CrowdStrike Spotlight
CrowdStrike Spotlight
Overview
The CrowdStrike Spotlight integration brings CrowdStrike vulnerability data into the Praetorian Guard Platform (PGP), so you can correlate endpoint findings with the rest of your exposure data.
In practice, PGP uses both Spotlight and Hosts data together:
Hosts data is used to map CrowdStrike devices into Guard assets
Spotlight data is used to ingest open CVEs as Guard risks
Findings are correlated to assets using CrowdStrike agent IDs
This gives you a clearer view of which vulnerable endpoints matter most in the context of your broader attack surface.
Prerequisites
Before you begin, make sure you have:
Access to the CrowdStrike Falcon console with permission to create API clients
A CrowdStrike tenant with Hosts and Spotlight access
Your CrowdStrike cloud region
Create a CrowdStrike API Client
Sign in to the CrowdStrike Falcon console.
Navigate to Support & Resources → API Clients & Keys.
Click Create API Client.
Grant the following read-only scopes:
If you enable Spotlight in Guard, you must also grant Hosts: Read so Guard can map vulnerability findings back to the correct assets.
After saving the client, copy the following values and store them securely:
Client ID
Client Secret
Cloud Region from your Falcon console URL
Supported regions:
us-1—api.crowdstrike.comus-2—api.us-2.crowdstrike.comeu-1—api.eu-1.crowdstrike.comus-gov-1—api.laggar.gcw.crowdstrike.com
You will not be able to retrieve the client secret again later.
Configure the Integration in PGP
In PGP, go to Integrations.
Select Managed Detection & Response → CrowdStrike.
Click Connect.
Enter your Client ID, Client Secret, and Cloud Region.
Enable the modules you want to use.
For Spotlight vulnerability ingestion, enable:
Spotlight
Hosts
Click Connect.
PGP validates the API credentials and confirms access to the enabled CrowdStrike modules before saving the integration.
What Data Is Synced
Spotlight → PGP Risks
PGP ingests:
Open CVEs from CrowdStrike Spotlight
Findings updated in the last 7 days
CVSS score, severity, description, remediation guidance, references, and proof artifacts
All Spotlight vulnerability vectors supported by CrowdStrike, not just network-reachable findings
Hosts → Asset Correlation
PGP also reads CrowdStrike host data so it can:
Correlate Spotlight findings to Guard assets using CrowdStrike agent IDs
Use hostname and local IP data for asset mapping
Skip devices missing required correlation fields such as hostname or local IP
Troubleshooting
Need Help?
If you run into issues during setup, contact support@praetorian.com.