Overview
The CrowdStrike integration monitors your endpoint security platform: endpoints, detections, incidents, policies, and vulnerabilities. LowerPlane uses read-only OAuth access to collect compliance evidence automatically.Prerequisites
How to Connect
Log in to CrowdStrike
Log in to the CrowdStrike Falcon Console.
Create API Client
Navigate to Support and Resources > API Clients and Keys and create a new OAuth2 API client with these scopes:
hosts:read— Read endpoint inventorydetects:read— Read detection alertsincidents:read— Read incident data
What LowerPlane Monitors
Endpoints
Managed endpoints, OS versions, sensor status, and agent health.
Detections & Incidents
Threat detections, incident reports, and response actions.
Policies
Prevention policies, device control policies, and firewall rules.
Vulnerabilities
Vulnerability assessments and exposure management findings.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Endpoint protection and threat detection are in place |
| ISO 27001 | Malware protection and vulnerability management are implemented |
| HIPAA | Endpoint security controls protect ePHI systems |
| PCI-DSS | Anti-malware and intrusion detection are deployed |