crowdstrike alert.md

CrowdStrike

The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.

Integration Overview

To enable these integrations you will perform the following actions:

Create an API Key

Scope Read Write Used By
Alerts Alert Source, Data Source
API Integrations Alert Source, Data Source
Cases Alert Source, Data Source
Detections Alert Source, Data Source
Hosts Data Source, Remediator Source
NGSIEM Data Source
Incidents Alert Source, Data Source
Quarantined Files Data Source
Real Time Response Data Source
Event Streams Data Source
Threatgraph Data Source
Identity Protection Entities Data Source
Identity Protection Timeline Data Source
Identity Protection GraphQL Data Source
Sandbox (Falcon Intelligence) Data Source
Indicators of Compromise Remediator Source

Enable Crowdstrike

The Alert source integration allows Dropzone AI to pull alerts from CrowdStrike for investigation.

You'll need the following information:

Dropzone Field Source
Client ID The "Client ID" value you copied earlier
Client Secret The "Secret" value you copied earlier

To enable the Alert Source integration, do the following:

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.