CrowdStrike Falcon
Copy link

CrowdStrike Falcon is a cloud-based platform that provides endpoint protection across your organization. If you currently use CrowdStrike Falcon, you can configure the Falcon SIEM Connector to send events to SIEM (InsightIDR) where you can generate investigations around that data. Alternatively, you can configure a cloud event source to retrieve data from the CrowdStrike Falcon API.

SIEM (InsightIDR) collects Alerts (Cloud Connection method only) and DetectionSummaryEvents (Collector method only) from CrowdStrike Falcon.

⚠️

MDR Customers

If you are an MDR customer, you must select the cloud connection method.

To set up CrowdStrike Falcon:

  1. Read the requirements and complete any prerequisite steps.
  2. Configure CrowdStrike Falcon to send data to SIEM (InsightIDR).
  3. Configure SIEM (InsightIDR) to collect data from the event source.
  4. Test the configuration.

You can also:

ℹ️

Visit the third-party vendor's documentation

For the most accurate information about preparing your event source product for integration with SIEM (InsightIDR), we recommend that you visit the third-party vendor’s product documentation.

Requirements
Copy link

Before you can set up a CrowdStrike Falcon event source you’ll need:

  • A CrowdStrike Falcon account with administrator access.
    • Note that you’ll configure SIEM (InsightIDR) to use the CrowdStrike Event Streams (eStream) API to pull alerts from the \alerts endpoint.
  • To collect Alerts using the Cloud Connection method, you must first install the Raptor release of CrowdStrike Falcon. For more information, contact CrowdStrike Customer Support at: https://supportportal.crowdstrike.com .
  • For the Expanded Cloud event source:
    • Access to a supported CrowdStrike Falcon region.
    • Permission to create an API client and assign API scopes in CrowdStrike Falcon.

Configure CrowdStrike Falcon to send data to SIEM (InsightIDR) for Cloud Connection method
Copy link

This step is only required if you are using the Cloud Connection method.

To ensure SIEM (InsightIDR) can receive data from CrowdStrike Falcon, you must configure your event source.

To obtain credentials from CrowdStrike:

This task is only required if you’re using the API collection method. If you are using another collection method and are not sure how to set it up, contact CrowdStrike Customer Support at: https://supportportal.crowdstrike.com 

  1. In your CrowdStrike Falcon environment, sign into the Management Console as an admin-level user.
  2. Go to Support and resources > Resources and Tools > Client Management.
  3. Create a new API client.
  4. Select Read access for Alerts and Read access for Event Streams.
  5. Take note of the Client ID and Secret.

Configure CrowdStrike Falcon to send data to SIEM (InsightIDR) for Expanded Cloud Connection method
Copy link

This step is only required if you are using the Expanded Cloud Connection method.

To ensure SIEM (InsightIDR) can receive data from CrowdStrike Falcon, you must configure your event source.

To Create an API Client in CrowdStrike Falcon

To allow SIEM (InsightIDR) to connect to CrowdStrike Falcon, create an API client and assign the required permissions.

  1. In your CrowdStrike Falcon environment, sign into the Management Console as an admin-level user for your region:

  2. Go to Support and Resources > Resources and Tools > Client Management.

  3. Create a new API client. Complete the following fields:

    FieldValue
    Client NameRapid7 AI SOC
    DescriptionRapid7 AI SOC API Access
  4. Assign the following permissions:

    Permission ScopeReadWrite
    AlertsRequiredRequired
    DetectionsRequired—
    HostsRequiredOptional*
    IncidentsRequiredRequired
    IOC ManagementRequired—
    ThreatgraphRequired—
    User ManagementRequired—
    NG-SIEMRequiredRequired

    * Enable Write permission for the Hosts scope if you want to use host quarantine actions.

  5. Take note of the Client ID and Secret.

Use the base URL to identify your CrowdStrike Falcon region:

Base URLRegion
https://api.crowdstrike.com us-1
https://api.us-2.crowdstrike.com us-2

Configure the Falcon SIEM Connector for the Collector method
Copy link

This step is only required if you are using the Collector method.

HP ArcSight Common Event Format (CEF) facilitates communication between devices by defining a syntax for log records. In order to send events to SIEM (InsightIDR), you must modify certain settings in the default CEF file.

