CrowdStrike

The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.

Integration Overview

To enable these integrations you will perform the following actions:

  • Create API credentials in the CrowdStrike dashboard

  • Install the credentials into your Dropzone tenant (Data Source and Alert Source)

  • Select integration parameters, such as which alert types to sync

Create an API Key

  • As an Admin, go to your CrowdStrike dashboard, e.g. https://falcon.us-#.crowdstrike.com/

  • From the menu in the upper left, navigate to Support and Resources > API clients and keys

Click API clients and keys
  • On the right, click "Create API Client"

Create API Client
  • On the "Create API Client" page, input "Dropzone AI" in the client name field. Under "Description," write "Dropzone AI Integration Key"

Create API Client Screen
  • Enable the following scopes:

Scope
Read
Write
Used By

Alerts

Alert Sources, Data Source

API Integrations

Alert Sources, Data Source

Detections

Alert Sources, Data Source

Hosts

Data Source

NGSIEM

Data Source

Incidents

Alert Sources, Data Source

Quarantined Files

Data Source

Real Time Response

Data Source

Event Streams

Data Source

Threatgraph

Data Source

Identity Protection Entities

Data Source

Identity Protection Timeline

Data Source

Identity Protection GraphQL

Data Source

  • When done, click "Create"

  • Copy the Client ID and Secret for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

Copy your API Credentials

Enable Crowdstrike

The Data source integration allows Dropzone AI to interact with your CrowdStrike environment to gather information for use in investigation analysis and interactive chat.

You'll need the following information:

Dropzone Field
Source

Client ID

The "Client ID" value you copied earlier

Client Secret

The "Secret" value you copied earlier

To enable the Data Source integration, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app

  • In the bottom left hand corner, navigate to Settings > Integrations

Integrations Dropdown
  • Click "Available"

Click Available
  • In the Search bar, search CrowdStrike, then click "Configure"

The Crowdstrike Tile
The CrowdStrike Data Source Configuration
  • Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.

Last updated

Was this helpful?