CrowdStrike

CrowdStrike

This guide explains how to integrate CrowdStrike Falcon with RedCarbon.

Overview

The CrowdStrike integration allows RedCarbon to ingest Detections, Incidents, and IOCs from the Falcon platform.

Configuration

To configure the integration, you need to create an API Client in the CrowdStrike Falcon console.

Step 1: Create an API Client

  1. Log in to the CrowdStrike Falcon console.
  2. Navigate to Support and Resources > API Clients and Keys.
  3. Click the Add new API client button in the top right corner.

Create API Client

Step 2: Set Permissions

Configure the API client with the following permissions:

  • Detections: Read
  • Incidents: Read
  • IOCs (Indicators of Compromise): Read
  • Alerts: Read & Write (if you want to update alert status)

Set Permissions

Step 3: Get Credentials

After creating the client, copy the following credentials:

  • Client ID
  • Client Secret
  • Base URL (e.g., https://api.crowdstrike.com)

Copy Credentials

Step 4: Configure RedCarbon

  1. Log in to the RedCarbon Dashboard.
  2. Navigate to the customer's Integrations page.
  3. Select CrowdStrike.
  4. Paste the Client ID, Client Secret, and Base URL.
  5. Select the CrowdStrike product to enable. The products supported by RedCarbon are:
    • Automated Leads Context: active by default on the CrowdStrike platform. Ingests detections, incidents, and IOCs.
    • Data Protection: ingests alerts from the CrowdStrike Data Protection module. Requires Falcon Insight XDR and Falcon Data Protection licenses. Also requires the Data Protection: Read & Write permission on the API client. See the CrowdStrike documentation for details.

Note: If only Data Protection is selected and no alerts are ingested, ensure this product is also enabled in CrowdStrike.

  1. Click Save and then Test to verify the connection.

Configure RedCarbon