Dropzone AI Documentation
WebsiteTest Drive
  • Dropzone Documentation
  • Overview
    • Alert Sources
    • Data Sources
    • Communicators
    • On-prem Support - Dropzone Connector
    • Interactive Chat
    • Metrics Guide
  • Dropzone Administraton
    • Team Admin
      • Google Workspace SAML
      • Okta SAML
  • Dropzone Integrations
    • Alert + Data Source Integrations
      • Amazon Web Services (AWS)
        • Cross-Account Access via CloudFormation
        • Cross-Account Access via Console
      • CrowdStrike
      • Datadog
      • Elasticsearch
      • Google Workspace
      • Google GCP
      • Jira
      • Microsoft 365 / Microsoft Defender
      • Palo Alto Networks Firewall
      • Panther
      • SentinelOne
      • Splunk
      • Sumo Logic
    • Alert Integrations
      • Gem
    • Communicators
      • Slack Communicator
    • Data Source Integrations
      • AbuseIPDB
      • Active Directory (LDAP)
      • Archive Inspector
      • Blocklist.de
      • CAPA
      • Censys
      • Crowdstrike Falcon Intelligence
      • DNSResolver
      • File
      • GreyNoise
      • Hybrid Analysis
      • Host.io
      • IPInfo.io
      • IPQualityScore
      • MalwareBazaar
      • Nuclei
      • NVD
      • Okta
      • oletools
      • OpenSSL Sign Code
      • PDF Analysis
      • Perplexity AI
      • PhishTank
      • Shodan
      • TShark
      • QRadar
      • UnshortenMe
      • URLhaus
      • Urlscan.io
      • VirusTotal
      • Vision
      • WHOIS
      • YARAify
Powered by GitBook
On this page
  • Integration Overview
  • Create API Credentials
  • Enable The Dropzone Data Source Integration
  • Enable The Dropzone Alert Source Integration

Was this helpful?

  1. Dropzone Integrations
  2. Alert + Data Source Integrations

CrowdStrike

PreviousCross-Account Access via ConsoleNextDatadog

Last updated 7 days ago

Was this helpful?

This is a combined document for enabling the Dropzone AI Data Source and Alert Source for CrowdStrike.

Note that this is separate from the "CrowdStrike Falcon Intelligence" Threat intelligence data source.

The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.

Integration Overview

To enable these integrations you will perform the following actions:

  • Create API credentials in the CrowdStrike dashboard

  • Install the credentials into your Dropzone tenant (Data Source and Alert Source)

  • Select integration parameters, such as which alert types to sync

Create API Credentials

  • As an Admin, go to your CrowdStrike dashboard, e.g. https://falcon.us-#.crowdstrike.com/

  • From the menu in the upper left, select "Support and Resources" > "API clients and keys"

  • On the right, click on "Create API Client"

  • On the "Create API Client" page

    • Client name: "Dropzone AI"

    • Description: "Dropzone AI Integration Key"

  • Enable the following scopes:

Scope
Read
Write
Used By

Alerts

✓

Alert Sources, Data Source

API Integrations

✓

Alert Sources, Data Source

Detections

✓

Alert Sources, Data Source

Hosts

✓

Data Source

NGSIEM

✓

✓

Data Source

Incidents

✓

Alert Sources, Data Source

Quarantined Files

✓

Data Source

Real Time Response

✓

✓

Data Source

Event Streams

✓

Data Source

Threatgraph

✓

Data Source

Identity Protection Entities

✓

Data Source

Identity Protection Timeline

✓

Data Source

Identity Protection GraphQL

✓

Data Source

  • Click "Create" when done selecting the above scopes

  • Record the Client ID and Secret for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

Enable The Dropzone Data Source Integration

The Data source integration allows Dropzone AI to interact with your CrowdStrike environment to gather information for use in investigation analysis and interactive chat.

You'll need the following information:

Dropzone Field
Source

Client ID

The "Client ID" from the API Credentials

Client ID

The "Secret" from the API Credentials

To enable the Data Source integration, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.ai

  • Click System > Integrations

  • Click "Available"

  • In the Search bar, search CrowdStrike, then click "Configure"

Make sure you're using the EDR CrowdStrike tile, not the "CrowdStrike Falcon Intelligence" Threat Intelligence tile.

  • Under the Data Source header, input the Client ID and Client Secret

  • Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.

Enable The Dropzone Alert Source Integration

The Alert source integration allows Dropzone AI to pull alerts from CrowdStrike for investigation.

You'll need the following information:

Dropzone Field
Source

Client ID

The "Client ID" from the API Credentials

Client ID

The "Secret" from the API Credentials

To enable the Alert Source integration, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.ai

  • Click System > Integrations

  • Click "Available"

  • In the Search bar, search CrowdStrike, then click "Configure"

Make sure you're using the EDR CrowdStrike tile, not the "CrowdStrike Falcon Intelligence" Threat Intelligence tile.

  • Under the Alert Source header, input the Client ID and Client Secret

  • Check the severity levels you want to ingest

  • Under Exclusion, you may check to enable exclusions from investigations

  • Click "Test & Save" to finish

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.

API clients and keys
Create API Client
Create API Client Screen
API Credentials - save these for later
Integrations Dropdown
Click Available
The Crowdstrike Tile
The CrowdStrike Data Source Configuration
Integrations Dropdown
Click Available
The Crowdstrike Tile
The CrowdStrike Alert Source Configuration (pt 1)
The CrowdStrike Alert Source Configuration (pt 2)