📢 Read the latest Release Notes to learn what's new on Hunters! 💡

CrowdStrike FileVantage

Prev Next

Overview

Table name: crowdstrike_filevantage_queries_changes

FileVantage is designed to track file changes, access patterns, and potential unauthorized data movement, which are critical for data loss prevention (DLP) and insider threat detection. This tool helps organizations manage and secure their sensitive data by leveraging CrowdStrike's powerful endpoint security platform.

Send data to Hunters

⚠️ Attention

The process below requires you to select the CrowdStrike API tile (and not CrowdStrike).

image.png

Step 1: Create an API client

Create a CrowdStrike API client with the FILEVANTAGE: read scope and permissions (as specified here).

Step 2: Create a data source on Hunters

Complete the process on the Hunters platform, and supply the following keys following this process:

  • Client ID
  • Client Secret
  • Cloud Endpoint - This should only contain the domain name, without the https:// prefix. For example: api.crowdstrike.com.