Integrating with CrowdStrike

CrowdStrike integration with ThreatStream enables you to use the following CrowdStrike operators in Search:

  • cs_get_alert_entities

  • cs_get_process_detail

  • cs_get_system_info

  • cs_hunt_domain

  • cs_hunt_file

  • cs_hunt_ip

  • cs_list_users

  • cs_query_alerts

  • cs_query_device

See CrowdStrike Operators for details on CrowdStrike operators.

Before You Begin

Before activating the CrowdStrike integration, you must obtain your CrowdStrike Client ID, Secret, and Base URL.

To obtain your Crowdstrike Client ID, Secret, and Base URL:

  1. Log in to your CrowdStrike account.

  2. Navigate to Support and resources > API Clients and Keys.

  3. In the API Clients section, click Create API client.

  4. In the Add new API client window: 

    1. Enter a name for the API client (for example, Anomali API).

    2. (Optional) Enter a description.

    3. Select the following minimum required API scopes:

      • Alerts: READ

      • Detections: READ

      • Hosts: READ

      • IOCs (Indicators of Compromise): READ

      • User Management: READ

  5. Click Add.

  6. In the API client dialog box that opens, copy the API Client ID, Secret, and Base URL.
    Save the information in a safe location. If you lose it, you will have to generate a new secret.

  7. Click Done.

Activating the CrowdStrike Integration

To active the CrowdStrike integration:

  1. In the bottom-left corner of the side navigation panel, click > ThreatStream > Integrations.

  2. On the Crowdstrike Operator tile, click Activate.

  3. Enter your CrowdStrike Client ID, Client Secret, and Base URL.

  4. Click Save.

The integration is now ready for use.