Crowdstrike Falcon Enrichment Out-of-the-Box Integration

Crowdstrike Falcon Enrichment Out-of-the-Box Integration

Notes This integration is currently in Early Access and is available exclusively to Lumu Defender customers. A full roll-out for general availability is scheduled for a later date.
This article describes the required procedure to integrate CrowdStrike Falcon with Lumu for automated data enrichment procedures. This is one of our featured Out-of-the-Box Response Integrations.

Requirements

  • An active Lumu Defender Subscription.
  • An active CrowdStrike platform license.
    • CrowdStrike’s Falcon Insight or Falcon Prevent.

Preliminary setup - CrowdStrike

To set up the integration, you must retrieve the API base URL and create a CrowdStrike API client. To do so, log in to your CrowdStrike Falcon Console and follow these steps:

1. From the menu at the top left side of the screen. Navigate to Support and resources > API clients and keys.


2. Copy and save the API base URL from the OAuth2 API clients window. It is located in the top left corner of the window.


3. On the OAuth2 API clients window, click Create API client. Within the Create API client window, provide a descriptive name and select the appropriate API scopes. Select the Read option for the scopes Alerts, Device Content, and Hosts.



4. Once a new API Client is created, you will have access to the Information needed for the next step in the Lumu Portal.

NotesEnsure you save the API client information, especially the client secret. This is the only time it will be displayed. If lost, it must be reset to generate a new client secret. Then, you must edit your integration credentials in the Lumu portal.

NotesIt is recommended to create one API Client per integration to avoid throttling issues with CrowdStrike. Using the same credential across multiple integrations might cause CrowdStrike to limit the number of API requests during a specific period.

Integration setup - Lumu Portal

This section of the article describes the steps that must be completed on the Lumu portal to properly set up the CrowdStrike Falcon integration.To start, log into your Lumu account through the Lumu Portal.

1. In the Lumu Portal, head to the panel on the left and go to Integrations > Apps.


2. Go to the Available Apps tab and select the Enrichment option. Then, Locate the CrowdStrike Falcon integration in the available apps area and click Add.


3. Review the detailed description provided for the app to understand the integration and click Activate to proceed with the integration.


4. Provide a meaningful Name, select the Base URL, and enter the Client ID and Client Secret you collected in step 4 of the Preliminary setup - CrowdStrike section. When finished, click Activate to complete the integration.


5. Once the integration is activated, you can see its details.