XDRIntegrate CrowdStrike

Integrate CrowdStrike

Learn how to connect your CrowdStrike Falcon environment with Scrut to automatically collect user access, endpoint device, and prevention policy data as continuous compliance evidence.

What This Integration Does in Scrut

  • User Access Data: Fetches user details, roles, and permissions from CrowdStrike for Access Reviews.
  • User Endpoint Devices: Fetches employee device details, including security posture and installed software. These devices are mapped to employees and visible in their profile under People → Employees → Technical.
  • Automated Tests: Runs automated checks that evaluate CrowdStrike for security misconfigurations and applicable compliance checks against your compliance frameworks.

Prerequisites

  • An active CrowdStrike Falcon account with permission to create API clients
  • The Falcon sensor installed on the employee workstations you want to monitor
  • A Falcon Discover license to fetch device owner, disk encryption, hardware, and installed software details

Permissions and Access Requirements

For CrowdStrike

Create an API client with the following Read scopes:

ScopeUsed for
User ManagementUsers, emails, and assigned roles
HostsDevice details and login history
AssetsDevice owner, encryption, hardware, and installed software (Falcon Discover)
Zero Trust AssessmentZero Trust Assessment (ZTA) score and screen lock signals
Prevention PoliciesPrevention policy assignments and settings

For Scrut

  • Admin access to Scrut (or Contributor with access to the Integration module)

Limitations

  • Scrut fetches only workstations that have checked in with CrowdStrike in the last 30 days. Servers and inactive devices are not synced.
  • Device owner, disk encryption, hardware, and installed software details are available only with a Falcon Discover license.
  • CrowdStrike does not always expose screen lock status. When it isn't available, the field shows as unavailable in Scrut rather than disabled.

Data Collected

User Access Data

Scrut FieldSource Field / DataNotes
Namefirst_name, last_name
EmailuidCrowdStrike stores the user's email in uid.
RoleRole display nameA user with multiple roles appears once per role.

User Endpoint Devices

Scrut FieldSource Field / DataNotes
Hostnamehostname
Serial Numberserial_numberAlso used to match devices with your MDM.
Form Factor, Manufacturer, Modelform_factor, system_manufacturer, system_product_nameRequires Falcon Discover.
OS Versionos_version
OS End of Lifeos_is_eol
Disk Encryptionunencrypted_drives_countMarked encrypted when no drives are unencrypted.
Endpoint Protection Versionagent_versionThe installed Falcon sensor version.
Screen LockZero Trust Assessment signalsShows as unavailable if CrowdStrike doesn't report it.
Zero Trust ScoreZTA overall score
Installed SoftwareApplication name and versionRequires Falcon Discover.
Browser ExtensionsExtension name, version, and browserRequires Falcon Discover.
First Seen, Last Seenfirst_seen, last_seen
OwnerDevice owner emailSee How does Scrut identify the owner of a device? in FAQs.

Sync Frequency

Data syncs automatically every 24 hours. You can also manually trigger a sync from the integration settings page.

Integration Setup

Step 1: Create an API Client in CrowdStrike

  1. Log in to your CrowdStrike Falcon console.
  2. Navigate to Support → API clients and keys.
  3. Click Add New API client.
  4. Configure your API client.
    • Enter a Client name (for example, Scrut Integration) and an optional Description.
    • Select Read for the following scopes:
      • User Management
      • Hosts
      • Assets
      • Zero Trust Assessment
      • Prevention Policies
  5. Click Create.
  6. Copy the Client ID and Client Secret and store them securely.

CrowdStrike displays the Client Secret only once. If you lose it, reset the secret from the API client and use the new value in Scrut. Learn more: CrowdStrike Developer Docs.

Step 2: Connect CrowdStrike in Scrut

  1. Log in to Scrut and navigate to Integrations → Integrations Library.
  2. Search for CrowdStrike and click Integrate.
    Integration CrowdStrike
    Integration CrowdStrike
  3. Enter the Client ID and Client Secret you copied in Step 1.
  4. Select the Region of your CrowdStrike environment.
  5. Click Connect.

Pro Tip! Not sure which region to select? Check the URL of your Falcon console. For example, falcon.crowdstrike.com is US-1, falcon.us-2.crowdstrike.com is US-2, and falcon.eu-1.crowdstrike.com is EU-1. See More.

Enter CrowdStrike Credentials
Enter CrowdStrike Credentials

What Happens Next?

Initial Data Sync

The initial sync begins automatically after you connect the integration. Depending on the number of users and devices in your environment, it can take some time to complete. You can monitor the sync status in Audit Logs in the integration settings.

Review Synced Data

  • Navigate to People → Employees → Technical to view employee device records.
  • Navigate to Access Reviews to review CrowdStrike users and their roles.
  • Navigate to Tests and search for Ensure All Active Hosts Have a Non-Empty Prevention Policy to view test results.
    • This test passes for a host when it has a prevention policy assigned and that policy has prevention settings turned on. It fails when a host has no policy assigned or its policy has all prevention settings turned off.

Common Errors and Troubleshooting

FAQs

Contact support@scrut.io or your CSM for further assistance.