Skip to main content

Connect CrowdStrike Spotlight

Use this guide to import CrowdStrike Exposure Management vulnerability data into Cracken.

Prerequisites

  • CrowdStrike Exposure Management enabled
  • Access to CrowdStrike Falcon → API Clients and Keys
  • Permission to create an API client
  • A Cracken realm where you can configure data integrations

Prepare the credentials

Create an API client and grant Read for:

  • Vulnerabilities
  • Hosts and Host Groups
  • User Management
  • Prevention Policies
  • Device Control Policies
  • Response Policies
  • Sensor Update Policies

Record the generated Client ID and Client Secret. The secret is shown once. Select the API Base URL for your cloud:

  • US-1: https://api.crowdstrike.com
  • US-2: https://api.us-2.crowdstrike.com
  • EU-1: https://api.eu-1.crowdstrike.com
  • US-GOV-1: https://api.laggar.gcw.crowdstrike.com

Connect CrowdStrike Spotlight

  1. Open Integration Center → Data Integrations.
  2. On the CrowdStrike Spotlight card, click Install.
  3. Enter the Base URL, Client ID, and Client Secret.
  4. Click Test Connection, then Save & Connect.

Cracken can list vulnerability findings and request an on-demand synchronization of the latest results within the API client's assigned scope.

Sources

Next steps

  • Data Integrations — Review how connected security data flows into Cracken.
  • Cybergraph — See how Cracken uses imported vulnerability data.