  1. Open the default CEF configuration file located in /opt/crowdstrike/etc/.
  2. Rename /opt/crowdstrike/etc/cs.falconhoseclient.cef.cfg to /opt/crowdstrike/etc/cs.falconhoseclient.cfg.
  3. If you have the line cat = event.DetectName in your config file, you should update it to cat = event.Tactic.
  4. Make the following changes to the config file:
output_format=syslog output_to_file=true/false output_path=<filepath> act = event.Technique reason = event.Objective outcome = event.PatternDispositionDescription CSATRPatternDisposition = event.PatternDispositionValue
  1. If you plan to use a proxy to connect to the Falcon Firehose endpoint, you will need to update http_proxy=<protocol>://<host>:<port> in your config file. Otherwise, update the Logging section.
  2. To configure your collector as a Syslog server, update the Syslog section to:
send_to_syslog_server=true host=<collector ip> port=<listening port> protocol=udp/tcp
  1. Start the service: # service cs.falconhoseclientd start.

Configure SIEM (InsightIDR) to collect data from the event source
Copy link

After you complete the prerequisite steps and configure the event source to send data, you must add the event source in SIEM (InsightIDR).

Task 1: Select CrowdStrike Falcon
Copy link

  1. From the left menu, click Data Connectors, and navigate to SIEM > Data Collectors. Click Setup Event Source > Add Event Source.
  2. Do one of the following:
  • Search for CrowdStrike Falcon in the event sources search bar.
  • In the Product Type filter, select Third Party Alerts.
  1. Select CrowdStrike Falcon.

Task 2: Set up your collection method
Copy link

There are three methods of collecting data from CrowdStrike Falcon: through a cloud connection, through an expanded cloud connection, or through a collector.

If you are an MDR customer, you must select the cloud connection method or the expanded cloud connection method.

Use the Cloud Connection method

ℹ️

New credentials are required for cloud event sources

You cannot reuse existing on-premise credentials to create a cloud connection with this event source. You must create new credentials.

  1. In the Add Event Source panel, select Run On Cloud.
  2. Name the event source. This will become the name of the log that contains the event data in Log Search.
  3. Optionally, select the option to send unparsed data.
  4. Click Add a New Connection.
  5. In the Create a Cloud Connection screen, enter a name for the new connection.
  6. In the Client ID field, enter the Client ID that you obtained in the previous section, Configure CrowdStrike Falcon to send data to SIEM (InsightIDR).
  7. In the Region field, enter the region of your CrowdStrike Falcon instance.
  8. In the Client Secret field, add a new credential:
  9. Click Save & Test Connection.
  10. Optionally, enter a collection filter.
  11. Optionally, select the option to send unparsed data.
  12. Select your LDAP Account Attribution preference:
    • Use short name attribution: Applies the short name of the user without the domain suffix in the username field. For example, if the username was jsmith@myorg.example.com, the short name would be jsmith.
    • Use fully qualified domain name attribution: If you have a multi-domain environment, this option works best to attribute users and assets.
  13. Optionally, in a multi-domain environment, use the dropdown menu to select your main Active Directory domain. See Deploy in Multi-domain Environments and Advanced Event Source Settings.
  14. Click Save.

Use the Expanded Cloud Connection method

ℹ️

Phased Rollout

Expanded cloud event sources are being made available through a phased rollout and may not yet be visible to all users. If you don’t see these event sources, your organization hasn’t yet received access. Existing event source functionality remains unchanged in the meantime.

  1. In the Add Event Source panel, select Expanded Cloud.
  2. Name the event source. This will become the name of the log that contains the event data in Log Search.
  3. Optionally, select the option to send unparsed data.
  4. Click Add a New Connection. If no connections exist, click Create a New Connection.
  5. Enter the CrowdStrike Falcon Client ID.
  6. Select the region associated with your CrowdStrike Falcon base URL.
  7. In the credential section, click Add Credential.
  8. Enter a name and description for the credential.
  9. Enter the CrowdStrike Falcon Client Secret in the Secret Key field.
  10. For Product Access, select All Rapid7 Products.
  11. Click Save.
  12. Optionally, enable Bidirectional Sync.
  13. Click Save to complete the configuration.

Use the Collector method

  1. In the Add Event Source panel, select Run On Collector.
  2. Name the event source. This will be the name of the log that contains the event data in Log Search. If you do not name the event source, the log name will default to CrowdStrike Falcon.
  3. Optionally, select the option to send unparsed data.
  4. Choose the collector with the IP address that is specified in the cs.falconhoseclient.cfg file.
  5. Enter the same listening port and protocol that is specified in the cs.falconhoseclient.cfg file.
  6. Click Save.
  7. Start the SIEM Connector service by running /etc/init.d/cs.falconhoseclientd start or service cs.falconhoseclientd start.
  8. To verify that your setup was correct and your connectivity has been established, you should tail the cs.falconclient.log file. This log file may be in /var/log/crowdstrike/falconhoseclient or /opt/crowdstrike or another folder depending on how you installed the Falcon SIEM Connector.

