> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/remediator/crowdstrike_remediator.md).

# Crowdstrike

## CrowdStrike

The CrowdStrike Remediator integration allows Dropzone AI to perform automated containment actions during investigations. See the [Remediator](/integrations/remediator.md) documentation for more information.

### Integration Overview

To enable these integrations you will perform the following actions:

* Create API credentials in the CrowdStrike dashboard
* Install the credentials into your Dropzone tenant
* Select integration parameters, such as which alert types to sync

See the [CrowdStrike Data Source](https://docs.dropzone.ai/integrations/data/crowdstrike_data) page for instructions on how to complete these actions.

If you have already configured the Data Source integration, you will need to reconfigure it with the following additional remediator scopes:

| Scope                      | Read | Write | Used By    |
| -------------------------- | ---- | ----- | ---------- |
| `Hosts`                    | ✓    | ✓     | Remediator |
| `Indicators of Compromise` | ✓    | ✓     | Remediator |

## Enable CrowdStrike

To enable the Remediator integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8c77435ef341f8180540e049f505d3390a27bbf4%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7e038b4f51ee27d4cf4f1ac6f76c5ddae2bf29c5%2Fapp_system_integrations_library.png?alt=media" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Crowdstrike, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-fe0e7b2cb60a602a9ece242e1cf9eb5481d92d8a%2Fapp_system_integrations_available_CrowdStrike.png?alt=media" alt=""><figcaption><p>The Crowdstrike Tile</p></figcaption></figure>

* Under the Remediator header, input the Client ID and Client Secret
  * If you use a non-default URL for the CrowdStrike API, configure the API Base URL as well

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8a6ae8979f2f92930216696a4bf264b553df0b01%2Fapp_system_integrations_available_crowdstrike_remediator_config_1.png?alt=media" alt=""><figcaption><p>The Crowdstrike Remediator Configuration (pt 1)</p></figcaption></figure>

* In the "Available Containment Actions" section, check the Containment Actions you want to enable Dropzone to perform

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-5c9abcc9f9fc97bf6817aa18e64ae2db14ab10e2%2Fapp_system_integrations_available_crowdstrike_remediator_config_2.png?alt=media" alt=""><figcaption><p>The Crowdstrike Remediator Configuration (pt 2)</p></figcaption></figure>

* Click "Test & Save" to finish

{% hint style="warning" %}
Dropzone does not test that your permissions have been configured correctly when running Remediator Containment Actions. Be sure to double check that your configuration is correct and up to date.
{% endhint %}

If you have any errors engage your Dropzone AI support representative.
