Interpres Application - CrowdStrike Falcon
- Type: Endpoint
- Vendor: Crowsstrike
The CrowdStrike app will process CrowdStrike Detections and turn them into the Alert and Detection DataModel for Interpres. This includes both the Behavioral and Custom IOA based detections
Vendor setup
Go to Support and Resources then API clients and keys
- Click Create API client
- For Client name enter "Interpres"
- Add the below Scopes as with the "Read" permission
Assets
Alerts
Custom IOA rules
Detections
Device control policies
Hosts
Host groups
Incidents
IOA Exclusions
Machine Learning Exclusions
Prevention policies
Response policies
Sensor update policies
Sensor Visibility Exclusions
Zero Trust Assessment
- Click Create
- Copy the Client ID, Secret, and Base URL to Interpres. If setting up more than one CrowdStrike integration (e.g. CrowdStrike Falcon EDR and CrowdStrike Spotlight) then do not click Done until you have used these credentials for both integrations.
App Configuration
App Parameters:
- Base URL: The base url for the api this should just be scheme + host e.g.
https://api.us-2.crowdstrike.com - Client ID: The API Client ID created
- Client Secret: The API Secret created
- Asset FQDN: Only grab assets with this fully qualified domain name
App Validation
Check there is connectivity (green light) in the integration created.
Implemented Actions
-
Get Alerts: Retrieves Falcon alerts.
-
Get Available Telemetry: This action just returns a predefined set of telemetry that Crowdstrike provides if it is in use.
- file access telemetry
- file creation telemetry
- file modification telemetry
- file deletion telemetry
- network connection creation telemetry
- active dns telemetry
- command execution telemetry
- process access telemetry
- process creation telemetry
- process metadata telemetry
- scheduled job creation telemetry
- scheduled job deletion telemetry
- scheduled job metadata telemetry
- scheduled job modification telemetry
- user account authentication telemetry
- user account creation telemetry
- windows registry key access telemetry
- windows registry key creation telemetry
- windows registry key deletion telemetry
- windows registry key modification telemetry
- wmi creation telemetry
-
Get Detections: Creates detections from Falcon alerts that have already been triggered. CrowdStrike does not provide direct visibility into all detections. This action also includes predefined Endpoint Protection Platform detections.


