Skip to main content
The CrowdStrike Falcon integration uses Real Time Response (RTR) to extend Forge across your existing endpoint fleet. It imports Falcon hosts, connects them to Forge devices and people, and supports setup, health, repair, inventory, and remediation from Forge. Falcon-backed devices receive agentless Forge coverage through the CrowdStrike agent already deployed in your environment. Forge verifies the resulting endpoint state and keeps a complete audit trail for every operation.

Capabilities

Before you start

Choose an online pilot host in the correct Falcon cloud and record its AID, platform, and owner. Confirm your Falcon subscription and host policy permit RTR before scheduling local collection.

Create credentials and permissions

Create an OAuth2 API client in Falcon with these scopes: Falcon assigns the admin-command and put-file APIs to Real time response (admin): Write. Forge therefore needs that scope even when the command being executed is a read-only inventory probe. Forge validates command content and scope separately before dispatch. See CrowdStrike’s Real Time Response Admin API reference for the upstream scope requirements.

Connection

Setup

  1. In Falcon, open Support and resources → API clients and keys.
  2. Create an OAuth2 API client and grant all six required scopes above.
  3. Open Integrations → CrowdStrike Falcon in Forge. Enter the Falcon API URL, client ID and secret, and optional Member CID.
  4. Select Test connection. Forge validates authentication, host access, RTR session access, and RTR admin-command access independently.
  5. Import targetable hosts and explicitly bind them to the correct person. Conflicts and blocked hosts remain visible instead of creating ambiguous Forge device identities.
  6. Allow the scheduled inventory to run, or start an inventory or deployment operation and monitor progress for each device in Forge.
Import enables scheduled inventory that can upload and execute a Forge helper through RTR. Approve that execution on your pilot hosts before importing them. Open Host import to review the exact Falcon IDs and owner assignments. See Endpoint operations for the shared import and inventory workflow. For a configuration-only edit, leave both Client ID and Client secret empty to retain the saved credential. To rotate credentials, enter both values and run Test connection again. Do not grant additional Falcon scopes to resolve a failed test without first reviewing the failed capability. A successful OAuth exchange does not prove host, RTR, alert, or event-stream access.

Host model

Operations

Endpoint inventory runs can target one imported device, a bounded device list, or all imported CrowdStrike devices in the organization. Each intentional run uses a client-generated idempotency key, and each device reports its own queued, dispatched, running, succeeded, failed, timed_out, partially_succeeded, or canceled state. Forge keeps provider references, execution evidence, accepted and rejected inventory counts, and the resulting canonical inventory batch. Full-fleet runs automatically continue through the complete Falcon host list. Forge shows progress and per-device results throughout the run, so large environments can be operated with the same workflow as a single endpoint. Forge reconciles Falcon host identity with directory and endpoint sources such as Microsoft Entra ID, Intune, Jamf Pro, and Forge for devices. Matching records appear as one device in Forge while retaining their source history.

Validate coverage and troubleshoot

Use one online pilot host with a confirmed Falcon AID and person assignment. Check host discovery, a completed inventory operation, and the resulting Forge records separately. MCP and skill discovery depends on supported local profile paths and readable configuration; a Falcon software list alone is insufficient. A denied RTR capability needs its corresponding Falcon scope and endpoint policy. An offline host needs connectivity before an execution canary can pass. Review the recorded per-device failure before expanding permissions or retrying. Rotate the API client secret in both Falcon and Forge, then test the same pilot before revoking the previous credential.

Platform coverage

This is the Forge operation surface, not a promise that every provider tenant or endpoint grants execution. Each action still requires a compatible published helper, provider permissions, an online agent, and the target/profile evidence required by that collector. Provider inventory can include platforms without Forge remote-operation support.