Crowdstrike Falcon Insight

Samurai [Local] CollectorSamurai [Cloud] Collector
Picture1.svg

To complete this Integration you will need to:

1) From the Crowdstrike Falcon Console:

2) From the Samurai MDR portal:

3) Complete and send authorization form

Create a new API client

For additional information you can refer to the Crowdstrike documentation

To create a new API client follow the steps below:

  1. Log in to the Crowdstrike Falcon Console

  2. Click the Support and resources icon in the left menu pane.

  3. Under Resources and tools select API Clients and Keys. The API Clients and Keys page is displayed.

  4. Click Create API client. The Create API client page appears.

  5. Perform the following steps:

    5.1 Specify NTT API Client in the CLIENT NAME field.

    5.2 Specify API client for NTT in the DESCRIPTION field.

    5.3 Under API SCOPES, perform the following steps:

    5.4 Select the Read checkbox for:

    • Detections
    • Event Streams
    • Host groups
    • Hosts
    • Prevention policies
    • Threatgraph
    • User Management

    5.5 Select the Write checkbox for:

    • Hosts
  6. Click Create to save the API client and generate the client ID and secret.

  7. Copy and record the values:

    • CLIENT ID
    • SECRET
  1. Take note of your Cloud location which is dervived from the Base URL as per the table below, you will need to specify the cloud location under Complete the Crowdstrike Falcon Insight Integration.

The table below outlines the Cloud location and Base URL:

Cloud LocationBase URL
US-1https://api.crowdstrike.com
US-2https://api.us-2.crowdstrike.com
EU-1https://api.eu-1.crowdstrike.com
US-GOV-1https://api.laggar.gcw.crowdstrike.com

Complete the Crowdstrike Falcon Insight Integration

You will need:

  1. Login to the Samurai MDR portal

  2. Click Telemetry and select Integrations from the main menu

  3. Select Create

  4. Locate and click Crowdstrike Falcon Insight

  5. Click Next (we leverage a Samurai Cloud Collector)

  6. Enter a Name of Integration

  7. Enter a Description (Optional)

  8. Enter your OAuth Client ID

  9. Enter your OAuth Secret

  10. Select your Cloud Location (US-1 is default). 

  11. Click Finish

Complete and send authorization form

The Samurai SOC requires access to your Crowdstrike instance in order to:

  • Perform deeper investigations
  • Access data not present in the APIs
  • Perform remote isolation tasks

To ensure the Samurai SOC has access please complete this form Authorization Form for Access to Crowdstrike Falcon Host by MSP Personnel.

Once you have completed, email the form to mssp@crowdstrike.com.

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai MDR application and we shall get it updated.