CrowdStrike API resources collector
Overview
The CrowdStrike Falcon platform is a powerful solution that includes EDR (Endpoint Detection and Response), next-generation anti-virus, and device control for endpoints. It also provides a whole host of other operational capabilities across IT operations and security including Threat Intelligence. The CrowdStrike API is managed from the CrowdStrike Falcon UI by the Falcon Administrator. From there, multiple API clients can be defined along with their required scope
Crowdstrike is one of the top data sources for Devo customers and prospects alike, so would encourage new customers to use this one, and existing ones to transition to this one soon.
Data source description
Data Source | Subtype | Table | Service | End Point | Description | Available from release |
Hosts | - |
|
|
Check the | Hosts are endpoints that run the Falcon sensor. You can get information and details about these agents. Refer to the Crowdstrike documentation. |
|
Incidents | - |
|
|
Check the | Incidents are events that occur in an organization which can represent a cybersecurity threat or an attack. |
|
Vulnerabilities | - |
|
|
| Vulnerabilities are known security risks in an operating system, application, hardware, firmware, or other part of a computing stack. |
|
Behaviors | - |
|
|
| Behaviors are patterns of data transmissions in a network that are out of the norm, used to detect anomalies before cyber attacks occur. |
|
Event Stream (eStream) |
|
|
| The endpoints are dynamically generated by following this (simplified) approach:
| The Streaming API provides several types of events. |
|
|
|
| ||||
|
|
| ||||
|
|
| ||||
|
|
| ||||
|
|
| ||||
| Depending on the event’s
|
|
Vendor setup
In order to configure the Devo | CrowdStrike API Resources collector, you need to create an API client that will be used to authenticate API requests.
After getting your Crowdstrike Falcon Cloud credentials, log into the CrowdStrike Falcon Cloud dashboard.
Click the three dots in the left menu bar.
Click API Clients and Keys. This will open a page to create an API client.
Click Add API Client at the top right corner. Enter a CLIENT NAME and DESCRIPTION.
Then, enable the API scopes for your new API client. Click the required Read permissions for each scope and click ADD to create the client.
Finally, copy the Client ID and Client Secret shown on the next screen. You will need these values to configure the collector.
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading ( | Not allowed |
Running environments | Cloud collector, on-premise |
Run the collector
Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (Cloud collector), or deploy and host the collector in your own machine using a Docker image (On-premise collector).
API limitations
Crowdstrike does not apply limitations as long as its use is reasonable.
Change log for 1.x.x
Release | Released on | Release type | Details | Recommendations |
---|---|---|---|---|
| Dec 16, 2021 | FEATURE | New Features:
|
|
| Apr 8, 2022 | IMPROVEMENTS VULNS | Improvements:
Vulnerabilities mitigation:
|
|
| Jul 7, 2022 | IMPROVEMENTS | Improvements:
|
|
| Sep 9, 2022 | IMPROVEMENTS FEATURE | Improvements:
New Features:
|
|
| Sep 15, 2022 | IMPROVEMENTS | Improvements:
|
|
| Sep 15, 2022 | IMPROVEMENTS | Improvements:
Bug Fixing:
|
|