In this article, you will learn how to integrate CrowdStrike’s Falcon Insight, an endpoint protection platform (EPP), with Real-Time Coaching. Once the integration is complete, data from CrowdStrike will be available under the Coaching tab in your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in CrowdStrike
To set up the CrowdStrike integration, you'll first need to create an OAuth Client in your CrowdStrike admin console by following the steps below:
- Log in to your CrowdStrike Falcon admin console.
- From the sidebar menu, navigate to Support and resources > Resources and tools > API clients and keys. An API clients and keys window will display.
-
In the API clients and keys window, navigate to OAuth2 API clients > Create API client. A Create API client window will display.
-
To configure and create your API client, see the screenshot and list below:
- Client Name: Enter your preferred client name.
- Alerts Permissions: Select the check box to enable Read permissions for Alerts.
- Create: Select this button to create the new API client.
-
Locate the Client ID and Client Secret. Copy both items and save them somewhere you can easily access later. You will need both of these credentials to set up the integration in Real-Time Coaching.
-
Select the Base URL for your region using the table below:
Region Base URL US https://api.us-2.crowdstrike.com/ EU https://api.eu-1.crowdstrike.com/ All other regions https://api.crowdstrike.com
Set Up the Integration in Real-Time Coaching
To set up the CrowdStrike integration in Real-Time Coaching, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the CrowdStrike vendor tile and select Configure.
- From the Cloud API Endpoint drop-down menu, select the endpoint for your region from the following list:
- For the US region, select api.us-2.crowdstrike.com.
- For the EU region, select api.eu-1.crowdstrike.com.
- For any other region, select api.crowdstrike.com.
- In the Client ID and Client Secret fields, enter the Client ID and the Client Secret that you saved earlier.
- Select Authorize.
Map Your Users
After you’ve finished integrating CrowdStrike, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage CrowdStrike detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
To delete the CrowdStrike integration from Real-Time Coaching, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the CrowdStrike vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.


