Connect CrowdStrike Falcon

The CrowdStrike Falcon connector lets ISPM discover AI agents that run on your managed endpoints.

About this task

Early Access release

Connecting CrowdStrike Falcon to ISPM lets ISPM discover AI agents that run on your managed endpoints. ISPM can read host and asset inventory from CrowdStrike Falcon over the CrowdStrike API using a read-only API client that you create. Setup happens in two locations:
  1. In CrowdStrike Falcon, create an API client and grant it the required read scopes.
  2. In ISPM, enter the client credentials.

Before you begin

  • You need a Falcon Discover license (required for the Assets scope).
  • You need ngsiem:write and ngsiem:read permissions for MCP discovery.
  • You need a Falcon role that can create API clients (Falcon Administrator, or a custom role with API client management).
  • Know your CrowdStrike Falcon cloud region. It determines your base URL (for example, https://api.crowdstrike.com for US-1).
  • You need permissions for IP allowlist management.

Procedure

  • Allowlist ISPM IP range
    1. Optional. If your CrowdStrike Falcon account has IP allowlisting enabled, add the ISPM IP range. In the CrowdStrike Falcon Console, go to Host setup and management > Falcon users > IP Allowlist Management.
    2. Click Create IP group.
    3. Name the group (for example, ISPM-AI-Discovery).
    4. Set the Access type to API.
    5. Enter each of the following IP addresses and CIDR ranges:
      • 18.98.16.160/27

      • 3.44.64.96/27

      • 3.40.0.96/27

      • 13.52.68.184

      • 54.193.209.206

      • 13.57.96.208

      • 184.72.14.192

      • 13.57.65.107

      • 13.57.96.250

      • 18.99.81.192/27

      • 18.97.155.0/27

    6. Click Create IP group.
    7. Toggle the group Status to On. Allow 30 minutes for enforcement to take effect.
  • Connect CrowdStrike Falcon
    1. In the CrowdStrike Falcon Console, go to Support and resources > Resources and tools > API clients and keys.
    2. Click Create API Client.
    3. Enter a name for the client (for example, ISPM-AI-Discovery).
    4. Grant Read access to the Hosts, Assets (Falcon Discover), and NGSIEM API scopes.
    5. Grant Write access to the NGSIEM API scope.
    6. Copy the Client ID, Secret, and Base URL. The Secret is shown only once. Copy it before closing this page.
    7. Click to create.
    8. In the ISPM console, go to Settings > Sources Gallery.
    9. Select the Crowdstrike integration.
    10. Paste the Client ID, Secret, and Base URL.
    11. Save and test the connection.