> ## Documentation Index
> Fetch the complete documentation index at: https://docs.allquiet.app/llms.txt
> Use this file to discover all available pages before exploring further.

# CrowdStrike

> Connect CrowdStrike Falcon with All Quiet

<Info>Setup time: 5 Min</Info>

Integrate Crowdstrike Falcon with All Quiet in a matter of minutes. With webhooks, you can automatically send alerts from CrowdStrike Falcon directly to All Quiet, streamlining your team's incident management process.

## 1. Create CrowdStrike Integration on All Quiet

Sign in to your All Quiet account.

### Create Integration

1. Click on the `Inbound Integrations` tab.
2. Click on `+ Create`.

<img className="CrowdStrike_Create" src="https://mintcdn.com/allquiet/DD3fFjQiex-iZR__/images/crowdstrike/01.png?fit=max&auto=format&n=DD3fFjQiex-iZR__&q=85&s=51d66d7e4cbec82ec89dfdba52d9a51c" width="2740" height="678" data-path="images/crowdstrike/01.png" />

### Select CrowdStrike as the integration's type

1. Enter a `Display Name` for your integration, e.g. "CrowdStrike".
2. Select a `Team`.
3. Select `CrowdStrike` as the integration's type.
4. Click `Create Inbound Integration`.

<img className="CrowdStrike_Select" src="https://mintcdn.com/allquiet/DD3fFjQiex-iZR__/images/crowdstrike/02.png?fit=max&auto=format&n=DD3fFjQiex-iZR__&q=85&s=ce0bd6dde9bf5255b1ab2b9ad514ad88" width="2158" height="1864" data-path="images/crowdstrike/02.png" />

### Get the All Quiet Webhook URL

After creating the integration on All Quiet, you can view and copy the webhook URL. You will require this URL in step 2 when configuring the custom integration on CrowdStrike.

<img className="CrowdStrike_Get" src="https://mintcdn.com/allquiet/DD3fFjQiex-iZR__/images/crowdstrike/03.png?fit=max&auto=format&n=DD3fFjQiex-iZR__&q=85&s=d9f2bf5b8fc77e9cb6d089313bb35acd" width="2186" height="954" data-path="images/crowdstrike/03.png" />

## 2. Configure the Integration with CrowdStrike

Once you've set up an integration of type "CrowdStrike" with All Quiet, it takes only three more steps in your CrowdStrike account to finish off your setup.

### Set up the Webhook to All Quiet

Sign in to your CrowdStrike Account.
We first need to create the Webhook

1. From the home screen, open the side navigation and select `CrowdStrike Store`
2. Select `All apps`

<img className="CrowdStrike_FindStore" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/04.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=b435508ca4aafc90d5742b40e3f35d86" width="1600" height="1606" data-path="images/crowdstrike/04.png" />

1. In the store, search for \`Webhook\`\`
2. Select the `CrowdStrike Webhook`

<img className="CrowdStrike_Store_Webhook" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/05.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=80c38017ca309e94a2f154044b5286fd" width="2720" height="1806" data-path="images/crowdstrike/05.png" />

1. Click `Configure`
2. Select `Add configuration`

<img className="CrowdStrike_Store_AddWebhook" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/06.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=490bf55a87c320ee7f9b5162a29e0c3f" width="3420" height="1449" data-path="images/crowdstrike/06.png" />

1. Select a name for you Webhook, like `All Quiet`
2. As `Webhook URL`, paste in the All Quiet Webhook URL you've obtained in step [Get the All Quiet Webhook URL](/integrations/inbound/crowdstrike#get-the-all-quiet-webhook-url).
3. **Remove** the `HMAC Secret Keys`
4. **Remove** the `Signature Header Name`
5. Save the Webhook.

<img className="CrowdStrike_ConfigureWebhook" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/07.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=036e3bbcffc62fbd7ced9538c5a8a2bc" width="1409" height="1969" data-path="images/crowdstrike/07.png" />

<Check>You've successfully created the Webhook. Next, we need to set up a workflow to create All Quiet incidents from CrowdStrike, using the Webhook.</Check>

### Set up Workflow for Incident Creation

Now, we need to set up a workflow to **create** All Quiet incidents from CrowdStrike.

1. In the sidebar navigation, select \`Fusion SOAR\`\`
2. Open `Workflows`

<img className="CrowdStrike_SidebarWorkflow" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/08.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=e34d228f9242512082fbd414beb4f65b" width="1346" height="1176" data-path="images/crowdstrike/08.png" />

In the workflows overview, select `Create workflow`

<img className="CrowdStrike_WorkflowOverview" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/09.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=969661a2edf5b16a63caf972d275e393" width="3715" height="817" data-path="images/crowdstrike/09.png" />

1. Select `Create workflow from scratch`
2. Click `Next`

<img className="CrowdStrike_ConfigureWorkflowFromScratch" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/10.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=51b44265b8d13dd3e0b1cc1afdac5417" width="1811" height="1969" data-path="images/crowdstrike/10.png" />

