-
Notifications
You must be signed in to change notification settings - Fork 1.5k
[SAASINT-4634] DDS: CrowdStrike FDR Integration v1.0.0 #21242
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 8 commits
fa8d4bd
082f497
c4cca39
c7b6a27
1f8d63f
66020f3
c2c269b
05a91cc
cd19be2
e466dc1
3823183
39138c5
e709330
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
# CHANGELOG - crowdstrike_fdr | ||
|
||
## 1.0.0 / 2025-09-03 | ||
|
||
***Added***: | ||
|
||
* Initial Release |
Original file line number | Diff line number | Diff line change | ||||
---|---|---|---|---|---|---|
@@ -0,0 +1,121 @@ | ||||||
# CrowdStrike FDR | ||||||
|
||||||
## Overview | ||||||
|
||||||
[CrowdStrike Falcon Data Replicator (FDR)][1] is a high-fidelity data export solution that enables organizations to securely stream raw endpoint telemetry in near real time. FDR delivers detailed event data through a data feed in JSON format using Amazon Web Services Simple Storage Service (Amazon S3) and Amazon Simple Queue Service (Amazon SQS). | ||||||
|
||||||
Integrate CrowdStrike FDR with Datadog to gain insights into Authentication & Identity, Account & Privilege Changes, Execution Monitoring & Threat Detection, File & Malware Activity and Network Behavior events using pre-built dashboard visualizations. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search, and detailed insights. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. | ||||||
|
||||||
## Setup | ||||||
|
||||||
### Set up data replication from CrowdStrike FDR to a customer-owned S3 bucket | ||||||
|
||||||
#### Configure CrowdStrike FDR Feed | ||||||
|
#### Configure CrowdStrike FDR Feed | |
#### Configure the CrowdStrike FDR feed |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
6. Select **Customize your FDR feed** in **How do you want to create this feed?** option. | |
6. Select **Customize your FDR feed** in the **How do you want to create this feed?** option. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
Uh oh!
There was an error while loading. Please reload this page.