---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# CrowdStrike Falcon Intelligence integration overview

# CrowdStrike Falcon Intelligence integration overview {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

CrowdStrike Falcon Intelligence provides cyber security intelligence that easily
integrating with Security Operations.  
Note:  
The Threat Intelligence plugin is required to implement the CrowdStrike Falcon Intelligence integration.
**Related tasks**   

* [Submit an IoC Lookup request from the Security Incident Catalog](https://servicenow-prod.fluidtopics.net/HaHjNYPHLT_Nwz6XIlJzLw "If the Security Incident Response plugin is activated, you can submit threat lookups for files, hash values, URLs, and IP addresses from the Security Incident Catalog. The requests are submitted and you can view the results in the My Requests module.")

## Threat Lookup - CrowdStrike Falcon Intelligence flows {#ariaid-title2}

The Threat Lookup - CrowdStrike Falcon Intelligence flow designer performs a lookup on selected observables. If the observables are of a type recognized by CrowdStrike Falcon Intelligence, the observables are scanned for malware, and the results are returned.  
This flow is triggered by the [Security Operations Integration - Threat Lookup capability](https://servicenow-prod.fluidtopics.net/aKsui0~8zhutMOFnbigrAA "The Threat Lookups capability performs threat intelligence lookups to determine whether one or more observables are associated with known security threats.") when you publish one or more observables to a watchlist, and the CrowdStrike Falcon Intelligence implementation is selected. After they are published, the watchlists can be viewed
in the CrowdStrike Falcon Host software.

Role required: admin

For information on the activities used by this flow designer, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").

## Activate and configure the CrowdStrike Falcon Intelligence integration {#ariaid-title3}

The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the CrowdStrike Falcon Intelligence integration. Before you can use the CrowdStrike Falcon Intelligence, you must download it from the ServiceNow Store and add the appropriate API key and ID.

### Before you begin

Role required: admin  
* The Threat Intelligence plugin must be installed and activated before you can use the CrowdStrike Falcon Intelligence integration.
* Obtain the API Client ID and API Client Secret under your CrowdStrike Falcon Intelligence profile.
* If you are upgrading CrowdStrike Falcon Intelligence integration from a previous version, then you must delete the existing configuration and set up a new configuration. The integration supports OAUTH2 authentication. This update requires you to enter the API Client ID and the API Client Secret to authenticate and complete the configuration.
* In the CrowdStrike Falcon Intelligence portal API Scopes, enable the Read setting for Indicators (Falcon X) or IOCs (Indicators of Compromise).
{#activate-configure-crowdstrike-intell__ul_gyp_1hh_qnb}

### Procedure

1. [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. In your instance, navigate to Security OperationsIntegrationsIntegration Configurations.  
   The available security integrations appear as a series of cards. {#activate-configure-crowdstrike-intell__Nav-To}
{#activate-configure-crowdstrike-intell__Nav-To}
3. In the CrowdStrike Falcon Intelligence card, click Configure.
4. On the form, fill in the fields to complete the configuration:  
   {#activate-configure-crowdstrike-intell__table_ifn_tlk_mnb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the integration, for example, <kbd class="ph userinput">demo-1</kbd>. |
   | API Client ID | The client ID that you obtain from the settings section of your account profile in CrowdStrike Falcon Intelligence portal. |
   | API Client Secret | The client secret key that you obtain from the settings section of your account profile in CrowdStrike Falcon Intelligence portal. |
   [Table 1. CrowdStrike Falcon Intelligence Configuration]

   {#activate-configure-crowdstrike-intell__table_ifn_tlk_mnb}
5. Click Submit.
{#activate-configure-crowdstrike-intell__steps_gfz_1yn_vw}

### Result

After it is configured, CrowdStrike Falcon Intelligence can be selected for performing lookups on observables in Threat Intelligence and on observables in security incidents.
**Related tasks**   

* [Perform lookups on observables](https://servicenow-prod.fluidtopics.net/lpoUE~l5Cuui5Nt5XCnFsA "You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.")

*[\>]: and then


