Connect CrowdStrike
Use this guide to connect CrowdStrike endpoint alerts and host data to Cracken.
Prerequisites
- Access to CrowdStrike Falcon → API Clients and Keys
- Permission to create an API client
- A Cracken realm where you can configure data integrations
Prepare the credentials
Create an API client and grant Read for:
- Alerts
- Hosts and Host Groups
- User Management
- Prevention Policies
- Device Control Policies
- Response Policies
- Sensor Update Policies
Record the generated Client ID and Client Secret. The secret is shown once. The connector also needs the API Base URL for your CrowdStrike cloud:
- US-1:
https://api.crowdstrike.com - US-2:
https://api.us-2.crowdstrike.com - EU-1:
https://api.eu-1.crowdstrike.com - US-GOV-1:
https://api.laggar.gcw.crowdstrike.com
Connect CrowdStrike
- Open Integration Center → Data Integrations.
- On the CrowdStrike card, click Install.
- Enter the Base URL, Client ID, and Client Secret.
- Click Test Connection, then Save & Connect.
Cracken can list endpoint alerts and request an on-demand synchronization of the latest results within the API client's assigned scope.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported endpoint data.