Configure and enable CrowdStrike Falcon Intelligence integration

  • Release version: Australia
  • Updated March 12, 2026
  • 1 minute to read
  • Set up CrowdStrike Falcon Intelligence integration to perform threat lookups on observables in Threat Intelligence Security Center.

    Before you begin

    Role required: sn_sec_tisc.admin

    Note:
    The Threat Intelligence Security Center and VirusTotal Threat Lookup plugins must be installed and active.

    Download the VirusTotal integration from the ServiceNow Store. Confirm you have a valid VirusTotal account before use. For more information, see Download the integration from the ServiceNow Store.

    About this task

    This integration requires downloading the app from the ServiceNow Store and configuring API credentials from your CrowdStrike account.

    Obtain the API Client ID and API Client Secret under your CrowdStrike Falcon Intelligence profile. In the CrowdStrike Falcon Intelligence portal API Scopes, enable the Read setting for Indicators (Falcon Intelligence).

    Procedure

    1. Navigate to Workspaces > Threat Intelligence Security Center > Integrations > Enrichment Integrations > All Integrations > Threat Lookup.
    2. Select Configure New Enrichment to configure CrowdStrike Falcon Intelligence integration.
    3. Fill in the fields on the Configure New Enrichment form.
      Table 1. Enrichment Integration
      Field Description
      Name Name for the new enrichment integration. For example, CrowdStrike Falcon Intelligence.
      Vendor Name Name of the vendor. The details of the selected vendor is populated by default. For example, CrowdStrike Falcon Intelligence.
      Integration Type Type of integration that you selected. For example, Threat Lookup.
      Description Description for the new enrichment integration.
      Integration Configuration
      Client ID The client ID that you obtained from CrowdStrike.
      Client Secret The client secret key that you obtained from CrowdStrike.
    4. Select Save to apply the changes.
      The integration details are validated, and by default the CrowdStrike Falcon Intelligence integration's status is inactive.
    5. Select Enable to enable the CrowdStrike Falcon Intelligence integration.

    Result

    After you configure it, CrowdStrike Falcon Intelligence can be selected for performing lookups on observables in Threat Intelligence Security Center.