Test the configuration
Copy link

The event IDs that SIEM (InsightIDR) parses are:

  • Alerts
  • DetectionSummaryEvents

To test that event data is flowing into SIEM (InsightIDR):

  1. From the Data Collection Management page, open the Event Sources tab.
  2. Find the event source you created and click View raw log. If the Raw Logs modal displays raw log entries, logs are successfully flowing to the Collector.
  3. Open Log Search.

Next, verify that log entries are appearing in Log Search:

  1. In the Log Search filter panel, search for the event source you named in Task 2. CrowdStrike Falcon logs should flow into the log set: Third Party Alerts.
  2. Select the log sets and the logs within them.
  3. Set the time range to Last 10 minutes and click Run.

The Results table displays all log entries that flowed into SIEM (InsightIDR) in the last 10 mins. The keys and values that are displayed are helpful to know when you want to build a query and search your logs.

Sample logs
Copy link

In Log Search, the log that is generated uses the name of your event source by default and appears under the log set: Third Party Alerts.

Here are two typical log entries that are created by the event source:

Alert event

{ "activity_id": "3D14C6B6-XXXX-460EC4FCD27D", "aggregate_id": "aggind:dca1XXXX1660:097877B9-C71F-42C7-A836-2944D119B6CB", "cid": "0123456789ABCDEFGHIJKLMNOPQRSTUV-WX", "composite_id": "28a1xxxxxxxx3914:ind:a618xxxxxxxx4d85:1328xxxxxxxx1933-117-1930xxxxxxxx9544", "confidence": 30, "context_timestamp": "2022-05-15T10:32:00.000Z", "created_timestamp": "2022-05-15T11:34:56.887790892Z", "description": "User access from an unusual location", "display_name": "Unusual user geolocation", "end_time": "2022-05-15T10:32:00.000Z", "falcon_host_link": "https://falcon.crowdstrike.com/identity-protection/detections/dca1xxxx1660", "id": "ind:a618xxxxxxxx4d85:1328xxxxxxxx1933-117-1930xxxxxxxx9544", "location_country_code": "US", "name": "AnomalousGeoLocationAccess", "objective": "Gain Access", "okta_application_id": "0oa1xxxxL5d7", "pattern_id": 51125, "product": "idp", "scenario": "machine_learning", "severity": 31, "show_in_ui": true, "source_account_name": "demo.user@example.com", "source_account_okta_id": "00u4xxxxf5d7", "source_endpoint_address_ip4": "192.0.2.100", "source_endpoint_ip_address": "192.0.2.100", "sso_application_identifier": "Okta Admin Console", "sso_application_uri": "0oa1xxxxL5d7", "start_time": "2022-05-15T10:32:00.000Z", "status": "new", "tactic": "Initial Access", "tactic_id": "TA0001", "technique": "Valid Accounts", "technique_id": "T1078", "timestamp": "2022-05-15T10:34:56.509Z", "type": "xdr", "updated_timestamp": "2022-05-15T11:34:56.887790892Z" }

DetectionSummaryEvent event

CEF:0|CrowdStrike|FalconHost|1.0|DetectionSummaryEvent|Exploit|4|externalId=123456fdfbb789db61cc398ef01c1377 cn2Label=ProcessId cn2=28039534917112 cn1Label=ParentProcessId cn1=27874350988291 dhost=RPD07_01 duser=N/A msg=Detected and blocked a heap spray attempt, which was likely part of an attempted exploit. fname=Acrobat.exe filePath=\Device\HarddiskVolume2\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat cs5Label=CommandLine cs5="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrobat.exe" -Embedding fileHash=1f3f9a0bbda9b383e1e248b35f1b81ea dntdom=N/A cs6Label=FalconHostLink cs6=https://falcon.crowdstrike.com/activity/detections/detail/777049fdfbb746db61cc398ef01c1377/395223296275?_cid\=e9f0d5fbbee04aa1a6593f1f465d9fb8 cn3Label=Offset cn3=24813 rt=1594167159000 src=10.80.153.236 smac=12-f5-71-cc-f6-3c cat=Exploit act=Exploit Mitigation reason=Falcon Detection Method outcome=1024 CSATRPatternDisposition=Prevention, operation blocked