Step 1: Enable console access
Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
Expel is a CrowdStrike Certified Managed Security Provider partner. To allow the Expel partner console access to your console, you need to do the following:
- Print, complete, and sign the CrowdStrike MSP Authorization Form. This form can be provided by the Expel Solutions Architect, Engagement Manager or Customer Success Engineer.
- Create a CrowdStrike support ticket, attaching the completed form.
Step 2: Enabling the OAuth2 API
- After you're logged into the Falcon UI, navigate to Support > API Clients and Keys.
- Select Add new API Client.
- Enter Expel as the Client Name.
- Enter Expel API Access as the Description.
- Select the following permissions:
- Read and Write for Detections
- Read for Hosts
- Read for IOCs (Indicators of Compromise)
- Read and Write for Real Time Response
- Click Save.
- Make a record of your Client ID and the Client Secret for the API.
- Go to Step 3 to type these credentials into Workbench.
Step 3: Configure the technology in Workbench
Now that we have the correct access configured and noted the credentials, we can integrate CrowdStrike Falcon with Expel.
Register device in Expel Workbench
- Login into https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
- At the top right of the page, select Add Security Device.
- Search for and select CrowdStrike Falcon (not Data Replicator!).
- For Name type the hostname of the device.
- For Location type the geographic location of the appliance.
- After typing the name and location, complete the remaining fields using the credentials and information you collected in Step 2.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.