Skip to main content
The CrowdStrike Falcon integration uses Real Time Response (RTR) to extend Forge across your existing endpoint fleet. It imports Falcon hosts, connects them to Forge devices and people, and supports setup, health, repair, inventory, and remediation from Forge. Falcon-backed devices receive agentless Forge coverage through the CrowdStrike agent already deployed in your environment. Forge verifies the resulting endpoint state and keeps a complete audit trail for every operation.

Capabilities

Permissions

Create an OAuth2 API client in Falcon with these scopes: Falcon assigns the admin-command and put-file APIs to Real time response (admin): Write. Forge therefore needs that scope even when the command being executed is a read-only inventory probe. Forge validates command content and scope separately before dispatch.

Connection

Setup

  1. In Falcon, open Support and resources → API clients and keys.
  2. Create an OAuth2 API client and grant all six required scopes above.
  3. Open Settings → Integrations → CrowdStrike Falcon in Forge. Enter the Falcon cloud URL, client ID and secret, and optional Member CID.
  4. Select Test connection. Forge validates authentication, host access, RTR session access, and RTR admin-command access independently.
  5. Import targetable hosts and explicitly bind them to the correct person. Conflicts and blocked hosts remain visible instead of creating ambiguous Forge device identities.
  6. Allow the scheduled inventory to run, or start an inventory or deployment operation and monitor progress for each device in Forge.
Do not grant additional Falcon scopes to resolve a failed test without first reviewing the failed capability. A successful OAuth exchange does not prove host, RTR, alert, or event-stream access.

Host model

Operations

Endpoint inventory runs can target one imported device, a bounded device list, or all imported CrowdStrike devices in the organization. Each intentional run uses a client-generated idempotency key, and each device reports its own queued, dispatched, running, succeeded, failed, timed_out, partially_succeeded, or canceled state. Forge keeps provider references, execution evidence, accepted and rejected inventory counts, and the resulting canonical inventory batch. Full-fleet runs automatically continue through the complete Falcon host list. Forge shows progress and per-device results throughout the run, so large environments can be operated with the same workflow as a single endpoint. Forge reconciles Falcon host identity with directory and endpoint sources such as Microsoft Entra ID, Intune, Jamf Pro, and Forge for devices. Matching records appear as one device in Forge while retaining their source history.