🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

CrowdStrike

integrations endpoints vmware crowdstrike edr


The following instructions are for configuring a native ingest of telemetry and detections from CrowdStrike into Secureworks® Taegis™ XDR using Falcon Data Replicator (FDR).

Note

Customers who wish to integrate their CrowdStrike endpoints into XDR will need to purchase the standard Falcon Data Replicator (FDR) from CrowdStrike. Customers will need to contact their CrowdStrike account representative for the pricing details about FDR.

Data Provided from Integration

  Alerts Auth DNS File Collection HTTP NIDS Netflow Process File Modification API Call Registry Scriptblock Management Persistence Thread Injection
Crowdstrike      

Set Up FDR and Gather Information

Please note that we've developed this guide to assist with integrating XDR with CrowdStrike FDR based on our current understanding of the CrowdStrike software, but can't offer a guarantee due to potential changes made by CrowdStrike. We advise you to use the official CrowdStrike documentation to set up your FDR feed and create necessary credentials for the integration. Please consider our instructions as a helping hand to be followed at your discretion as we aim to ease this process for you.

  1. Open Falcon Data Replicator under Support and Resources, or use search within Falcon to locate the feature.

Open FDR from Navigation

Open FDR from Navigation

Open FDR from Search

Open FDR from Search

  1. From Create Feed, enter a feed name, select Customize your FDR feed, and then choose Next.

Create Feed

Create Feed

  1. On the Primary Events tab, select all the event types and then choose + Add selected events.

Select all Event Types

Select all Event Types

  1. On the Secondary Events tab, select all available options.

Select All Secondary Events Options

Select All Secondary Events Options

Important

Make sure both Primary and Secondary events are added to the Feed configuration.

  1. On the Partitions tab, select both partition types.

Select Both Partition Types

Select Both Partition Types

  1. Save the feed credentials presented for your records as this screen is only shown once.

Save Feed Credentials

Save Feed Credentials

Important

Save the authentication information FDR provides as it is never displayed again.

  1. You will need following items to set up the CrowdStrike integration in XDR:

Note

This information can be gathered from the Feed's Overview tab and from the Create feed: copy feed credentials confirmation screen.

Feed Overview

Feed Overview

Set Up CrowdStrike Integration in XDR

  1. From the XDR left-hand side navigation, select Integrations → Cloud APIs → Add API Integration.
  2. Choose Set Up CrowdStrike.

Set up CrowdStrike Integration

Set up CrowdStrike Integration

  1. Provide a name for the integration, and then input the information gathered from the FDR console in the previous section.
  2. Select Add when complete to validate the integration. The Cloud API Integrations page displays with the successfully added CrowdStrike integration listed.

Verification

Use Advanced Search to find alerts relating to this integration with the following query:

FROM alert WHERE sensor_types='ENDPOINT_CROWD_STRIKE'

 

On this page: