Connect CrowdStrike Falcon
The CrowdStrike Falcon connector lets ISPM discover AI agents that run on your managed endpoints.
About this task
Early Access release
Connecting CrowdStrike Falcon to ISPM lets ISPM discover AI agents that run on your managed endpoints. ISPM
can read host and asset inventory from CrowdStrike Falcon over the CrowdStrike API using a read-only API
client that you create. Setup happens in two locations:
- In CrowdStrike Falcon, create an API client and grant it the required read scopes.
- In ISPM, enter the client credentials.
Before you begin
- You need a Falcon Discover license (required for the Assets scope).
- You need ngsiem:write and ngsiem:read permissions for MCP discovery.
- You need a Falcon role that can create API clients (Falcon Administrator, or a custom role with API client management).
- Know your CrowdStrike Falcon cloud region. It determines your base URL (for example, https://api.crowdstrike.com for US-1).
- You need permissions for IP allowlist management.