Skip to main content
availability

Package: Invicti AppSec Enterprise (on-premise, on-demand)

CrowdStrike Infra

CrowdStrike Falcon Spotlight provides real-time vulnerability management for endpoints through the CrowdStrike cloud platform. In Invicti AppSec, the CrowdStrike Infra integration connects to your CrowdStrike account to import vulnerability findings from Spotlight reports into your projects.

Prerequisites

FieldDescription
UsernameCrowdStrike API Client ID
PasswordCrowdStrike API Client Secret

Get API credentials (on CrowdStrike side)

  1. Log in to the CrowdStrike Falcon console.
  2. Navigate to Support & Resources > API Clients and Keys.
  3. Click Add new API client.
  4. Enter a name for the client and select the required scopes:
    • Spotlight vulnerabilities: Read
  5. Click Add. Copy the Client ID and Client Secret immediately — the secret is shown only once.

Step 1: Navigate to Integrations

From the left sidebar menu, click Integrations.

Integrations sidebar

Step 2: Select the Infra tab

On the Integrations > Scanners page, click the Infra tab.

Infra tab

Step 3: Find and activate CrowdStrike Infra

Scroll through the list of Infra scanners to find Crowdstrike Infra.

  • If CrowdStrike Infra is not activated, click Activate to enable the integration.

Step 4: Configure connection settings

Click the gear icon on the CrowdStrike Infra card to open the settings panel. Fill in the required fields:

FieldDescriptionRequired
UsernameCrowdStrike Falcon API Client IDYes
PasswordCrowdStrike Falcon API Client SecretYes
CrowdStrike Infra settings

Step 5: Test the connection

Click Test Connection. A green Connection successful message confirms that Invicti AppSec can authenticate with the CrowdStrike Falcon API.

Summary

StepAction
1Navigate to Integrations from the sidebar
2Select the Infra tab
3Activate CrowdStrike Infra
4Enter Client ID (Username) and Client Secret (Password)
5Test the connection

Create a scan

  1. Open a project in Invicti AppSec.
  2. Go to Settings > Scanners.
  3. Click Add Scanner.

Add CrowdStrike Infra scanner

  1. Select Infra as the scanner type.
  2. Choose Crowdstrike Infra from the scanner list.
  3. Click Add to open the scan configuration drawer.

Scan configuration fields

FieldDescriptionRequired
Profile Namea name to identify this scan configurationYes
Bind toselect the CrowdStrike Spotlight report to bind toYes
Meta Dataadditional metadata to tag the scanYes
Scan Tagfree-text tag to identify or group scansNo
Severity+increase severity of imported findings by one levelNo
Severity-decrease severity of imported findings by one levelNo
note

Bind to links the Invicti AppSec project to a specific CrowdStrike Spotlight report. Vulnerability findings from that report are imported into the project. Severity+ and Severity- are mutually exclusive — only one can be enabled at a time.

CrowdStrike Infra scan creation

Scheduler

Enable the Scheduler toggle to automatically run CrowdStrike Infra scans on a recurring schedule.

Webhook (optional)

Add a webhook URL to receive scan completion notifications.

KDT command

kdt scan -p <project_name> -t crowdstrikeinfra -b -

Troubleshooting

Connection fails

IssueResolution
Invalid Client ID or Secretverify the API credentials in the CrowdStrike Falcon console under Support & Resources > API Clients and Keys.
Insufficient permissionsensure the API client has the Spotlight vulnerabilities: Read scope assigned.
Client Secret not availablethe client secret is shown only at creation — create a new API client if the original wasn't saved.

Scan issues

IssueResolution
No reports available in Bind to dropdownensure Falcon Spotlight is enabled in your CrowdStrike subscription and that report data is available.
Scan shows no findingsthe selected report may have no active vulnerabilities, or Falcon Spotlight may not have data for the associated hosts yet.
Scan not startingverify the scanner is activated and the connection test passes in the integration settings.

Best practices

  • Use a dedicated API client for Invicti AppSec with only the Spotlight vulnerabilities: Read scope — don't grant broader permissions than necessary.
  • Rotate the Client Secret periodically and update the integration settings in Invicti AppSec accordingly.
  • Bind each Invicti AppSec project to the CrowdStrike report that covers its production endpoint fleet for accurate vulnerability data.
  • Use the Scheduler to align scans with your endpoint detection cadence so findings always reflect the latest Spotlight state.

Limitations

  • CrowdStrike Infra in Invicti AppSec imports vulnerability data from CrowdStrike Falcon Spotlight — it doesn't trigger new endpoint scans.
  • Only reports accessible via the provided API client credentials are available for selection.
  • Detection and response (EDR) alerts from CrowdStrike Falcon aren't surfaced in Invicti AppSec; only Spotlight vulnerability findings are imported.
  • Requires an active CrowdStrike Falcon Spotlight subscription.

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?