Skip to main content
 

Caution

If you are a CrowdStrike Complete customer, do NOT use this guide. Use the CrowdStrike Falcon Complete article instead.

Tip

This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!

  • If you plan to enroll in the Expel Hunting service, a Falcon Data Replicator subscription is required.

Step 1: Enable console access

Expel is a CrowdStrike Certified Managed Security Provider partner. To allow the Expel partner console access to your console, do the following:

  1. Print, complete, and sign the CrowdStrike MSP Authorization Form. This form can be provided by the Expel customer success engineer.

  2. Attach the completed form in an email to CrowdStrike Falcon Support. An Expel customer success engineer can help and can provide a template to send to CrowdStrike Falcon Support.

Step 2: Enabling the OAuth2 API

  1. After you're logged into the Falcon UI, navigate to Support > API Clients and Keys.

  2. Select Add new API Client.

  3. Enter Expel as the Client Name.

  4. Enter Expel API Access as the Description.

  5. Select the following permissions:

    • Read and Write for Detections.

      Note

      Write permission is only required to use the Mark in Progress option.

    • Read and Write for Hosts.

      Note

      Write permission for Hosts is required for Auto Host Containment. For more information, see the CrowdStrike Auto Host Containment article.

    • Read for Incidents.

    • Read for IOCs (Indicators of Compromise).

    • Read and Write for Real Time Response.

    • Read and Write for IOC Manager APIs.

      Note

      Write permission is required to block hashes through auto-remediation. For more information, see the Auto Block Bad Hashes article.

  6. Make a record of your Client ID and the Client Secret for the API.

  7. Go to Step 3 to type these credentials into Workbench.

Step 3: Configure the technology in Workbench

  1. Login to https://workbench.expel.io/settings/security-devices?setupIntegration=crowdstrike.

    mceclip0.png
  2. For Name type the host name of the device.

  3. For Location type the geographic location of the appliance.

  4. After typing the name and location, complete the remaining fields using the credentials and information you collected in Step 2 above.

    • API Username and API Key can be left blank.

    • Type OAuth2 Client ID from Step 2 in Client ID.

    • Type OAuth2 Secret from Step 2 in Client secret.

    • Leave Mark in console blank because the API access is read-only.

    • Type the Base URL from Step 2 in CrowdStrike API access.

    • Enable CrowdScore ingest, type y.

      Note

      Requires the incidents:read permission to work.