Overview

The CrowdStrike integration polls the Falcon Streaming API and detection endpoints to ingest:

  • Endpoint detections (malware, IOA, IOC matches)
  • Incident lifecycle changes
  • Real-Time Response (RTR) session activity
  • Audit events for user, role, and policy changes

Prerequisites

  • A CrowdStrike Falcon tenant.
  • Falcon Administrator privileges to create API clients.
  • The Falcon cloud region your tenant lives in (us-1, us-2, eu-1, or us-gov-1).

Step 1: Create an API client in Falcon

  1. Sign in to the Falcon console.
  2. Go to Support and resources → API clients and keys.
  3. Click Create API client.
  4. Name it atatus-siem and grant the following scopes (read-only):
    • Detections — Read
    • Incidents — Read
    • Event streams — Read
    • Audit — Read
  5. Click Create, then copy the Client ID and Client Secret shown once.
  6. Note the Base URL for your cloud region (for example, https://api.crowdstrike.com for US-1).

Step 2: Connect CrowdStrike in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the CrowdStrike card and click Connect.
  3. Fill in the form:
Field Description Example
Client ID Falcon API client ID. abc123...
Client Secret Falcon API client secret. ••••••••
Cloud Region Falcon cloud region. us-1
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The CrowdStrike card shows Configured.
  • Detections and audit events appear in Security → Cloud SIEM → Audit Logs → Events with source crowdstrike.