All integrations
CrowdStrike Spotlight logo
// Data Integration · Vulnerability Management

Cracken + CrowdStrike Spotlight

CrowdStrike Falcon Spotlight rates every vulnerability by what ExPRT.AI predicts attackers are likely to exploit somewhere in the world. Cracken replaces that prediction with evidence from your own hosts, reporting the ones it exploited.

Get started
// 01

Connecting CrowdStrike Spotlight

Connect with

The Falcon API Base URL for your cloud plus the Client ID and Client Secret of an API client granted Read on Vulnerabilities, Hosts and Host Groups, User Management, Prevention Policies, Device Control Policies, Response Policies and Sensor Update Policies.

Cadence

Syncs on a schedule — every 6 hours by default — and can be re-synced on demand via the Trigger Scan action.

Requires

CrowdStrike Exposure Management enabled, plus access to Falcon → API Clients and Keys with permission to create an API client.

// 02

What Cracken gets from CrowdStrike Spotlight

  • Vulnerability Findings with name, description, severity and state (new, active, re-opened, fixed)

  • cve[] identifiers with cvss_base_score, cvss_vector and cvss_version

  • The host the finding sits on as a device{} object with hostnames, ipv4s and tags[]

  • patchable and a solution string, plus first_seen, last_seen and state_updated_at

  • Spotlight's own grading kept beside Cracken's: vendor, vendor_id, vendor_severity and vendor_scan_id

  • In the Cybergraph: a Device node CONTAINS a Finding node, which CONTAINS a cve: Vulnerability node

// 03

What CrowdStrike Spotlight does not do

Nothing is written back to Falcon Spotlight beyond a request to re-sync. Cracken cannot close, remediate, suppress or re-rate a Spotlight vulnerability, and it never installs or runs a scanner of its own on those hosts.

// 04

How Cracken uses CrowdStrike Spotlight

  1. 01

    Connect CrowdStrike Spotlight

  2. 02

    Sync vulnerability findings

  3. 03

    Prove which are exploitable

  4. 04

    Confirm it connected

// 05

Frequently asked questions

How is the CrowdStrike Spotlight integration different from Cracken's CrowdStrike Falcon integration?

Spotlight supplies vulnerability findings Cracken syncs and validates by attacking hosts; the separate Falcon EDR integration supplies detection alerts pulled on demand, and connecting one does not connect the other.

Does Cracken change anything in CrowdStrike Falcon?

No; it reads findings through a Falcon API client you create and never alters Spotlight policies, suppresses findings, or writes to the Falcon console.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real CrowdStrike Spotlight context.

See how Cracken works what CrowdStrike Spotlight already knows into attack paths it proves end to end.