> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/alert/crowdstrike_alert.md).

# CrowdStrike

{% hint style="info" %}
Note that this is separate from the "CrowdStrike Falcon Intelligence" Threat intelligence data source.
{% endhint %}

The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Create API credentials in the CrowdStrike dashboard
* Install the credentials into your Dropzone tenant (Data Source and Alert Source)
* Select integration parameters, such as which alert types to sync

## Create an API Key

* As an Admin, go to your CrowdStrike dashboard, e.g. https\://*falcon.us-#*.crowdstrike.com/
* From the menu in the upper left, navigate to Support and Resources > API clients and keys

<figure><img src="/files/sYgCICJsGcFEZFanrpV9" alt="" width="375"><figcaption><p>Click API clients and keys</p></figcaption></figure>

* On the right, click "Create API Client"

<figure><img src="/files/9K9if4XaMkcMrfXPmJEf" alt=""><figcaption><p>Create API Client</p></figcaption></figure>

* On the "Create API Client" page, input "Dropzone AI" in the client name field. Under "Description," write "Dropzone AI Integration Key"

<figure><img src="/files/gLXKDfOdpiPyshDN5q55" alt=""><figcaption><p>Create API Client Screen</p></figcaption></figure>

* Enable the following scopes:

| Scope                         | Read | Write | Used By                        |
| ----------------------------- | ---- | ----- | ------------------------------ |
| Alerts                        | ✓    |       | Alert Source, Data Source      |
| API Integrations              | ✓    |       | Alert Source, Data Source      |
| Cases                         | ✓    | ✓     | Alert Source, Data Source      |
| Detections                    | ✓    |       | Alert Source, Data Source      |
| Hosts                         | ✓    | ✓     | Data Source, Remediator Source |
| NGSIEM                        | ✓    | ✓     | Data Source                    |
| Incidents                     | ✓    |       | Alert Source, Data Source      |
| Quarantined Files             | ✓    |       | Data Source                    |
| Real Time Response            | ✓    | ✓     | Data Source                    |
| Event Streams                 | ✓    |       | Data Source                    |
| Threatgraph                   | ✓    |       | Data Source                    |
| Identity Protection Entities  | ✓    |       | Data Source                    |
| Identity Protection Timeline  | ✓    |       | Data Source                    |
| Identity Protection GraphQL   |      | ✓     | Data Source                    |
| Sandbox (Falcon Intelligence) | ✓    | ✓     | Data Source                    |
| Indicators of Compromise      | ✓    | ✓     | Remediator Source              |

{% hint style="info" %}
Some of these scopes are only necessary for the Data Source or Remediator integration. If you don't intend to perform those integrations, you may ignore them.
{% endhint %}

* Write permission details
  * `Cases`: Write permissions are only required when used in Response Actions
  * `Hosts`: Write permissions are only required when used in Remediator Containment Actions
  * `NGSIEM`: Write permissions are required when NextGen SIEM is enabled in order to execute NGSIEM queries ([docs](https://www.falconpy.io/Service-Collections/NGSIEM.html#startsearchv1))
  * `Real Time Response`: Write permissions are required when File Retrieval is enabled ([docs](https://www.falconpy.io/Service-Collections/Real-Time-Response.html#rtr_executeactiverespondercommand))
    * Dropzone *only* uses Real Time Response to perform `get <file>` commands
  * `Identity Protection GraphQL`: Write permissions are required when Identity Protection is enabled in order to execute queries for user directory information ([docs](https://www.falconpy.io/Service-Collections/Identity-Protection.html#api_preempt_proxy_post_graphql))
  * `Sandbox (Falcon Intelligence`: Write permissions are only required when File Detonation is enabled in order to upload collected or attached files in the Falcon Sandbox
  * `Indicators of Compromise`: Write permissions are only required when used in Remediator Containment Actions
* When done, click "Create"
* Copy the Client ID and Secret for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

<figure><img src="/files/Zx5mxxH4fgn6Z32n0Bhn" alt=""><figcaption><p>Copy your API Credentials</p></figcaption></figure>

## Enable Crowdstrike

The Alert source integration allows Dropzone AI to pull alerts from CrowdStrike for investigation.

