Crowdstrike Falcon Reports

Updated 2 weeks ago by Elvis Hovor

This document explains how to set up and use Crowdstrike Falcon Reports with TruSTAR Station. 

Leveraging artificial intelligence (AI), the CrowdStrike Falcon® platform offers instant visibility and protection across the enterprise and prevents attacks on endpoints on or off the network. CrowdStrike Falcon delivers real-time protection and actionable intelligence from Day One.

  • Source Type: Premium Intel
  • Update Type: Feed-based
  • Update Frequency: 15 minutes
  • Time to Install: 10 minutes

Data Types

The integration pulls all observables supported by TruSTAR.


  • Licensed user of Crowdstrike
  • Access to Crowdstrike Falcon Intelligence Reports.
  • Crowdstrike API ID and API key for the reports API.
TruSTAR Admin rights are required to activate this Premium Intel feed.

Getting Started

  1. Log into TruSTAR Station.
  2. Click the Marketplace icon on the left side icon list.
  3. Click Premium Intel.
  4. Click Subscribe on the Crowdstrike Falcon Reports box.
  5. Enter your API key and click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

Report Mapping 




Report Title

The ID name field of the response.

99XX CSIT-17023 Stampado 2.0 Released  

External ID

The ID field of response.


Report Body

Entire JSON body resources list of the response.

Time Begun

The created_date field of the response.


Report DeepLink

The URL of the report.


Slugs of the response.



Q: How do I find my Crowdstrike Falcon Report API keys?
  1. Navigate to API Clients and Keys in the Crowdstrike portal
  2. If your keys have not already been created for the Indicators API scope then "Add new API client"
  3. From here select a Client Name and select the following API scopes
  4. Copy the keys and subscribe to the Crowdstrike Falcon Reports Marketplace source

Known Issues

None reported.

Contact if you have issues with this integration.

How Did We Do?