayIp * | string | null | ||
deploymentType * | string | null | ||
ec2InstanceArn | string | ||
emails * | array | null | Email addresses associated with the host. email and associated_email_addresses are referenced. | |
externalIp * | string | null | ||
filesystemContainmentStatus | string | ||
firstSeenOn | number | ||
groupHash | string | ||
groupIds * | array | null | ||
instanceId * | string | null | CrowdStrike's ID of the cloud VM. Per provider: AWS EC2 id (i-...), Azure VM vmId GUID, GCP numeric instance id, or OCI OCID. | |
isContentUpdatePolicyApplied * | boolean | null | ||
isExposureManagementPolicyApplied * | boolean | null | ||
isGlobalConfigPolicyApplied * | boolean | null | ||
isHostRetentionPolicyApplied * | boolean | null | ||
isPreventionPolicyApplied * | boolean | null | ||
isReducedFunctionalityMode * | boolean | null | ||
isRemoteResponsePolicyApplied * | boolean | null | ||
isScaPolicyApplied * | boolean | null | ||
isSensorUpdatePolicyApplied * | boolean | null | ||
kernelVersion | string | ||
lastLoginUser | string | ||
lastLoginUserSid | string | ||
linuxSensorMode * | string | null | ||
majorVersion * | string | null | ||
minorVersion * | string | null | ||
osKernel | string | ||
ou | array of strings | ||
platformId * | string | null | ||
podAnnotations * | array | null | ||
podLabels * | array | null | ||
policyIds * | array | null | ||
policyTypes * | array | null | ||
provisionStatus | string | ||
serviceProvider * | string | null | Raw CrowdStrike service provider of the asset, e.g. 'AWS_EC2_V2' or 'AZURE'. Use cloudProvider for the normalized value. | |
serviceProviderAccountId * | string | null | ||
zoneGroup * | string | null |
Crowdstrike Image Vulnerability
crowdstrike_image_vulnerability inherits from Finding, Vulnerability
| Property | Type | Description | Specifications |
|---|---|---|---|
cpsCurrentRating | string | ||
cvssScore | number | ||
exploitedStatus | number | ||
remediationAvailable | boolean |
Crowdstrike Image Vulnerability
crowdstrike_image_vulnerability inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
cpsCurrentRating | string | ||
cvssScore | number | ||
exploitedStatus | number | ||
remediationAvailable | boolean |
Crowdstrike Iom Finding
crowdstrike_iom_finding inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | ||
accountName * | string | null | ||
azureTenantId * | string | null | ||
cid * | string | null | ||
cloudProvider * | string | ||
id * | string | ||
numericSeverity * | number | null | ||
policyId * | number | ||
policyStatement * | string | ||
policyType * | string | null | ||
region * | string | null | ||
reportedOn * | number | ||
resourceCreatedOn * | number | null | ||
resourceId * | string | ||
resourceIdType * | string | null | ||
resourceUrl * | string | null | ||
resourceUuid * | string | null | ||
scannedOn * | number | null | ||
service * | string | ||
severity * | string | ||
status * | string |
Crowdstrike Iom Rule
crowdstrike_iom_rule inherits from Rule
| Property | Type | Description | Specifications |
|---|---|---|---|
accountScope * | string | null | ||
attackTypes * | array | null | ||
cid * | string | null | ||
cloudAssetType * | string | null | ||
cloudProvider * | string | null | ||
cloudService * | string | null | ||
cloudServiceFriendly * | string | null | ||
cloudServiceSubtype * | string | null | ||
defaultSeverity * | string | null | ||
fqlPolicy * | string | null | ||
isGlobal * | boolean | null | ||
isRemediable * | boolean | null | ||
policyId * | number | ||
policyTimestampOn * | number | null | ||
policyType * | string | null | ||
remediationSummary * | string | null |
Crowdstrike Prevention Policy
crowdstrike_prevention_policy inherits from ControlPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
cid * | string |
Crowdstrike Prevention Policy Setting
crowdstrike_prevention_policy_setting inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
categoryName * | string | ||
configured | boolean | ||
description * | string | ||
enabled | boolean | ||
type * | string |
Crowdstrike Remediation
crowdstrike_remediation inherits from Record
| Property | Type | Description | Specifications |
|---|---|---|---|
action * | string | null | ||
link * | string | null | ||
patchPublishedOn * | number | null | ||
recommendationType * | string | null | ||
reference * | string | null | ||
vendorUrl * | string | null |
Crowdstrike Sensor
crowdstrike_sensor inherits from HostAgent
| Property | Type | Description | Specifications |
|---|---|---|---|
cloudProvider * | string | null | Canonical, lowercased cloud provider ('aws', 'azure', 'gcp', 'oci') derived from the raw serviceProvider so it matches the cloudProvider on CrowdStrike findings/CSPM entities. Null for non-cloud devices. | |
ec2InstanceArn | string | ||
firstSeenOn | number | ||
macAddress | string | A normalized MAC address for the device's network interface | |
originalMacAddress * | The original MAC address for the device's network interface |
Crowdstrike Serverless Vulnerability
crowdstrike_serverless_vulnerability inherits from Finding, Vulnerability
