Falcon is CrowdStrike's cloud-delivered cybersecurity platform, designed to prevent breaches across all attack vectors (malware, exploits, credential theft, etc.). It combines next-gen antivirus, endpoint detection and response (EDR), managed threat hunting, and IT hygiene in a single lightweight agent.
This connector queries the Falcon API to produce indicators (numerical values tracked over time on a perimeter) for a general module plus 4 optional modules: Discovery (assets), Identity Threat Protection (ITP), Mobile, and Spotlight (vulnerabilities). It can also sync ITP alerts and Spotlight vulnerabilities as gaps (security flaws recorded in a Tenacy register).
This article is for Tenacy Admins in charge of configuring connectors.
This connector collects the following information:
General module: IOCs, whitelisted IOCs, detections, incidents, Crowdscore.
ITP module: ITP perimeter alerts, at-risk users, total users, users with weak passwords.
Mobile module: mobile alerts.
Discovery module: unsupported, managed, and unmanaged endpoints.
Spotlight module: opened and closed vulnerabilities, vulnerable assets, remediations, monitored assets.
ITP alerts and Spotlight vulnerabilities as gaps in Tenacy.
Add and configure the connector
To add this connector, go to Catalog > Connectors > Crowdstrike Falcon > Add connector.
After adding it, you must configure:
Operating perimeter: the perimeter that operates and prescribes asset protection rules. Indicators will be attached here by default.
Frequency: how often the Falcon API is queried and indicators are updated (daily, weekly, monthly, half-yearly, or yearly).
Once the connector is created, configuration continues with the Falcon API credentials:
Falcon API URL: your Falcon subscription's regional API URL, usually in the form api.*.crowdstrike.com. Default: api.eu-1.crowdstrike.com.
API Client ID: the ID of the API key generated in the Falcon management console.
API Client Secret: the value shown when the API key is generated. If lost or compromised, it must be reset in Falcon and then updated in Tenacy, since this invalidates the previous value.
History: the period, in days, over which recent results are retrieved. It's recommended to match this to the connector's frequency for consistent period-over-period comparisons.
💡 To generate an API key, go to the Falcon console (Falcon admin rights required): falcon.crowdstrike.com/api-clients-and-keys. The following permissions must be granted at minimum, read-only unless stated otherwise: Alerts, Detections, Hosts, Assets, Host groups, Identity Protection Detections, Identity Protection Enforcement, and Identity Protection Entities (Read), Identity Protection GraphQL (Write, no read option exists), Incidents, IOC Management, and Vulnerabilities.
⚠️ An IP restriction may be in place on your Falcon platform. If so, contact your Tenacy CSM, who will provide the IP address to whitelist in Crowdstrike.
For the Discovery module, you can send indicators to several perimeters based on your Falcon host-groups (or sites). In the Consumer perimeter dropdown, enter host-group or site values separated by commas, using at least two sites or groups for each desired perimeter.
⚠️ A managed endpoint is always attached to a Crowdstrike host-group. For Tenacy to calculate the number of managed endpoints, you must enter at least one host-group value in this perimeter mapping.
For the ITP and Spotlight modules, once activated, you must also configure:
Gap register: the register where detected alerts (ITP) or vulnerabilities (Spotlight) are synced.
Attachment perimeter: the perimeter the register above is attached to.
Maximum number of gaps to sync: the limit of gaps synced per connector run (100 by default if left blank, maximum value: 100).
⚠️ If the Gap register field is left blank for the ITP or Spotlight modules, no remediation will be synced to Tenacy.
Run your first test
Once the connector is properly configured, test the integration by running an initial execution.
Go to ⚙️ > Connectors > click on the Crowdstrike Falcon connector > Run now:
💡 Feel free to contact Tenacy support if you have any questions regarding this.
Expected result
Once the test runs successfully, the connector automatically queries the Falcon API according to the chosen frequency. Indicators for the activated modules start updating, and ITP alerts as well as Spotlight vulnerabilities progressively appear as gaps in the configured registers.
FAQ
What happens if I don't set a host-group for the Discovery module?
The module keeps working, but the managed endpoints indicator can't be calculated correctly, since a managed endpoint is always attached to a host-group on the Crowdstrike side.
Can I split my Discovery indicators across several Tenacy perimeters?
Yes. By entering several host-groups or sites separated by commas in the Consumer perimeter dropdown, you can send differentiated values to several perimeters.
What happens if I don't set a gap register for ITP or Spotlight?
Detected alerts or vulnerabilities are then not synced as gaps in Tenacy. Only the indicators keep being updated.
What should I do if API access is blocked by an IP restriction?
Contact your Tenacy CSM: they'll provide the IP address to whitelist on your Falcon platform.
What is the History field for?
It sets the period, in days, over which the connector looks for recent results on each run. Matching it to the connector's frequency avoids gaps or duplicates between two consecutive readings.




