Skip to main content

CrowdStrike

Integrate CrowdStrike with Cloudaware to ingest hosts, detections, policies, and vulnerabilities for unified security reporting and correlation with applications and assets.

info
  • Audience: Cloudaware administrators, SecOps
  • Outcome: The CrowdStrike account is connected, and hosts, detections, policies, and vulnerability data are available in the CMDB for security reporting and correlation

Capabilities

The integration supports:

  • Read-only discovery of CrowdStrike hosts, groups, detections, policies, and vulnerabilities in the CMDB
  • Relationships between CrowdStrike detections, affected assets, applications, and related infrastructure
  • Security reporting for detection trends, endpoint coverage, and vulnerability context in Cloudaware

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • CrowdStrike Falcon Client ID and Client Secret.
  • Environment or region matching your CrowdStrike Falcon tenant.
  • API scopes for sensor download, detections, hosts, host groups, and vulnerabilities.

Add a CrowdStrike Account to Cloudaware

To connect your CrowdStrike account to Cloudaware:

  1. In Cloudaware, go to Admin.
  2. Find CrowdStrike, then click + ADD.
  3. Enter the following values:
    • Name: A display name for this connection
    • Client ID: The CrowdStrike Falcon API client ID
    • Client Secret: The CrowdStrike Falcon API client secret
    • Environment: The environment or region that matches your Falcon tenant
  4. Click SAVE.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View CrowdStrike Data in CMDB

To browse discovered CrowdStrike resources:

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select CROWDSTRIKE.
  3. Open an object list, e.g., CrowdStrike Hosts or CrowdStrike Detections, to view records.

Supported Objects

Cloudaware ingests the following CrowdStrike objects:

CrowdStrike ObjectCMDB Object API Name
CrowdStrike AccountCA10CR__CaCrowdstrikeAccount__c
CrowdStrike DetectionCA10CR__CaCrowdstrikeDetection__c
CrowdStrike Detection BehaviorCA10CR__CaCrowdstrikeDetectionBehavior__c
CrowdStrike GroupCA10CR__CaCrowdstrikeGroup__c
CrowdStrike HostCA10CR__CaCrowdstrikeHost__c
CrowdStrike Host Group LinkCA10CR__CaCrowdstrikeHostGroupLink__c
CrowdStrike Sensor Update PolicyCA10CR__CaCrowdstrikeSensorUpdatePolicy__c
CrowdStrike Sensor Update Policy Group LinkCA10CR__CaCrowdstrikeSensorUpdatePolicyGroupLink__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify the Client ID and Client Secret values.
  • Confirm that the selected Environment matches your CrowdStrike Falcon tenant.
  • Check that the API client is active in CrowdStrike.
  • Re-enter the credentials by editing the integration in Cloudaware.

Required Objects Are Missing or Access Errors Appear

  • Confirm that the CrowdStrike API client has the required scopes for sensor download, detections, hosts, host groups, and vulnerabilities.
  • Review the error message to identify which object or endpoint is not accessible.
  • Update the CrowdStrike API client scopes if a required permission is missing.

No Data Appears After a Successful Save

  • Allow the initial discovery cycle to complete.
  • Confirm that the CrowdStrike tenant contains hosts, detections, policies, or vulnerabilities that the API client can read.
  • In CMDB Navigator, verify that you are viewing the CROWDSTRIKE section and related resources.

Changes in CrowdStrike Are Not Yet Visible in Cloudaware

  • Synchronization is periodic. Wait for the next cycle or contact support to review the schedule.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate credentials, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select CrowdStrike.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select CrowdStrike.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated CrowdStrike API client with the minimum required read scopes for Cloudaware discovery.
  • Avoid granting write, remediation, or administrative scopes unless Cloudaware specifically requires them for your deployment.
  • Rotate the Client Secret according to your organization's credential-rotation policy.
  • Update the Cloudaware integration immediately if the Client Secret is revoked or regenerated in CrowdStrike.
  • Credentials are stored securely and are only visible to Cloudaware collector.