Add the CrowdStrike Feed
Configure the CrowdStrike feed to be used as a source for Threat Intelligence (Intelligence Hub).
Prerequisites
To add the Crowdstrike feed as a source, you must have access to the following endpoints as part of your CrowdStrike subscription:
/user/entities/user/v1
/iocs/ endpoints
/intel/combined/indicators/v1
Add the Crowdstrike Feed
To add the CrowdStrike feed to Threat Intelligence:
- Configure CrowdStrike:
- From CrowdStrike, open the Support > API Clients and Keys window.
- On the desired Oauth2 API client, click Edit.
- Ensure that Read is selected for Falcon X (indicators).
- Copy the Base URL.
- Configure Threat Intelligence feed:
- From the Command Platform navigation panel, go to Data Connectors > Threat Intelligence > Sources.
- Click CrowdStrike to display the feed configuration.
- Enter the Client ID, Secret, and Base URL (from the previous step).
- Click Save, then Test Credentials.
- Enable the feed.