Crowdstrike Falcon Intelligence

Updated 5 months ago by Elvis Hovor


TruSTAR is a threat intelligence platform designed to accelerate incident analysis process and exchange of intelligence among various internal and external teams. This document provides a description how paying customers of Crowdstrike can correlate reports in their TruSTAR enclaves with their Crowdstrike falcon intelligence feeds in the TruSTAR platform. 


This integration requires TruSTAR users to be paying customers of Crowdstrike and users of Crowdstrike's Falcon Intelligence Feeds. User will also need access to their Crowdstrike API ID and API key.

Note: Crowdstrike integration has been updated to Crowdstrike API version 2.0

Configure Integration

After you have retrieved your Crowdstrike API ID and key follow these steps:

Note: Only TruSTAR admins can activate closed source integrations.
  1. Log into TruSTAR Station and go the Explore->Marketplace (
  2. Click on Closed Sources.
  3. Click on subscribe button on the Crowdstrike logo and fill in your API key.
  4. Click Submit.

TruSTAR will validate and enable the Crowdstrike integration within 48 hours. You will receive an email from us informing you as soon as it is enabled.

After the integration in enabled you should see it reports from Crowdstrike being submitted into an enclave you control on TruSTAR.

How it works

After a user has activated the Crowdstrike Integration, every 15 mins the integration will query the Crowdstrike Falcon Intelligence endpoint and ingest all new indicators from Falcon into the users enclave in TruSTAR. 


    What data do you currently pull from Crowdstrike? 

    Our integration currently queries indicators from newly submitted reports in users  enclave against Crowdstrike's indicators API. 

      TruSTAR currently queries Crowdstrike with over 13 TruSTAR indicator types :

      • IP
      • URL
      • MD5 
      • SHA1
      • SHA256
      • CVE 
      • SOFTWARE
      • MALWARE

          How often is the data pulled?

          Our integration retrieves data from the Crowdstrike every 15mins.

          Technical Details on Queries

          Crowdstrike Indicator API 


          API ID

          API Key



          Indicator types we query:

          ALL (13 Indicator types - IP's, Hashes, URL, Bitcoin addresses etc)

          Query URL for all indicator types 


          Returns Full JSON Response

          Please reach out to for any additional questions.

          How Did We Do?