The Cloud Security Connector is currently in development and will be expanded with additional Providers and queries in the future.
The CrowdStrike Cloud Security Provider uses OAuth 2.0 client credentials for authentication, and requires the use of a Client ID and Secret.
Before you begin, ensure you have:
- Access to the CrowdStrike Falcon Console
- Administrator privileges
- Log in to your CrowdStrike Console instance with administrative privileges.
- Go to the Support and resources > Resources and tools > API Client and keys section where an API Client can be managed.
- Create an API Client
- Provide a Client name and a related description with read permissions for the following Scopes
- CSPM registration
- Cloud Security Assets
- Create the new API Client.
- Securely store the generated Client ID, Secret and Base URL
The Base URL for your CrowdStrike environment. This can be found in the CrowdStrike Base URLs documentation.
The OAuth2.0 Client ID is generated when the new API Client is created via the API Client and keys section in the CrowdStrike Console.
The OAuth2.0 Client Secret is generated when the new API Client is created via the API Client and keys section in the CrowdStrike Console.
The token_url should not be set or configured when setting up the Integration.