CrowdStrike Falcon Permissions

Permissions to Fetch Assets

The following permissions are required to fetch specific asset types:

Permissions:
  • Assets:Read
API Permissions
ScopePermissionNotes
HostsRead
Host groupsRead
IOC ManagementRead
Prevention policiesRead
DetectionsRead
User ManagementRead
Sensor Update PoliciesRead
IndicatorsRead

Requires CrowdStrike Falcon Intelligence Add-on. Used to discover shadow SaaS applications.

VulnerabilitiesRead

Requires an active CrowdStrike Falcon Vulnerability subscription. May assist in discovering shadow SaaS applications.

Permissions for Advanced Settings

The following permissions are required to use specific Advanced Settings:

Advanced Setting Name

API Scope

Permission

Fetch users

User Management

Read

Enable vulnerability fetch (and all the settings listed in this section)

vulnerabilities:read

Read

Get Configuration Assessments for device
Enrich Configuration Assessments with Rule Name

Falcon Configuration Assessment:read

Read

Fetch installed patches from the following report

Scheduled Reports API

Read
Additional requirement: a Spotlight subscription

Setting Up Installed Patches Permissions

In Spotlight, follow these steps:

  1. Navigate to Scheduled Reporting > Vulnerability Management.

  2. Select Installed Patches.

  3. Include at least the Hostname in the report; add more filters as needed.

  4. Name the report (to use in the adapter's Advanced Configuration) and click Next.

  5. Schedule the report to run daily 2 hours before the start of the global fetch or custom adapter discovery time, then click Next.

  6. Ensure that the scheduled report can be read by the credentials used in the adapter configuration. Then, click Next.

  7. Skip the Sharing part and click Save.

  8. In Axonius, enable the Fetch installed patches from the following report advanced setting, and enter the name of the Installed Patches report to fetch.

Permissions for Enforcement Actions

The following permissions are required to run CrowdStrike Falcon Related Enforcement Actions:

ScopePermission
HostsWrite