CrowdStrike Spotlight
Connect CrowdStrike Spotlight to import open vulnerabilities into Guard as risks on the matching hosts.
Overview
The CrowdStrike Spotlight integration brings CrowdStrike vulnerability data into the Praetorian Guard Platform (PGP), so you can correlate endpoint findings with the rest of your exposure data.
In practice, PGP uses both Spotlight and Hosts data together:
- Hosts data is used to map CrowdStrike devices into Guard assets
- Spotlight data is used to ingest open CVEs as Guard risks
- Findings are correlated to assets using CrowdStrike agent IDs
Prerequisites
Before you begin, make sure you have:
- Access to the CrowdStrike Falcon console with permission to create API clients
- A CrowdStrike tenant with Hosts and Spotlight access
- Your CrowdStrike cloud region
Create a CrowdStrike API Client
Sign in to the CrowdStrike Falcon console.
Navigate to Support & Resources → API Clients & Keys.
Click Create API Client.
Grant the following read-only scopes:
If you enable Spotlight in Guard, you must also grant Hosts: Read so Guard can map vulnerability findings back to the correct assets.
After saving the client, copy the following values and store them securely:
- Client ID
- Client Secret
- Cloud Region from your Falcon console URL
Supported regions:
us-1—api.crowdstrike.comus-2—api.us-2.crowdstrike.comeu-1—api.eu-1.crowdstrike.comus-gov-1—api.laggar.gcw.crowdstrike.com
You will not be able to retrieve the client secret again later.
Configure the Integration in PGP
- In PGP, go to Integrations.
- Select Managed Detection & Response → CrowdStrike Falcon.
- Click Connect.
- Enter your Client ID, Client Secret, and Cloud Region.
- Enable the modules you want to use.
For Spotlight vulnerability ingestion, enable:
- Spotlight (Vulnerabilities)
- Hosts (Endpoint Inventory)
Both are enabled by default.
- Click Connect.
PGP validates the API credentials and confirms access to each enabled CrowdStrike module before saving the integration. If a module is not licensed for your tenant, PGP shows The CrowdStrike <module> module is not licensed or not available for this tenant.
What Data Is Synced
Spotlight → PGP Risks
PGP ingests:
- Open CVEs from CrowdStrike Spotlight that match at least one of these filters:
- CrowdStrike ExPRT rating of High or Critical, with a network attack vector
- Listed in the CISA Known Exploited Vulnerabilities catalog, with any attack vector
- On Guard's list of CVEs used in attack-chain correlation
- Findings updated since the last successful Spotlight sync, looking back at least 1 day and at most 5 days (5 days on the first sync)
- CVSS score, severity, description, remediation guidance, references, and proof artifacts
Hosts → Asset Correlation
PGP also reads CrowdStrike host data so it can:
- Correlate Spotlight findings to Guard assets using CrowdStrike agent IDs
- Use hostname and local IP data for asset mapping, for devices seen in the last 7 days
- Skip devices missing required correlation fields such as hostname or local IP
Troubleshooting
Need Help?
If you run into issues during setup, contact support@praetorian.com.