Configure and enable CrowdStrike Falcon Intelligence integration
Set up CrowdStrike Falcon Intelligence integration to perform threat lookups on observables in Threat Intelligence Security Center.
Before you begin
Role required: sn_sec_tisc.admin
Download the VirusTotal integration from the ServiceNow Store. Confirm you have a valid VirusTotal account before use. For more information, see Download the integration from the ServiceNow Store.
About this task
This integration requires downloading the app from the ServiceNow Store and configuring API credentials from your CrowdStrike account.
Obtain the API Client ID and API Client Secret under your CrowdStrike Falcon Intelligence profile. In the CrowdStrike Falcon Intelligence portal API Scopes, enable the Read setting for Indicators (Falcon Intelligence).
Procedure
Result
After you configure it, CrowdStrike Falcon Intelligence can be selected for performing lookups on observables in Threat Intelligence Security Center.