Connect CrowdStrike Spotlight
Use this guide to import CrowdStrike Exposure Management vulnerability data into Cracken.
Prerequisites
- CrowdStrike Exposure Management enabled
- Access to CrowdStrike Falcon → API Clients and Keys
- Permission to create an API client
- A Cracken realm where you can configure data integrations
Prepare the credentials
Create an API client and grant Read for:
- Vulnerabilities
- Hosts and Host Groups
- User Management
- Prevention Policies
- Device Control Policies
- Response Policies
- Sensor Update Policies
Record the generated Client ID and Client Secret. The secret is shown once. Select the API Base URL for your cloud:
- US-1:
https://api.crowdstrike.com - US-2:
https://api.us-2.crowdstrike.com - EU-1:
https://api.eu-1.crowdstrike.com - US-GOV-1:
https://api.laggar.gcw.crowdstrike.com
Connect CrowdStrike Spotlight
- Open Integration Center → Data Integrations.
- On the CrowdStrike Spotlight card, click Install.
- Enter the Base URL, Client ID, and Client Secret.
- Click Test Connection, then Save & Connect.
Cracken can list vulnerability findings and request an on-demand synchronization of the latest results within the API client's assigned scope.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported vulnerability data.