Configure CrowdStrike Falcon Endpoint for Arctic Wolf Active Response
With the Active Response service, Arctic Wolf® can perform host-based response actions in your network using CrowdStrike Falcon® endpoint.
CrowdStrike Falcon supports these response actions:
- Contain a host/Remove from containment
For more information, see Response action descriptions.
These resources are required:
- A Falcon Administrator role for the CrowdStrike Falcon environment that you want Arctic Wolf to monitor.
- A CrowdStrike Falcon Enterprise license.
For more information about pricing, see CrowdStrike pricing.
These actions are required:
- If you are using Falcon Complete, read the terms of your CrowdStrike Falcon agreements to make sure that third-party containment actions are permitted.
- Define your containment policy with your CST.
- Contact your CST to validate the Active Response integration. Have a device or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.
Create the API client
Note: Do not reuse API credentials from the CrowdStrike Falcon EDR configuration. They have different permissions.