Overview

The CrowdStrike integration monitors your endpoint security platform: endpoints, detections, incidents, policies, and vulnerabilities. LowerPlane uses read-only OAuth access to collect compliance evidence automatically.

Prerequisites

You need CrowdStrike Falcon Administrator permissions to create OAuth API credentials.

How to Connect

1

Log in to CrowdStrike

2

Create API Client

Navigate to Support and Resources > API Clients and Keys and create a new OAuth2 API client with these scopes:
  • hosts:read — Read endpoint inventory
  • detects:read — Read detection alerts
  • incidents:read — Read incident data
3

Connect in LowerPlane

Go to Settings > Integrations in LowerPlane, find CrowdStrike, click Connect, and authorize with your API credentials.

What LowerPlane Monitors

Endpoints

Managed endpoints, OS versions, sensor status, and agent health.

Detections & Incidents

Threat detections, incident reports, and response actions.

Policies

Prevention policies, device control policies, and firewall rules.

Vulnerabilities

Vulnerability assessments and exposure management findings.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Endpoint protection and threat detection are in place
ISO 27001Malware protection and vulnerability management are implemented
HIPAAEndpoint security controls protect ePHI systems
PCI-DSSAnti-malware and intrusion detection are deployed