CrowdStrike | Dropzone AI Documentation
For the complete documentation index, see llms.txt. This page is also available as Markdown.
Note that this is separate from the "CrowdStrike Falcon Intelligence" Threat intelligence data source.
The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.
Integration Overview
To enable these integrations you will perform the following actions:
Create API credentials in the CrowdStrike dashboard
Install the credentials into your Dropzone tenant (Data Source and Alert Source)
Select integration parameters, such as which alert types to sync
Create an API Key
As an Admin, go to your CrowdStrike dashboard, e.g. https:// falcon.us-#.crowdstrike.com/
From the menu in the upper left, navigate to Support and Resources > API clients and keys
Click API clients and keys
- On the right, click "Create API Client"
Create API Client
On the "Create API Client" page, input "Dropzone AI" in the client name field. Under "Description," write "Dropzone AI Integration Key"
Enable the following scopes:
| Scope | Read | Write | Used By |
|---|---|---|---|
| Alerts | ✓ | Alert Source, Data Source | |
| API Integrations | ✓ | Alert Source, Data Source | |
| Cases | ✓ | ✓ | Alert Source, Data Source |
| Detections | ✓ | Alert Source, Data Source | |
| Hosts | ✓ | ✓ | Data Source, Remediator Source |
| NGSIEM | ✓ | ✓ | Data Source |
| Incidents | ✓ | Alert Source, Data Source | |
| Quarantined Files | ✓ | Data Source | |
| Real Time Response | ✓ | ✓ | Data Source |
| Event Streams | ✓ | Data Source | |
| Threatgraph | ✓ | Data Source | |
| Identity Protection Entities | ✓ | Data Source | |
| Identity Protection Timeline | ✓ | Data Source | |
| Identity Protection GraphQL | ✓ | Data Source | |
| Sandbox (Falcon Intelligence) | ✓ | ✓ | Data Source |
| Indicators of Compromise | ✓ | ✓ | Remediator Source |
Some of these scopes are only necessary for the Remediator integration. If you don't intend to perform this integration, you may ignore them.
Write permission details
Cases: Write permissions are only required when used in Response ActionsHosts: Write permissions are only required when used in Remediator Containment ActionsNGSIEM: Write permissions are required when NextGen SIEM is enabled in order to execute NGSIEM queries (docs)Real Time Response: Write permissions are required when File Retrieval is enabled (docs)- Dropzone only uses Real Time Response to perform
get <file>commands Identity Protection GraphQL: Write permissions are required when Identity Protection is enabled in order to execute queries for user directory information (docs)Sandbox (Falcon Intelligence: Write permissions are only required when File Detonation is enabled in order to upload collected or attached files in the Falcon SandboxIndicators of Compromise: Write permissions are only required when used in Remediator Containment Actions
When done, click "Create"
Copy the Client ID and Secret for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively
Enable Crowdstrike
The Data source integration allows Dropzone AI to interact with your CrowdStrike environment to gather information for use in investigation analysis and interactive chat.
You'll need the following information:
| Dropzone Field | Source |
|---|---|
| Client ID | The "Client ID" value you copied earlier |
| Client Secret | The "Secret" value you copied earlier |
To enable the Data Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https:// mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations
Click "Available"
In the Search bar, search CrowdStrike, then click "Configure"
Make sure you're using the EDR CrowdStrike tile, not the "CrowdStrike Falcon Intelligence" Threat Intelligence tile.
Under the Data Source header, input the Client ID and Client Secret. If you use a non-default URL for the CrowdStrike API, configure the API Base URL as well
Check the boxes to enable Crowdstrike's Identity Protection, Next-Gen SIEM, Real Time Response, and Falcon Sandbox services
These services are optional, but enabling them enhances the quality of Dropzone investigations
Enabling "file reputation lookup" for Falcon Sandbox will allow Dropzone to retrieve files in the Falcon Sandbox.
Enabling "file detonation" will allow Dropzone to upload collected or attached files in the Falcon Sandbox. Dropzone will wait the the "Max detonation wait time" for results from the detonation before proceeding with investigation.
Only check
Special Member CID Handlingif your Dropzone AI representative indicates that your environment requires itClick "Test & Save" to finish
If you have any errors engage your Dropzone AI support representative.