Connect CrowdStrike to Anzenna
Integrate Anzenna with CrowdStrike Falcon to monitor endpoint detections, alerts, device inventory, and optionally enable real-time response capabilities.
Prerequisites
- CrowdStrike Falcon administrator access
- Anzenna account
- Ability to create API clients in CrowdStrike Falcon
Step-by-Step Instructions
Part 1: Start in Anzenna
- Log into Anzenna and click Connect to CrowdStrike
Part 2: Create an API Client in CrowdStrike Falcon
- Log into CrowdStrike Falcon and click the Menu icon
- Click Support and resources
- Click API clients and keys
- Click Create API client
- Type Anzenna as the Client name
Part 3: Configure API Permissions
- Set Alerts to Read
- Set Detections to Read
- Set Hosts to Read (Write required for remediations)
- Set Device Control Policies to Read
- Set Host Groups to Read (Write required for remediations)
- Set User management to Read
- Set NGSIEM to Read and Write
- Set Real Time Response to Read and Write, and Real Time Response (admin) to Write
- Click Create
Part 4: Copy Credentials to Anzenna
- Copy the Client ID to clipboard
- Paste the Client ID into Anzenna
- Copy the Client Secret to clipboard
- Paste the Client Secret into Anzenna and click Save
Core Setup Complete!
Anzenna is now connected to CrowdStrike. Continue below to optionally configure Device Control and Real Time Response policies for deeper visibility and remediation.
Part 5: Configure Falcon Device Control Policies (Optional)
To get file exfiltration information, enable metadata collection in Device Control policies.
- Open Falcon Device Control Policies and edit your Windows policy — enable Enhanced file metadata detection and click Save
- Switch to Mac policy and repeat — enable Enhanced file metadata detection and click Save
Part 6: Configure Real Time Response Policies (Optional)
- In the side menu, click Host setup and management
- Click Response policies
- Select Mac policies and open your selected policy for editing
- Enable Real Time Response
- Enable Custom Scripts
- Enable put, run, and put-and-run
- Click Save
- Repeat these steps for Windows and Linux (if applicable)
You are all set!
Anzenna is now fully connected to CrowdStrike Falcon.