Note: This guide is specific to the CrowdStrike Complete service. For CrowdStrike Falcon, use the CrowdStrike Falcon getting started guide instead.
Note: Our guide was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave us a description in the comment field below and let us know!
Step 1: Enable console access
Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
Expel is a CrowdStrike Certified Managed Security Provider partner. To allow the Expel partner console access to your console, do the following:
- Print, complete, and sign the CrowdStrike MSP Authorization Form. This form can be provided by the Expel Solutions Architect, Engagement Manager or Customer Success Engineer.
- Attach the completed form in an email to Falcon Complete Support. An Expel Customer Success Engineer can help and can provide a template to send to Falcon Complete Support.
To integrate the technology with Expel, we need to create secure credentials to the API.
Step 2: Enabling the OAuth2 API
To enable the OAuth2 API, follow the steps below:
- After logged into the Falcon UI, navigate to Support > API Clients and Keys.
- If API Clients and Keys doesn't appear in your Falcon UI, we need to reach out to Falcon Support to get it enabled for the integration. An Expel Customer Success Engineer can help you with this.
- Select Add new API Client.
- Type Expel as the Client Name.
- Type Expel API Access as the Description.
- Select the following permissions:
-
Read for Detections.
-
Read for Hosts.
-
Read for Incidents.
-
Read for IOCs (Indicators of Compromise).
-
Read for Real Time Response.
-
- Click Save.
-
Make a record of your Client, Client Secret and Base URL for the API.
- Go to Step 3 to enter these credentials into Workbench.
Step 3: Configure the technology in Workbench
Now that we have all the correct access configured and have noted the credentials, we can integrate CrowdStrike Falcon Complete with Expel.
Register device in Expel Workbench
- Login to https://workbench.expel.io/settings/security-devices?setupIntegration=crowdstrike.
- For Name type the hostname of the device.
- For Location type the geographic location of the appliance.
- After typing the name and location, complete the remaining fields using the credentials and information you collected in Step 2 above.
- API Username and API Key can be left blank.
- Type OAuth2 Client ID from Step 2 in Client ID.
- Type OAuth2 Secret from Step 2 in Client secret.
- Mark in console is left blank because the API access is read-only.
- Enter the Base URL from Step 2 in CrowdStrike API access.
- Enable CrowdScore ingest, type y. Note: Requires the incidents:read permission to work.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.
Comments
0 comments
Please sign in to leave a comment.