{
  "name": "ti_crowdstrike",
  "title": "CrowdStrike Falcon Intelligence",
  "version": "2.9.1",
  "release": "ga",
  "description": "Collect logs from CrowdStrike Falcon Intelligence with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_crowdstrike/ti_crowdstrike-2.9.1.zip",
  "path": "/package/ti_crowdstrike/2.9.1",
  "icons": [
    {
      "src": "/img/crowdstrike_falcon_intelligence-logo.svg",
      "path": "/package/ti_crowdstrike/2.9.1/img/crowdstrike_falcon_intelligence-logo.svg",
      "title": "Sample logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.18.0 || ^9.0.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_crowdstrike/ti_crowdstrike-2.9.1.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_crowdstrike/2.9.1/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/ti_crowdstrike-ioc-dashboard.png",
      "path": "/package/ti_crowdstrike/2.9.1/img/ti_crowdstrike-ioc-dashboard.png",
      "title": "IOC Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ti_crowdstrike-intel-dashboard.png",
      "path": "/package/ti_crowdstrike/2.9.1/img/ti_crowdstrike-intel-dashboard.png",
      "title": "Intel Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_crowdstrike/2.9.1/LICENSE.txt",
    "/package/ti_crowdstrike/2.9.1/changelog.yml",
    "/package/ti_crowdstrike/2.9.1/manifest.yml",
    "/package/ti_crowdstrike/2.9.1/validation.yml",
    "/package/ti_crowdstrike/2.9.1/docs/README.md",
    "/package/ti_crowdstrike/2.9.1/img/crowdstrike_falcon_intelligence-logo.svg",
    "/package/ti_crowdstrike/2.9.1/img/ti_crowdstrike-intel-dashboard.png",
    "/package/ti_crowdstrike/2.9.1/img/ti_crowdstrike-ioc-dashboard.png",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/lifecycle.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/manifest.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/sample_event.json",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/lifecycle.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/manifest.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/sample_event.json",
    "/package/ti_crowdstrike/2.9.1/kibana/dashboard/ti_crowdstrike-37a9ef30-9993-11ee-9b44-fd906664033c.json",
    "/package/ti_crowdstrike/2.9.1/kibana/dashboard/ti_crowdstrike-b81b5020-9e64-11ee-9777-1d1f44d25bb5.json",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/fields/base-fields.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/fields/beats.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/fields/ecs.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/fields/fields.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/fields/is-ioc-transform-source-true.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/fields/base-fields.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/fields/beats.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/fields/ecs.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/fields/fields.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/fields/is-ioc-transform-source-true.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/manifest.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/transform.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/agent/stream/cel.yml.hbs",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/elasticsearch/ilm/default_policy.json",
    "/package/ti_crowdstrike/2.9.1/data_stream/intel/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/agent/stream/cel.yml.hbs",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/elasticsearch/ilm/default_policy.json",
    "/package/ti_crowdstrike/2.9.1/data_stream/ioc/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/fields/agent.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/fields/base-fields.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/fields/beats.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/fields/ecs.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/fields/fields.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_intel/fields/is-ioc-transform-source-false.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/fields/agent.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/fields/base-fields.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/fields/beats.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/fields/ecs.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/fields/fields.yml",
    "/package/ti_crowdstrike/2.9.1/elasticsearch/transform/latest_ioc/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_crowdstrike",
      "title": "CrowdStrike Falcon Intelligence logs",
      "description": "Collect CrowdStrike Falcon Intelligence logs.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "client_id",
              "type": "text",
              "title": "Client ID",
              "description": "Client ID for the CrowdStrike Falcon Intelligence.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "client_secret",
              "type": "password",
              "title": "Client Secret",
              "description": "Client Secret for the CrowdStrike Falcon Intelligence.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the CrowdStrike Falcon Intelligence API. Defaults to https://api.crowdstrike.com",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.crowdstrike.com"
            },
            {
              "name": "token_url",
              "type": "text",
              "title": "Token URL",
              "description": "Token URL of CrowdStrike Falcon Intelligence.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://api.crowdstrike.com/oauth2/token"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect CrowdStrike Falcon Intelligence logs via API",
          "description": "Collecting CrowdStrike Falcon Intelligence logs via API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_crowdstrike.intel",
      "ilm_policy": "logs-ti_crowdstrike.intel-default_policy",
      "title": "Collect Intel logs from CrowdStrike Falcon Intelligence.",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the Intel logs from CrowdStrike Falcon Intelligence. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the CrowdStrike Falcon Intelligence API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the CrowdStrike Falcon Intelligence API. Default is 10000. It must be between 1 - 10000.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 10000
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "Enforces all IOCs to expire after this duration. This setting is required to avoid \"orphaned\" IOCs that never expire. Specify [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units)) using only days, hours, or minutes (e.g., 10d), avoiding mixed time units.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ti_crowdstrike-intel"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve ti_crowdstrike.intet fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Intel logs",
          "description": "Collect Intel logs from CrowdStrike Falcon Intelligence.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_crowdstrike",
      "path": "intel"
    },
    {
      "type": "logs",
      "dataset": "ti_crowdstrike.ioc",
      "ilm_policy": "logs-ti_crowdstrike.ioc-default_policy",
      "title": "Collect IOC logs from CrowdStrike Falcon Intelligence.",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the IOC logs from CrowdStrike Falcon Intelligence. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the CrowdStrike Falcon Intelligence API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the CrowdStrike Falcon Intelligence API. Default is 2000. It must be between 1 - 2000.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 2000
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "Enforces all IOCs to expire after this duration. This setting is required to avoid \"orphaned\" IOCs that never expire. Specify [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units)) using only days, hours, or minutes (e.g., 10d), avoiding mixed time units.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ti_crowdstrike-ioc"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve ti_crowdstrike.ioc fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "IOC logs",
          "description": "Collect IOC logs from CrowdStrike Falcon Intelligence.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_crowdstrike",
      "path": "ioc"
    }
  ]
}