You'll need the following information:

| Dropzone Field | Source                                   |
| -------------- | ---------------------------------------- |
| Client ID      | The "Client ID" value you copied earlier |
| Client Secret  | The "Secret" value you copied earlier    |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Available"

<figure><img src="/files/brI7n2Ux40Tk0jTwBCVh" alt=""><figcaption><p>Click Available</p></figcaption></figure>

* In the Search bar, search CrowdStrike, then click "Configure"

<figure><img src="/files/Wv7ZdJQpOMEXUBCsDeE4" alt=""><figcaption><p>The Crowdstrike Tile</p></figcaption></figure>

{% hint style="success" %}
Make sure you're using the EDR CrowdStrike tile, not the "CrowdStrike Falcon Intelligence" Threat Intelligence tile.
{% endhint %}

* Under the Alert Source header, input the Client ID and Client Secret. If you use a non-default URL for the CrowdStrike API, configure the API Base URL as well

<figure><img src="/files/uWUHlkyyF7WeiiNHDXBH" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 1)</p></figcaption></figure>

* If you wish to enable endpoint detection, check the box labeled "Enable Endpoint Detection." Then select the severity levels you want Dropzone to investigate alerts for
* Under Exlusions, you may choose to exclude alerts by display name. To do so, click "Add Item," then input a list of [Python regexes](https://docs.python.org/3/library/re.html) of the alerts you wish to exclude

<figure><img src="/files/ByIUyzsnszDE018qQ5jl" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to enable CrowdStrike's [Next-Gen SIEM](https://developer.crowdstrike.com/docs/ng-siem/) cases, check the box labeled "Enable Next-gen SIEM Cases"
* Input the minimum case severity you want Dropzone to investigate
* Under "Enabled Next-Gen SIEM Case statuses," select the Case statuses you want Dropzone to investigate

<figure><img src="/files/1lVvPYO4rJc9EU7n22EN" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 3)</p></figcaption></figure>

* Under "Case Name Regex Filters," you may choose to filter cases by name. To do so, click "Add Item," then input a list of regexes. Under "Case Name Filter mode," select whether to include or include the cases

<figure><img src="/files/xHeoBdE5HWa8xttRbahf" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 4)</p></figcaption></figure>

* If you wish to enable CrowdStrike's [Next-Gen SIEM](https://developer.crowdstrike.com/docs/ng-siem/) alerts, check the box labeled "Enable Next-gen SIEM Alert"
* Check the box labeled "Include Third Party Sources" if you want Dropzone to be able to ingest Next-gen alerts from other sources integrated into Crowdstrike
* Check the box labeled "Include Falcon Cloud Security Alert" if you want Dropzone to be able to ingest alerts from Crowdstrike's \[Falcon Cloud Security]
* Check the box for each severity level of alerts you want Dropzone to investigate

<figure><img src="/files/q4KUW2q14jBp8AyGqNFt" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 5)</p></figcaption></figure>

* Under "Next-Gen SIEM Alert Exlusions," you may choose to exclude alerts by display name. To do so, click "Add Item," then input a list of regexes to exclude alerts

<figure><img src="/files/615HWaveduLqs71mdpfH" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to enable Drozone to investigate alerts and cases from specific devices, check the box labeled "Enable Device Tag Filtering"
* Input each device tag individually

<figure><img src="/files/snw886YtGdjFs1iZzIS0" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish to enable Dropzone to investigate [identity protection alerts](https://www.crowdstrike.com/wp-content/uploads/2021/06/CrowdStrike-Falcon-Identity-Protection-Modules_DataSheet.pdf), check the box labeled "Enable Identity Protection Alerts"
* Select the severity levels you want Dropzone to investigate alerts for

<figure><img src="/files/SiRZLEV9hWSgjCaiSyYd" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 7)</p></figcaption></figure>

* Input your Crowdstrike UI Domain for ticket linkback
* If you wish to enable Dropzone to fetch original third party alerts, check the box labeled "Fetch Original Third Party Alerts" under "Next-Gen SIEM Alert Enrichment Options"

<figure><img src="/files/nGFum7MfvREUqEjVlCuO" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 8)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/X3lpri9ttCQVhvCj2KzQ" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 9)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/SZ8KkmrQwertPjVhzM0J" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 10)</p></figcaption></figure>

* Click "Test & Save" to finish

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.
