Setting Up a Zip Security & CrowdStrike Integration

Below we outline the guidance for connecting CrowdStrike to the Zip Console. If we are provisioning a CrowdStrike instance for you, this step will be completed by the Zip team. If your organization already has CrowdStrike provisioned, you can follow the below instructions to connect it with the Zip console.

Connecting Customer CrowdStrike Instance to the Zip Console

  1. Log in to CrowdStrike
  1. In the menu, go to Documentation & ResourcesApi clients and keys to create a service account.
  1. Click Add new API client in the top right corner.
  1. Create a new client named Zip App.
      • Select the following read permissions: Alerts, Detections, Device control policies (if available), hosts, assets (if available), host groups, incidents, installation tokens, IOC management, IOCs, prevention policies, quarantined files, sensor download, sensor update policies, user management.
      • Select the following write permissions: alerts, detections, device control policies (if available), hosts, host groups, incidents, prevention policies, sensor update policies.
  1. After you have created it, go to https://zipsecinc.cc/organizationsettings, click Add New ProviderCrowdStrike. Copy the Client ID and Client Secret from CrowdStrike.
    1. 📣
      For organizations connecting to a CrowdStrike tenant in a different region other than https://api.us-2.crowdstrike.com
      1. Expand the “Advanced Configuration” toggle at the bottom of the form
      1. Change the CrowdStrike API URL field to your CrowdStrike tenant’s base API URL. It should be one of the following:
          • US-1https://api.crowdstrike.com
          • US-2https://api.us-2.crowdstrike.com
          • EU-1https://api.eu-1.crowdstrike.com
          • US-GOV-1https://api.laggar.gcw.crowdstrike.com
          • US-GOV-2https://api.us-gov-2.crowdstrike.mil
      Otherwise, leave these fields as the default values.
      Click Save.
  1. Save down the Client ID and Client Secret in a secure way (i.e. in a password manager).

👋
Questions? Here’s how to reach us:
  • Email: info@zipsecinc.cc