Skip to main content
availability

Package: Invicti AppSec Enterprise (on-premise, on-demand)

CrowdStrike CSPM Integration

CrowdStrike Falcon provides cloud security posture management capabilities that detect misconfigurations and compliance violations across your cloud environments. In Invicti AppSec, the CrowdStrike CSPM integration connects to your CrowdStrike account to import cloud security findings into your projects.

Prerequisites

FieldDescription
Client IDCrowdStrike Falcon API Client ID
Client SecretCrowdStrike Falcon API Client Secret

Get API Credentials (on CrowdStrike Side)

  1. Log in to the CrowdStrike Falcon console.
  2. Navigate to Support & Resources > API Clients and Keys.
  3. Click Add new API client.
  4. Enter a name for the client and select the required scopes:
    • CSPM registration: Read
  5. Click Add. Copy the Client ID and Client Secret immediately — the secret is shown only once.

Step 1: Navigate to Integrations

From the left sidebar menu, click on Integrations.

Step 2: Select the CSPM Tab

On the Integrations > Scanners page, click on the CSPM tab.

  CSPM tab

Step 3: Find and Activate CrowdStrike CSPM

Scroll through the list of CSPM scanners to find CrowdStrike CSPM.

  • If CrowdStrike CSPM is not activated, click the Activate button to enable the integration.

Step 4: Configure Connection Settings

Click the gear icon on the CrowdStrike CSPM card to open the settings panel. Fill in the required fields:

FieldDescriptionRequired
Client IDCrowdStrike Falcon API Client IDYes
Client SecretCrowdStrike Falcon API Client SecretYes

  CrowdStrike CSPM settings

Step 5: Test the Connection

Click Test Connection. A green Connection successful message confirms that Invicti AppSec can authenticate with the CrowdStrike Falcon API.

Summary

StepAction
1Navigate to Integrations from the sidebar
2Select the CSPM tab
3Activate CrowdStrike CSPM
4Enter Client ID and Client Secret
5Test the connection

Create a Scan

  1. Open a project in Invicti AppSec.
  2. Go to Settings > Scanners.
  3. Click Add Scanner.

Add CrowdStrike CSPM Scanner

  1. Select CSPM as the scanner type.
  2. Choose CrowdStrike CSPM from the scanner list.
  3. Click Add to open the scan configuration drawer.

Scan Configuration Fields

FieldDescriptionRequired
EnvironmentAssociate the scan with a feature environmentNo
BranchThe branch to associate cloud findings withYes
Meta DataAdditional metadata to tag the scanNo
Scan TagFree-text tag to identify or group scansNo
Cloud FilterFilter imported findings by Account ID, Region, Platform, or SeverityNo
  • Invicti AppSec automatically syncs CrowdStrike CSPM vulnerabilities on a daily basis — no manual trigger is required after the initial scan is configured.

  • Cloud Filter lets you narrow which findings are imported into this project. You can filter by Account ID (comma-separated), Region, Cloud Platform, and Severity level. If no filter is set, all findings accessible via the API credentials are imported.

  CrowdStrike CSPM scan creation

Scheduler

Enable the Scheduler toggle to automatically re-run the CrowdStrike CSPM scan on a recurring schedule.

Webhook (Optional)

Add a webhook URL to receive scan completion notifications.

KDT Command

kdt scan -p <project_name> -t crowdstrikecspm -b <branch_name>

Troubleshooting

Connection Fails

IssueResolution
Invalid Client ID or SecretVerify the API credentials in the CrowdStrike Falcon console under Support & Resources > API Clients and Keys.
Insufficient permissionsEnsure the API client has the CSPM registration: Read scope assigned.
Client Secret not availableThe client secret is shown only at creation — create a new API client if the original was not saved.

Scan Issues

IssueResolution
No findings importedVerify that CrowdStrike Falcon CSPM is enabled in your subscription and that cloud account data is available. Check the Cloud Filter — overly restrictive filters may exclude all findings.
Scan not startingVerify the scanner is activated and the connection test passes in the integration settings.

Best Practices

  • Use a dedicated API client for Invicti AppSec with only the CSPM registration: Read scope — do not grant broader permissions than necessary.
  • Rotate the Client Secret periodically and update the integration settings in Invicti AppSec accordingly.
  • Use Cloud Filters to associate each project with the specific AWS Account IDs, regions, or cloud platforms it covers, so findings are relevant to that project's infrastructure.
  • Use the Scheduler to keep cloud security findings up to date alongside CrowdStrike's assessment cadence.

Limitations

  • CrowdStrike CSPM in Invicti AppSec imports cloud security posture findings — it does not trigger new CrowdStrike assessments.
  • Only findings accessible via the provided API credentials are available for import.
  • Vulnerability sync occurs daily automatically; manual on-demand sync is not supported outside of scheduled scans.
  • Requires an active CrowdStrike Falcon subscription with CSPM capabilities enabled.

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?