Integrate CrowdStrike Falcon
You can integrate CrowdStrike Falcon with Sophos XDR so that it sends data to Sophos for analysis.
Key steps
The key steps in a CrowdStrike Falcon integration are as follows:
- Add a new API client to CrowdStrike Falcon.
- Get details of your CrowdStrike Falcon service.
- If you want to ingest FDR data, create a Falcon Data Replicator (FDR) feed and save its credentials.
- Configure the integration in Sophos XDR, and enable the data sources you want to ingest.
Requirements
The following is required for CrowdStrike Falcon configuration:
- An administrator account in CrowdStrike Falcon.
To ingest FDR, you'll also require the following:
-
The CrowdStrike Falcon Data Replicator capability enabled on your CrowdStrike tenant.
If FDR is not available in your console, contact your CrowdStrike account representative or your Sophos account team.
-
Permission to create FDR feeds in the Falcon console.
Add a CrowdStrike Falcon integration
To integrate CrowdStrike Falcon, you must first create an API client in CrowdStrike Falcon, then configure the integration in Sophos XDR.
Add new API client to CrowdStrike Falcon
To get the CrowdStrike Falcon API details you need for integration, do as follows:
- Sign in to the CrowdStrike Falcon console.
- From the menu, go to Policies and settings > API clients and keys.
- Click Create API client.
- In Create API client, enter a client name and description.
- Select the Read permission in the Alerts API scope.
- Click Create.
-
Securely copy the Client ID, Client Secret, and base URL for your new client.
The Client Secret is shown only once. Make sure you save it somewhere safe.
-
Click Done.
Create a Falcon Data Replicator feed (FDR only)
FDR data is delivered through a CrowdStrike-managed S3 bucket and SQS queue that CrowdStrike creates for you when you create an FDR feed. To ingest FDR data, create a feed in the Falcon console and save the credentials CrowdStrike issues for it. Sophos XDR uses those credentials to read the feed.
Note
The following steps are based on the current version of the CrowdStrike Falcon console and may change. Refer to the CrowdStrike documentation for authoritative instructions on creating an FDR feed.
To create an FDR feed, do as follows:
- In the Falcon console, go to Support and resources > Falcon Data Replicator, or search for "Falcon Data Replicator".
- Click Create feed.
- Enter a feed name, then turn the feed on.
- Click Next.
- On the feed review page, confirm that all Primary and Secondary events are included. If they're not, click the Pencil icons to customize these events and select all event types.
- Click Create feed.
-
Make note of the feed credentials shown in the Falcon console.
The feed credentials are only shown once. Make sure you save them somewhere safe.
-
You'll need the following details to configure the FDR data source in Sophos XDR.
Parameter Description Where to find in Falcon console CID (customer ID) The customer ID of your CrowdStrike account Host setup and management > Sensor downloads AWS region (storage region) The AWS region that hosts your FDR S3 bucket and SQS queue Copy feed credentials confirmation screen, or Support and resources > Falcon data replicator > (Feed Name) AWS SQS queue URL (notifications URL) The URL of the SQS queue for your feed, in the form https://sqs.<region>.amazonaws.com/<account-id>/<queue-name>Copy feed credentials confirmation screen, or Support and resources > Falcon data replicator > (Feed Name) AWS S3 URI (storage location) The S3 URI for your feed, in the form s3://<bucket-name>Copy feed credentials confirmation screen, or Support and resources > Falcon data replicator > (Feed Name) AWS access key ID (client ID) The access key ID CrowdStrike issued for the feed Copy feed credentials confirmation screen AWS secret access key (secret) The secret access key CrowdStrike issued for the feed Copy feed credentials confirmation screen
Configure the integration in Sophos XDR
To integrate CrowdStrike Falcon with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click CrowdStrike Falcon.
The CrowdStrike Falcon page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
- In Endpoint Data Sources, select the CrowdStrike data sources you want Sophos XDR to ingest: Alerts and FDR.
- Enter the API Base URL, API Client ID, and API Client Secret you got from CrowdStrike Falcon.
- (FDR only) Enter the Customer ID, AWS Region, FDR SQS Queue URL, FDR S3 URI, FDR AWS Access Key ID, and FDR AWS Secret Access Key you copied from the Falcon console.
-
(FDR only) In Ignore CrowdStrike FDR Alerts, choose how to handle detection summary events delivered by FDR:
- Ingest (default): Sophos XDR normalizes FDR detection summary events to third-party security alert telemetry.
- Ignore: Sophos XDR discards FDR detection summary events. Choose this if you also have the Alerts data source turned on and you don't want detections reported by both data sources.
-
Click Done.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Configuration notes
Keep the following in mind during CrowdStrike Falcon configuration:
- When you turn on FDR, Sophos XDR validates the integration by checking the SQS queue. If validation fails, verify that the queue URL, AWS region, and access key match the CrowdStrike feed configuration.
- Sophos XDR reads and deletes FDR messages from the SQS queue after processing them. Don't use the same queue with another consumer, and update the integration if you delete or recreate the feed to avoid data loss.
- If FDR data accumulates faster than it can be consumed, such as after an outage, Sophos XDR ingests both backlog and current data. Backlog data older than 12 hours is processed through a separate pipeline and may appear in the Sophos Data Lake later than current data.
Additional resources
For more information on configuring CrowdStrike Falcon, see the following documents: