Getting Started
- Login to https://falcon.crowdstrike.com/login/
- You may have a different portal URL depending on geolocation
- Expand the navigation in the top left > Support and resources > API Clients and keys
- Select Create API Client
- Select the following scopes
- Alerts - Read / Write
- Hosts - Read / Write
- Host Groups - Read
- User Management - Read
- Prevention Policies - Read / Write
- Device Control Policies - Read / Write
- Response Policies - Read
- Sensor Update Policies - Read / Write
- Real Time Response - Read / Write
- IOC Management - Read / Write
- Threatgraph - Read
- Detections - Read
- Create and save Client ID, Client Secret, and Base URL
- Login to Tier4 and navigate to Integrations > Crowdstrike and provide the information from step 5.