Integrating Permissions
Last updated
Last updated
This document describes integrating the Rezonate product with CrowdStrike Falcon, which provides observability to on-premise hosts, users, and CrowdStrike detection data.
Note: To Integrate, please perform the following actions after authenticating to CrowdStrike as a Falcon Administrator.
Navigate to CrowdStrike Store > All apps
Scroll down to the “Plugins” section and click on Webhook
Click “Configure”:
Click "Add Configuration" and configure the following:
Name: Rezonate Webhook
Webhook URL: {Url Received From Rezonate}
HMAC Secret Key: {HMAC Received from Rezonate}
Signature Header Name: Keep the default value (X-Cs-Primary-Signature)
Save configuration
Navigate to Fusion workflows > All workflows
Click Create workflow
Click Create Workflow from scratch on the new page and then click Next.
In the “Create workflow dialog, choose Event as the workflow trigger and click next.
In the “Select trigger” dropdown box, choose Alert. Choose the subcategory to be “EPP Detection”, and click next.
On the right side of the “Create workflow” dialog, click the + button next to the trigger box.
Click on “Add action”
In the workflow dialog, choose Notify.
Choose “Call webhook”.
In the Webhook name, choose the new “Rezonate Webhook”.
In data to include, choose the following data points:
Alert ID
Behavior timestamp
Command Line
Description
Executable SHA256
File Path
Name
Sensor platform
Sensor hostname
Sensor domain
Sensor local IP address
Sensor external IP address
Sensor Host ID
Severity
Tactic
Technique
User name
User ID
Action Taken
Now click next and finish.
Name the workflow as “Rezonate Workflow”
Turn the workflow status to On
Save workflow
To Integrate, please perform the following actions after authenticating to CrowdStrike as a Falcon Administrator
Configure the following:
Client name - “Rezonate Integration”
Description - “API key used by Rezonate”
Scopes:
Alerts - Read
Detections - Read
Hosts - Read
IOC Management - Read, Write
IOCs (Indicators of Compromise) - Read, Write
OPTIONAL: Discover - Read
Click Create.
Copy the Client ID, Secret, and Base URL and share them back with Rezonate.
Navigate to Support and Resources> API clients and keys
Click on “Create API client”