Crowdstrike Falcon Stream

Updated 2 months ago by Elvis Hovor

This document explains how to set up and use Crowdstrike Falcon Stream with TruSTAR Station. 

  • Time to Install: 10 minutes
  • Type of Feed: Automatic updates
  • Update Frequency: 15 minutes
  • Intel Type: Premium Feed

Data Types

The integration pulls all observables supported by TruSTAR.


  • Licensed user of Crowdstrike
  • Access to Crowdstrike Falcon Stream
  • Crowdstrike API ID and API key for the reports API.
TruSTAR Admin rights are required to activate this Premium Intel feed.

Getting Started

  1. Log into TruSTAR Station.
  2. Click the Marketplace icon on the left side icon list.
  3. Click on Closed Sources.
  4. Click Subscribe on the Crowdstrike Falcon Stream box.
  5. Enter your API key and click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

Report Mapping




Report Title



Report Body

Entire JSON response

External ID



Report Tag


Report Deep Link


Time Began



Known Issues

None reported.

Contact if you have issues with this integration.

How Did We Do?