| Property | Type | Description | Specifications |
|---|---|---|---|
exploitStatus * | string | null | ||
exprtRating * | string | null | ||
exprtRatingHighest * | string | null | ||
firstSeenOn * | number | null | ||
remediations * | array | null | ||
runtime * | string | null | ||
scannerVersion * | string | null |
Crowdstrike User
crowdstrike_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
cid | string | ||
lastLoginOn | number | ||
uid | string |
Crowdstrike Vulnerability
crowdstrike_vulnerability inherits from Finding, Vulnerability
| Property | Type | Description | Specifications |
|---|---|---|---|
aid | string | ||
cid * | string | ||
closedOn | number | ||
confidenceLabel * | string | null | CrowdStrike's confidence that the detection is a true positive (e.g. 'Low', 'Medium', 'High'). The Spotlight console hides 'Low' by default; filter on this to reconcile J1 counts with the dashboard. | |
exploitStatus | number | ||
exprtRating | string | ||
id * | string | ||
isSuppressed * | boolean | null | Whether the detection is hidden by a Spotlight suppression rule. Suppressed detections are excluded from the console by default. | |
productNameVersion | string | ||
publishedOn | number | ||
remediationIds | array of strings | ||
suppressionReason * | string | null | Reason the detection was suppressed, when suppressed. | |
vendorAdvisory | array of strings |
Crowdstrike Vulnerability
crowdstrike_vulnerability inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
aid | string | ||
cid * | string | ||
closedOn | number | ||
confidenceLabel * | string | null | CrowdStrike's confidence that the detection is a true positive (e.g. 'Low', 'Medium', 'High'). The Spotlight console hides 'Low' by default; filter on this to reconcile J1 counts with the dashboard. | |
exploitStatus | number | ||
exprtRating | string | ||
id * | string | ||
isSuppressed * | boolean | null | Whether the detection is hidden by a Spotlight suppression rule. Suppressed detections are excluded from the console by default. | |
productNameVersion | string | ||
publishedOn | number | ||
remediationIds | array of strings | ||
suppressionReason * | string | null | Reason the detection was suppressed, when suppressed. | |
vendorAdvisory | array of strings |
Crowdstrike Zero Trust Assessment
crowdstrike_zero_trust_assessment inherits from Assessment
| Property | Type | Description | Specifications |
|---|---|---|---|
aid | string | ||
cid * | string | ||
eventPlatform * | string | ||
metOsSignals * | array of strings | ||
metSensorSignals * | array of strings | ||
osScore * | number | ||
overallScore * | number | ||
productTypeDescription * | string | ||
sensorConfigScore * | number | ||
sensorFileStatus * | string | ||
systemSerialNumber * | string | ||
unmetOsSignals * | array of strings | ||
unmetSensorSignals * | array of strings | ||
version * | string |
Release Notes
- 2026-07-14 — Vulnerability findings now include a confidence label and suppression status, indicating whether a detection is a confirmed true positive and whether it is hidden in the Spotlight console.
- 2026-03-31 — Promoted OS kernel version property to CrowdStrike host entities, exposing the operating system kernel version.
- 2026-02-20 — Added container image vulnerability assessments via the Image Assessments API, available behind a configuration flag.
- 2026-01-06 — Added CrowdStrike External Attack Surface Management (EASM) vulnerabilities ingestion as new findable entity types.
- 2025-12-10 — Added filtering of CrowdStrike compliance controls by severity.
- 2025-11-05 — Added remediation actions property to CrowdStrike vulnerability entities.
- 2025-10-08 — Added CrowdStrike container vulnerability ingestion, relating containers to their image vulnerabilities.
- 2025-10-03 — Added CrowdStrike Alerts ingestion as alert entities.
- 2025-09-30 — Added Device Unification support for CrowdStrike CSPM resources.
- 2025-09-10 — Added CrowdStrike Azure CSPM ingestion, covering Azure resource findings alongside existing AWS coverage.
- 2025-08-27 — Added host to container image relationships linking CrowdStrike hosts to their running container images.
- 2025-08-22 — Added CrowdStrike compliance controls ingestion as compliance finding entities with policy framework relationships.
- 2025-08-12 — Added CrowdStrike CSPM Phase 2, expanding cloud security posture findings coverage with additional ARN types.
- 2025-08-08 — Added CrowdStrike CSPM Phase 1, ingesting cloud security posture management findings for AWS resources.
- 2025-07-08 — Added image digest property to CrowdStrike container image entities for content-addressable image identification.
- 2025-06-16 — Added CrowdStrike application ingestion using the combined apps endpoint with configurable date filtering.
- 2025-06-02 — Added device remediation actions as device remediation entities.
- 2025-04-22 — Added CrowdStrike Users and device-user relationships ingestion.
- 2025-04-10 — Added CrowdStrike Firewall Policy and Device Control Policy ingestion.