TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Crowdstrike

Estimated reading: 3 minutes 1171 views

Set up Crowdstrike for automated tests with TrustCloud!

Purpose

Once you set up your compliance program, TrustCloud TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests against systems in your product and business stack and verifies that they are properly configured.

This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Crowdstrike instance so that TrustOps can validate and generate evidence for your compliance program.

Instructions to grant TrustCloud limited access to Crowdstrike

  1. Log in to your Crowdstrike falcon account as an admin user.crowdstrike 1
  2. Navigate to the API clients & keys page
    1. Within the Falcon console, select the options tab from the top left of the screen. Click Support & resources & then select API clients & keys
      crowdstrike 2
  3. Create the OAuth API Client
    1. Within API clients & keys, click Create API Client. This will open a confirmation dialog to create an API Client.crowdstrike 3
  4. Provide client name & select scopes for the API client
    Within the confirmation dialog, set the Client Name to TrustCloud API Client & provide a suitable description.
    Within the scopes section, select the following read scope & then click ADD:

    1. Hosts (required for accessing device information via /devices/entities/devices/v2 API endpoint)
      crowdstrike
  5. Once the API client is created, you will be provided with the Client ID, Client Secret & Base URL.
    Make a copy of these values, as you will be using them in the next step.
    NOTE – The Client Secret will never be shown again once this dialog is closed
    Crowdstrike
  6. Provide the Client Id
  7. Provide the Client Secret
  8. Provide the Base API URL
    1. Enter the Base API URL. Use the base URL that corresponds to the cloud where your Crowdstrike instance is hosted.

Data feeds

Types of control testing that TrustCloud enables with Crowdstrike:

  1. Vulnerability Scanning
  2. Audit Logging

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from Crowdstrike

  1. Servers
  2. Versions
  3. Policies
  4. Assets

A sample of read-only data elements we pulled from these data feeds.

Read: Servers
   - device_id
   - external_ip
   - hostname
   - last_seen
   - Machine_domain
   - os_version
   - platform_name
   - device_policies.prevention.applied
   - product_type_desc
   - system_manufacturer
   - systems_product_name
   - service_provider
   - tags

Read: versions
   - Sensor_version
   - platform
   - architecture
   - release_date
   - release_channe;
   - sha256
   - download_url
   - notes

Read: policies
   - id
   - name
   - platform_name
   - created_by
   - created_timestamp
   - modified_by
   - modified_timestamp
   - policy_type
   - description
   - enabled
   - settings

Read: Assets
   - devide_id
   - hostname
   - platform_name
   - product_type_desc
   - os_versions
   - Mac_address
   - ip_Address
   - last_seen
   - first_seen
   - sensor_version
   - agent_version
   - malware_protection_enabled
   - enable_malware_preventation
   - uninstall_protection
   - local_uninstall_password_enabled
   - machine_learning_enabled
   - exploit_prevention_enabled
   - cloud_detection_enabled
   - auto_update_enabled
   - version_lock_enabled
   - auto_uninstall_enabled
   - notify_user_before_update
   - defer_upgrade_days
   - allow_downgrade
   - firewall_enabled
   - default_inbound_action
   - default_outbound_action
   - logging_enabled_x
   - rule_set_x
   - usb_class_allowed
   - block_unknown_devices
   - enable_device_logging
   - trusted_vendors
   - allowlist_mode
   - script_control_enabled
   - rule_set_y
   - logging_enabled_y

Join the conversation

You might also be interested in

Excluding a Test or Assessment (Updated UI)

Excluding a test or assessment allows you to remove certain tests or assessments from...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...

Editing Controls

Control customization is a pillar of TrustCloud’s platform, effortless crafting of custom controls. With...

Adding Controls

TrustOps gives you the ability to add a custom control to your program, add...

Testing Controls

Once you have set up your integrations, you can leverage automated tests. Automated tests...

Self Attestations

The Self Assessments page in TrustOps provides users with a streamlined, centralized workspace to...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue