CrowdStrike Spotlight

CrowdStrike Spotlight

Overview

The CrowdStrike Spotlight integration brings CrowdStrike vulnerability data into the Praetorian Guard Platform (PGP), so you can correlate endpoint findings with the rest of your exposure data.

In practice, PGP uses both Spotlight and Hosts data together:

  • Hosts data is used to map CrowdStrike devices into Guard assets

  • Spotlight data is used to ingest open CVEs as Guard risks

  • Findings are correlated to assets using CrowdStrike agent IDs

This gives you a clearer view of which vulnerable endpoints matter most in the context of your broader attack surface.


Prerequisites

Before you begin, make sure you have:

  • Access to the CrowdStrike Falcon console with permission to create API clients

  • A CrowdStrike tenant with Hosts and Spotlight access

  • Your CrowdStrike cloud region


Create a CrowdStrike API Client

  1. Sign in to the CrowdStrike Falcon console.

  2. Navigate to Support & Resources → API Clients & Keys.

  3. Click Create API Client.

    1. Grant the following read-only scopes:

      Scope

      Required for

      Hosts: Read

      Asset correlation and host inventory lookup

      Vulnerabilities: Read

      Spotlight vulnerability ingestion

If you enable Spotlight in Guard, you must also grant Hosts: Read so Guard can map vulnerability findings back to the correct assets.

After saving the client, copy the following values and store them securely:

  • Client ID

  • Client Secret

  • Cloud Region from your Falcon console URL

Supported regions:

  • us-1api.crowdstrike.com

  • us-2api.us-2.crowdstrike.com

  • eu-1api.eu-1.crowdstrike.com

  • us-gov-1api.laggar.gcw.crowdstrike.com

You will not be able to retrieve the client secret again later.


Configure the Integration in PGP

  1. In PGP, go to Integrations.

  2. Select Managed Detection & Response → CrowdStrike.

  3. Click Connect.

  4. Enter your Client ID, Client Secret, and Cloud Region.

  5. Enable the modules you want to use.

For Spotlight vulnerability ingestion, enable:

  • Spotlight

  • Hosts

  1. Click Connect.

PGP validates the API credentials and confirms access to the enabled CrowdStrike modules before saving the integration.


What Data Is Synced

Spotlight → PGP Risks

PGP ingests:

  • Open CVEs from CrowdStrike Spotlight

  • Findings updated in the last 7 days

  • CVSS score, severity, description, remediation guidance, references, and proof artifacts

  • All Spotlight vulnerability vectors supported by CrowdStrike, not just network-reachable findings

Hosts → Asset Correlation

PGP also reads CrowdStrike host data so it can:

  • Correlate Spotlight findings to Guard assets using CrowdStrike agent IDs

  • Use hostname and local IP data for asset mapping

  • Skip devices missing required correlation fields such as hostname or local IP


Troubleshooting

IssueCauseFix

Spotlight validation fails

Missing Vulnerabilities: Read scope

Add the scope to the API client

Spotlight connects but findings do not appear

Findings may be closed, older than 7 days, or not correlated to a valid host

Confirm the vulnerabilities are open, recently updated, and tied to a host with valid hostname and local IP data

Findings are missing asset context

Hosts: Read is missing or host data could not be mapped

Add Hosts: Read and verify device data exists in Falcon


Need Help?

If you run into issues during setup, contact support@praetorian.com.