CrowdStrike Flight Control
Connect a parent CrowdStrike CID so Guard finds its child CIDs and imports hosts and vulnerabilities from each.
Overview
The CrowdStrike Flight Control integration is designed for MSSPs and multi-tenant CrowdStrike environments.
It lets the Praetorian Guard Platform (PGP) connect once using a parent or master CID, discover child tenants automatically, and create scoped integrations for each child tenant. PGP then pulls host and vulnerability data from each child tenant and correlates it with Guard exposure data.
Use this integration when you manage multiple CrowdStrike child CIDs from a parent tenant.
Prerequisites
Before you begin, make sure you have:
- Access to the CrowdStrike Falcon console for the parent CID
- Permission to create API clients in CrowdStrike
- A parent tenant licensed for Flight Control
- Your CrowdStrike cloud region
Create a CrowdStrike API Client
Sign in to the CrowdStrike Falcon console for the parent CID.
Navigate to Support & Resources → API Clients & Keys.
Click Create API Client.
Grant the following read-only scopes based on the modules you want enabled:
If you enable Spotlight, you must also grant Hosts: Read so PGP can map findings to the correct assets.
After saving the client, copy the following values and store them securely:
- Client ID
- Client Secret
- Cloud Region from your Falcon console URL
Supported regions:
us-1—api.crowdstrike.comus-2—api.us-2.crowdstrike.comeu-1—api.eu-1.crowdstrike.comus-gov-1—api.laggar.gcw.crowdstrike.com
You will not be able to retrieve the client secret again later.
Configure the Integration in PGP
- In PGP, go to Integrations.
- Select Managed Detection & Response → CrowdStrike Flight Control (MSSP).
- Click Connect.
- Enter the parent CID's Client ID, Client Secret, and Cloud Region.
- Enable the modules you want applied across child tenants. Hosts (Endpoint Inventory) and Spotlight (Vulnerabilities) are enabled by default.
- Click Connect.
PGP validates the credentials before saving the integration by authenticating and listing the parent's child CIDs. It does not check the scopes for each module at this step. If authentication fails, PGP shows CrowdStrike rejected the supplied Flight Control client ID or client secret.
What Happens After Connection
After Flight Control is connected, PGP automatically:
- Discovers child CIDs using the Flight Control API
- Creates a scoped CrowdStrike integration for each child tenant
- Uses the parent credentials with
member_cidscoping for child-tenant access - Applies the module configuration you selected to each child integration
You do not need to create a separate API client for every child tenant.
What Data Is Synced
Hosts → PGP Assets
For enabled child tenants, PGP syncs:
- Device hostname and local IP address
- Devices seen in the last 7 days
- Assets that can be mapped successfully from CrowdStrike host data
Spotlight → PGP Risks
For enabled child tenants, PGP ingests:
- Open CVEs from Spotlight that match at least one of these filters:
- CrowdStrike ExPRT rating of High or Critical, with a network attack vector
- Listed in the CISA Known Exploited Vulnerabilities catalog, with any attack vector
- On Guard's list of CVEs used in attack-chain correlation
- Findings updated since the last successful Spotlight sync, looking back at least 1 day and at most 5 days (5 days on the first sync)
- CVSS score, severity, description, remediation guidance, references, and proof artifacts
- Findings correlated to assets using CrowdStrike agent IDs
Shield
The Shield module does not import any data. Enabling it has no effect on what PGP syncs.
Troubleshooting
Need Help?
If you run into issues during setup, contact support@praetorian.com.
Still need help? Ask the team