CrowdStrike Falcon integration
The Detect in CrowdStrike Falcon rule response adds each lookalike domain a matched rule cites to CrowdStrike Falcon as a custom indicator of compromise (IOC) that expires after seven days. Falcon raises a detection when a host with a Falcon sensor resolves the domain. The rule decides which alerts trigger the response. Connecting an API client alone creates nothing.
Prerequisites
Section titled “Prerequisites”- A CrowdStrike Falcon subscription with IOC management, and hosts with the Falcon sensor on Windows, macOS, or Linux.
- A Falcon administrator who can create API clients.
- The network enforcement add-on on the Have I Been Squatted organization, and an organization admin to configure it.
Create an API client
Section titled “Create an API client”- In the Falcon console, open Support and resources > API clients and keys.
- Select Create API client and name it, for example
Have I Been Squatted. - Grant IOC Management with Read and Write, and nothing else.
- Copy the client ID and secret. Falcon shows the secret once. The API client details also show the base URL, which identifies the Falcon cloud.
IOC Management write covers every IOC in the Falcon customer ID (CID), not only the IOCs Have I Been Squatted creates, and Falcon cannot narrow it. Have I Been Squatted therefore limits itself: it changes only IOCs whose source is Have I Been Squatted. Do not use that source on IOCs you create yourself.
Connect
Section titled “Connect”- In the app, open Connectors > CrowdStrike Falcon.
- Select the Falcon cloud, then enter the client ID and secret.
- Optionally enter host group IDs and turn on retrodetects (see Scope).
- Select Save, then Test connection.
The secret is stored server-side and never returned to the browser. Leave the secret blank to keep the saved one; a new client ID needs its own secret.
| Cloud | API base URL |
|---|---|
| US-1 | https://api.crowdstrike.com |
| US-2 | https://api.us-2.crowdstrike.com |
| US-3 | https://api.us-3.crowdstrike.com |
| EU-1 | https://api.eu-1.crowdstrike.com |
| US-GOV-1 | https://api.laggar.gcw.crowdstrike.com |
| US-GOV-2 | https://api.us-gov-2.crowdstrike.mil |
Connection check
Section titled “Connection check”The check requests a token for the saved cloud, lists one IOC ID, and sends an IOC update that names no IOC. An API client without IOC Management write is refused with a permission error; with write access, Falcon rejects the empty update, so the check changes nothing. Saving pauses IOC creation until a check of the saved configuration passes.
| Result | Meaning |
|---|---|
| Authentication | CrowdStrike rejected the client ID and secret. |
| Wrong cloud | The API client belongs to another Falcon cloud. The message names it when Falcon reports it. |
| Read permission missing | The API client lacks IOC Management read. |
| Write permission missing | The API client lacks IOC Management write. |
| Rate limited | CrowdStrike throttled the check. Test again in a minute. |
| Unreachable | CrowdStrike timed out or returned a server error. Test again later. |
IOCs apply to every host in the CID by default. To limit them, enter up to 10 host group IDs, one per line. A host group ID is the 32-character hexadecimal identifier shown in the Falcon console under Host setup and management > Host groups. The API client does not need to read host groups, so saved IDs are not checked against Falcon. Changes apply to IOCs created or renewed afterward.
Retrodetects asks Falcon to also raise detections for hosts that resolved the domain before the IOC existed. It applies when an IOC is created.
Add the response to a rule
Section titled “Add the response to a rule”- Create or edit a rule and open the Response tab.
- Select Add action > Detect in CrowdStrike Falcon.
- Select the CrowdStrike Falcon destination.
- Save the rule.
The destination is listed only after a connection check has passed. The response needs at least one domain condition in the rule, because only cited lookalike domain records produce IOCs.
What is sent
Section titled “What is sent”For each active rule alert that cites lookalike domain records, Have I Been Squatted looks up each distinct cited domain, up to 10 per alert, and then:
- No IOC for the domain: creates one.
- An IOC with the Have I Been Squatted source: renews it when less than half of its seven days remain or it has expired, and otherwise leaves it.
- An IOC with the Have I Been Squatted source that someone set to No action before it expired: leaves it, so the change made in the Falcon console stands.
- Any other IOC for the domain, including one inherited from a parent CID: leaves it unchanged and records the domain as covered by your IOC. Falcon keeps one IOC per type and value.
| Field | Value |
|---|---|
type |
domain |
value |
The cited lookalike domain |
action |
detect |
severity |
From the rule level: informational, low, medium, high, or critical |
source |
Have I Been Squatted |
expiration |
Seven days after the change |
platforms |
Windows, Mac, and Linux |
host_groups, applied_globally |
The configured host groups, or every host when none are set |
description |
The Have I Been Squatted alert ID, the monitored domain, and the rule title |
The audit comment names the rule. After the changes, Have I Been Squatted reads the changed IOCs back and checks that each still detects.
- Only domains from cited domain (lookalike permutation) records are sent.
- The monitored domain and its subdomains are never sent.
- Email and canary evidence never produce IOCs.
If Falcon refuses one domain, the others are still sent. If CrowdStrike times out, returns a server error, or rejects the credentials, the remaining domains are not sent and the delivery is not retried. A throttled request is sent once more when CrowdStrike asks to wait ten seconds or less.
When an IOC expires, Falcon sets its action to No action. A later alert for the domain renews it.
What is recorded
Section titled “What is recorded”Have I Been Squatted stores the cloud, the client ID and secret, the host groups and retrodetects setting, and the time and outcome of the last connection check. For each alert and response, it records the delivery status, the ID, domain, and result (created, renewed, or current) of each IOC, the domains covered by your IOCs, refused, or not sent, the expiry, and, when a delivery fails, a short error code. Tokens and CrowdStrike response bodies are not stored.
Disable and disconnect
Section titled “Disable and disconnect”Disable stops new IOCs and keeps the connection and rule responses. A passing connection test turns detections back on.
Disconnect deletes the stored credentials and removes the Detect in CrowdStrike Falcon response from every rule, along with those responses’ delivery records.
Neither action deletes IOCs already in Falcon. They stop detecting when they expire, within seven days, or when an administrator removes them in the Falcon console under Endpoint security > IOC management. To revoke access, delete the API client in the Falcon console.
Limits
Section titled “Limits”- Each delivery requests a new token and makes up to 22 API calls for 10 domains.
- IOCs detect domains only. They do not detect URLs or IP addresses.
- Detection depends on the Falcon sensor observing the DNS request.