Skip to main content

CrowdStrike

Visualize Crowdstrike endpoint agents and protected devices, map agents to devices and their respective owners, and monitor changes through queries and alerts.

Installation

info

You will need to create an API client in the CrowdStrike Falcon console. See the CrowdStrike API Clients and Configuration documentation for details.

When creating the API client, grant (at minimum) read access to the following scopes:

  • Hosts
  • Prevention Policies

Additional scopes are required to enable optional ingestion steps:

  • Alerts
  • Apps (Falcon Discover applications)
  • Cloud Security API Assets (Compliance Controls)
  • Cloud Security API Detections (IOM Findings)
  • Cloud Security AWS Registration (CSPM)
  • Cloud Security Azure Registration (CSPM)
  • Device control policies
  • External Assets (EASM Findings)
  • Falcon Container Image (Container Security, Serverless Vulnerabilities)
  • Firewall management
  • Kubernetes Protection (Container–host relationships)
  • SaaS Security (Falcon Shield)
  • Spotlight Vulnerabilities (Vulnerabilities, Remediations, EASM Findings)
  • User management
  • Zero Trust Assessment

To install the CrowdStrike integration in JupiterOne, navigate to the Integrations tab and select CrowdStrike. Click New Instance to begin configuring your integration.

Creating an instance requires the following:

  • The Account Name used to identify the CrowdStrike account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName toggle is enabled.

  • An optional Description to help identify the integration instance.

  • A Polling Interval for how frequently data is refreshed. Leave this as DISABLED to trigger runs manually.

  • Your CrowdStrike API client ID and API client secret to authenticate with the Falcon API.

  • An optional Availability Zone for API calls. Leave blank to use the main endpoint (api.crowdstrike.com). For example, entering us-2 routes requests to api.us-2.crowdstrike.com.

Click Create once all values are provided to start the integration.

note

The CrowdStrike integration only ingests applications that have vulnerabilities. Applications without vulnerabilities will not appear in JupiterOne.

Data Volume Configuration

Ingestion Windows

Define how far back in time data is collected during each ingestion run. Each data type has its own configurable window.

FieldDescriptionDefaultOptions
Device Ingestion WindowDays to look back for devices by last-seen date.507, 15, 30, 50, 60, 90, 180, 275, 365
Vulnerabilities Ingestion WindowDays to look back for updated vulnerabilities.9090, 180, 275, 365
Alerts Ingestion WindowDays to look back for updated alerts.9090, 180, 275, 365
Applications Ingestion WindowDays to look back for last-used applications.9090, 180, 275, 365
Containers Ingestion WindowDays to look back for containers by first-seen date.507, 15, 30, 50, 60, 90, 180, 275, 365
Container Image Vulnerabilities Ingestion WindowDays to look back for container image vulnerabilities by first-seen date.36590, 180, 275, 365
EASM Findings Ingestion WindowDays to look back for EASM findings by created date.907, 15, 30, 50, 60, 90, 180, 275, 365
Serverless Vulnerabilities Ingestion WindowDays to look back for serverless vulnerabilities.9090, 180, 275, 365
Serverless Vulnerabilities Page SizeMaximum number of serverless vulnerabilities fetched per API request. Must be a whole number between 1 and 500.(not set)

Data Filtering Options

FieldDescriptionDefaultOptions
Included Vulnerability SeveritiesVulnerability severity levels to ingest. Configure this field or Included Vulnerability Exprt Ratings — not both simultaneously.Critical, High, Medium, UnknownCritical, High, Medium, Low, None, Unknown
Included Vulnerability Exprt RatingsExPRT ratings to use as a vulnerability filter instead of severity levels. When set, severity-based filters are ignored.(not set)Critical, High, Medium, Low, Unknown
Include Closed VulnerabilitiesWhen enabled, ingests vulnerabilities that are marked as closed in CrowdStrike.Disabled
Included Alerts SeveritiesAlert severity levels to ingest.Critical, High, MediumCritical, High, Medium, Low, Informational
Ingest suspicious applications onlyWhen enabled, only applications flagged as suspicious in CrowdStrike are ingested.Disabled
CSPM Cloud ProvidersCloud providers to monitor for CSPM findings, cloud accounts, and IOM findings. If nothing is selected, CSPM data is not ingested.(not set)AWS, Azure
IOM Severity FilterIOM finding severity levels to ingest.CriticalCritical, High, Medium, Informational
Compliance Control SeveritiesCompliance control severity levels to ingest.Critical, HighCritical, High, Medium, Informational, Unknown
Included EASM Finding SeveritiesEASM finding severity levels to ingest.Critical, HighCritical, High, Medium, Low, Unknown
Included Image Vulnerability SeveritiesContainer image vulnerability severity levels to ingest.Critical, HighCritical, High, Medium, Low, Unknown
Serverless Cloud ProvidersCloud providers to ingest serverless vulnerabilities for.AWSAWS, GCP, Azure
Included Serverless Vulnerability SeveritiesServerless vulnerability severity levels to ingest.Critical, HighCritical, High, Medium, Low, None, Unknown

Multi-Tenant (MSSP) Configuration

CrowdStrike Flight Control allows a parent account to manage multiple child CIDs. To enable multi-tenant ingestion:

  1. Enable Configure Child CIDs.
  2. Enter the Parent CID — the CID of the parent CrowdStrike account.

When configured, JupiterOne automatically creates a separate integration instance for each child CID discovered under the parent account.

Next steps

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.