Define the trigger. To select a trigger that creates new incidents,

1. open the `Endpoint security` section
2. and select `Alert` / `Detection`. This [selection differs from the worflow we will create later to update incidents that already got created](/integrations/inbound/crowdstrike#set-up-workflow-for-incident-updates)

<Tip>In the latest version of CrowdStrike Falcon Fusion, the “Alert” trigger has been renamed to “Detection.” If you encounter references to “Alert” in the information below, look for “Detection” instead in your current version of CrowdStrike.</Tip>

<img className="CrowdStrike_CreateIncident_Trigger1" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/11.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=f133a26fd63963edd2f4fbe436363c2a" width="2320" height="1452" data-path="images/crowdstrike/11.png" />

1. After selecting `Alert` / `Detection` click `Next`.

<img className="CrowdStrike_CreateIncident_Trigger2" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/12.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=b6a60dba42cb0e09d043329796eff67b" width="1086" height="754" data-path="images/crowdstrike/12.png" />

1. Now, we need to add an `Action` to the triggering alert / detection.
2. Select the `CrowdStrike` section.
3. Select `Call webhook`.

<img className="CrowdStrike_CreateIncident_Action1" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/13.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=8891709f1aa9de582688edce6505a1b3" width="2186" height="1672" data-path="images/crowdstrike/13.png" />

Now, we need to configure the `Call webhook` action.

1. As Webhook, select the `All Quiet` Webhook we configured in the [previous step](/integrations/inbound/crowdstrike#set-up-the-webhook-to-all-quiet).
2. For Data format, select `Default`.
3. As Data to include, select **all `Alert` objects / all `Detection` objects** from the dropdown and add them.
4. Click `Next`.

<img className="CrowdStrike_CreateIncident_Action2" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/14.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=fce2ce12ca6760dbb61c70c911acf54b" width="1092" height="1556" data-path="images/crowdstrike/14.png" />

We're almost done with this step. Time to `Save and exit` the workflow.

<img className="CrowdStrike_CreateIncident_save1" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/15.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=b6bcf17105b19f3895314eb426cce72d" width="2490" height="1364" data-path="images/crowdstrike/15.png" />

To `save and exit`,

1. Give your worflow a name, like `All Quiet Create Incident`
2. Don't forget to activate it.
3. Confirm.

<img className="CrowdStrike_CreateIncident_save2" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/16.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=016af629df13f07aa06a0561d844020d" width="1182" height="1650" data-path="images/crowdstrike/16.png" />

<Check>You're now able to create All Quiet incidents from CrowdStrike. In order to being able to update - e.g resolve - them from CrowdStrike, we need to add an extra, pretty similar workflow in the next step.</Check>

### Set up Workflow for Incident Updates

Add an extra Workflow.

1. This time, select `Audit event > Alert` / `Audit event > Detection` as trigger, as we want to listen to updates for existing incidents.

<img className="CrowdStrike_UpdateIncident_Trigger1" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/17.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=8b1625a232cee953f3fa84b5fc021d90" width="2312" height="1688" data-path="images/crowdstrike/17.png" />

1. As we want to listen to all kinds for updates, select `All` as type and continue.

<img className="CrowdStrike_UpdateIncident_Trigger2" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/18.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=4fa18c30e5110333540d0dbf9eac724d" width="1102" height="962" data-path="images/crowdstrike/18.png" />

After setting up the trigger, add the similar action with the same settings as in the previous step when defining the [workflow to create incidents](/integrations/inbound/crowdstrike#set-up-workflow-for-incident-creation). This ensures incident updates are sent to All Quiet via the same webhook.

<img className="CrowdStrike_CrowdStrike_UpdateIncident_Action" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/19.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=3424242f25f9eecbe1d4505b07f87490" width="2476" height="1680" data-path="images/crowdstrike/19.png" />

When saving the workflow

1. Make sure to add a suitable name, like `All Quiet - Update Incident`.
2. Activate the workflow.
3. And click `Save and exit` to confirm.

<img className="CrowdStrike_ConfigureWebhook" src="https://mintcdn.com/allquiet/y65KzxFgbkd3W3cK/images/crowdstrike/20.png?fit=max&auto=format&n=y65KzxFgbkd3W3cK&q=85&s=09d2cdcdacaeac356704c13a66746622" width="1176" height="1692" data-path="images/crowdstrike/20.png" />

<Check> You're ready to go. If you set up your integration this way, CrowdStrike alerts / detections will automatically create and update All Quiet incidents.</Check>

### Adjust Payload Mapping

Looking to customize the fields of your incidents by adjusting the pre-built payload mapping? Simply head over to the “Payload” tab within your integration and make the necessary edits to the mapping. For detailed guidance, you may check out our [payload mapping documentation](/essentials/inbound#how-does-attribute-mapping-work).

<Tip>Using our Terraform provider? [Download](https://allquiet.app/api/integrations/terraform/default/CrowdStrike.tf) the default mapping of the `allquiet_integration_mapping` resource for the CrowdStrike integration. Simply copy the syntax to your .tf file and tailor the resource to your team's needs!</Tip>
