---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure and enable CrowdStrike Falcon Intelligence integration

# Configure and enable CrowdStrike Falcon Intelligence integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Set up CrowdStrike Falcon Intelligence integration to perform threat lookups on observables in Threat Intelligence Security Center.

## Before you begin

Role required: sn_sec_tisc.admin  
Note:  
The Threat Intelligence Security Center and VirusTotal Threat Lookup plugins must be installed and active.

Download the VirusTotal integration from the ServiceNow Store. Confirm you have a valid VirusTotal account before use. For more information, see [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").

## About this task

This integration requires downloading the app from the ServiceNow Store and configuring API credentials from your CrowdStrike account.

Obtain the API Client ID and API Client Secret under your CrowdStrike Falcon Intelligence profile. In the CrowdStrike Falcon Intelligence portal API Scopes, enable the Read setting for Indicators (Falcon Intelligence).

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterIntegrationsEnrichment IntegrationsAll IntegrationsThreat Lookup.
2. Select Configure New Enrichment to configure CrowdStrike Falcon Intelligence integration.
3. Fill in the fields on the Configure New Enrichment form.  
   {#crowdstrike-intelligence__table_iqf_n4p_tzb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the new enrichment integration. For example, CrowdStrike Falcon Intelligence. |
   | Vendor Name | Name of the vendor. The details of the selected vendor is populated by default. For example, CrowdStrike Falcon Intelligence. |
   | Integration Type | Type of integration that you selected. For example, Threat Lookup. |
   | Description | Description for the new enrichment integration. |
   | Integration Configuration ||
   | Client ID | The client ID that you obtained from CrowdStrike. |
   | Client Secret | The client secret key that you obtained from CrowdStrike. |
   [Table 1. Enrichment Integration]

   {#crowdstrike-intelligence__table_iqf_n4p_tzb}
4. Select Save to apply the changes.  
   The integration details are validated, and by default the CrowdStrike Falcon Intelligence integration's status is inactive.
5. Select Enable to enable the CrowdStrike Falcon Intelligence integration.
{#crowdstrike-intelligence__steps_fjb_ctp_tzb}

## Result

After you configure it, CrowdStrike Falcon Intelligence can be selected for performing lookups on observables in Threat Intelligence Security Center.
**Related concepts**   

* [Threat Lookup](https://servicenow-prod.fluidtopics.net/_rITe~FbPtAFkY0_yCvhQw "Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.")  
**Related tasks**   

* [Configure and enable VirusTotal Integration](https://servicenow-prod.fluidtopics.net/juIGU8nubSIVGK69fxuowQ "Set up VirusTotal integration with Threat Intelligence Security Center to perform threat lookups on observables.")

*[\>]: and then


