Crowdstrike Falcon
Overview
CrowdStrike Falcon is an Endpoint Detection and Response solution. This setup guide shows how to forward device assets created in CrowdStrike Falcon to Sekoia.io.
- Vendor: CrowdStrike
- Product: CrowdStrike Falcon
- Supported environment: SaaS
Configure
How to create an API token
To connect CrowdStrike Falcon to Sekoia.io, you need to create an API key pair (Client id and Client secret) in your CrowdStrike Falcon console. Follow these steps:
-
Log in to the CrowdStrike interface.
-
Click on the burger menu and go to Support and
resources>Resources and tools>API client and keys.
-
In the
OAuth2 API Clientstab, create a newOAuth2 API Clientwith theReadandWritepermissions for the scopesUser Management.
-
Copy the api key in a safe place and start using it in Sekoia.io.
Create your asset
To start getting your CrowdStrike assets into Sekoia.io, you need to create an asset connector on the Assets page. To do so, follow these steps:
-
Click the Asset connectors button to create a new connector.

-
Click the + New connector button.

-
Choose CrowdStrike Falcon devices, give it a name, and fill the required fields:

-
Test the connection by clicking the Test connector button.

-
Click the Create asset connector button.