CrowdStrike Falcon and ThreatSync Integration Guide

CrowdStrike Falcon is a cloud-native endpoint security and XDR platform that provides endpoint detection and response, threat intelligence, incident management, and real-time visibility.

This document describes the steps to integrate CrowdStrike Falcon in ThreatSync, which enables you to view and manage incidents generated by CrowdStrike Falcon in the ThreatSync Management UI. This centralizes detection and response activities across environments and provides broader incident visibility.

Contents

Integration Summary

The hardware and software used in this guide includes:

  • CrowdStrike Falcon

Before You Begin

Before you begin these procedures, make sure that:

  • You have ThreatSync enabled in WatchGuard Cloud.
  • You have a ThreatSync Open license allocated in WatchGuard Cloud.
  • You have a CrowdStrike Falcon global administrator or user management administrator account.

Create the CrowdStrike Falcon API Client

Before you configure the integration in ThreatSync, you must create an OAuth 2.0 API client in CrowdStrike Falcon. You will use the Client ID and Secret values to connect to CrowdStrike Falcon from ThreatSync.

  1. Log in to the CrowdStrike Falcon management console as an administrator.
  2. Select Support and Resources > API Clients and Keys.
  3. Screen shot of the CrowdStrike Falcon Support and resources page with API clients and keys highlighted

  4. On the OAuth2 API Clients page, select Create API Client.
  5. Screen shot of the CrowdStrike Falcon OAuth2 API clients page

  6. In the Create API Client dialog box, enter a client name and description. 
  7. Screen shot of the Create API client dialog box

  8. In the Scope section, enable the Readcheck box forAlerts, API Integrations, and App Logs
  9. Screen shot of the Create API client dialog box with scopes selected

  10. Click Create
  11. The API Client Created dialog box appears.
  12. Copy the Client ID, Secret, and Base URL values to a secure location.
  13. Screen shot of the API client created dialog box with Client ID, Secret, and Base URL

Paste the copied information to a secure location. The information is only shown once; if you lose it you must reset the client and generate a new Secret.

  1. Click Done.

Configure the Integration in ThreatSync

  1. Log in to WatchGuard Cloud with WatchGuard Cloud operator account credentials.

    If you log in as a Service Provider, select a Subscriber account from Account Manager.
  2. Select Configure > ThreatSync > Integrations.
  3. Click Add Integration.
  4. From the Product drop-down list, select CrowdStrike Falcon.
  5. In the Name text box, enter a name for the integration. For example, CrowdStrike Integration.
  6. In the Client ID text box, enter the client ID you retrieved from the CrowdStrike management console.
  7. In the Secret Key text box, enter the API token you retrieved from the CrowdStrike management console.
  8. (Optional) In the Description text box, enter a description for the integration.
  9. Click Save.
  10. Screen shot of the ThreatSync Add Integration page for CrowdStrike Falcon

After you save, the new integration appears in the Integrations table on the Integrations page.

Test the Integration

  1. Log in to WatchGuard Cloud.
    If you log in as a Service Provider, select a Subscriber account from Account Manager.
  2. Select Configure > ThreatSync > Integrations.
  3. In the table, locate the integration you created. Verify the Status of the integration is Success.