Connect CrowdStrike to Anzenna
Integrate Anzenna with CrowdStrike Falcon to monitor endpoint detections, alerts, device inventory, and optionally enable real-time response capabilities.
Prerequisites
- CrowdStrike Falcon administrator access
- Anzenna account
Ability to create API clients in CrowdStrike Falcon
Step-by-Step Instructions
Part 1: Start in Anzenna
Log into Anzenna and click Connect to CrowdStrike
Part 2: Create an API Client in CrowdStrike Falcon
Log into CrowdStrike Falcon and click the Menu icon
Click Support and resources
Click API clients and keys
Click Create API client
Type Anzenna as the Client name
Part 3: Configure API Permissions
Set Alerts to Read
Set Detections to Read
Set Hosts to Read (Write required for remediations)
Set Device Control Policies to Read
Set Host Groups to Read (Write required for remediations)
Set User management to Read
Set NGSIEM to Read and Write
Set Real Time Response to Read and Write, and Real Time Response (admin) to Write
Click Create
Part 4: Copy Credentials to Anzenna
Copy the Client ID to clipboard
- Paste the Client ID into Anzenna
Copy the Client Secret to clipboard
Paste the Client Secret into Anzenna and click Save
Anzenna is now connected to CrowdStrike. Continue below to optionally configure Device Control and Real Time Response policies for deeper visibility and remediation.
Part 5: Configure Falcon Device Control Policies (Optional)
To get file exfiltration information, enable metadata collection in Device Control policies.
Open Falcon Device Control Policies and edit your Windows policy — enable Enhanced file metadata detection and click Save
Switch to Mac policy and repeat — enable Enhanced file metadata detection and click Save
Part 6: Configure Real Time Response Policies (Optional)
In the side menu, click Host setup and management
Click Response policies
Select Mac policies and open your selected policy for editing
Enable Real Time Response
Enable Custom Scripts
Enable put, run, and put-and-run
Click Save
Repeat these steps for Windows and Linux (if applicable)
Anzenna is now fully connected to CrowdStrike Falcon.