diff --git a/docs/docs.json b/docs/docs.json
index 8832cd32..cade0279 100644
--- a/docs/docs.json
+++ b/docs/docs.json
@@ -629,6 +629,18 @@
"integrations/cortex-xsoar/reference"
]
},
+ {
+ "group": "CrowdStrike",
+ "pages": [
+ {
+ "group": "Falcon for IT",
+ "pages": [
+ "integrations/crowdstrike/falcon-for-it/configure",
+ "integrations/crowdstrike/falcon-for-it/use"
+ ]
+ }
+ ]
+ },
{
"group": "Google SecOps",
"pages": [
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/add-filters.png b/docs/images/integrations/crowdstrike/falcon-for-it/add-filters.png
new file mode 100644
index 00000000..ace60646
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/add-filters.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/app-catalog.png b/docs/images/integrations/crowdstrike/falcon-for-it/app-catalog.png
new file mode 100644
index 00000000..7d84ec86
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/app-catalog.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/event-logs-queries.png b/docs/images/integrations/crowdstrike/falcon-for-it/event-logs-queries.png
new file mode 100644
index 00000000..254b2709
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/event-logs-queries.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/event-logs-upload.png b/docs/images/integrations/crowdstrike/falcon-for-it/event-logs-upload.png
new file mode 100644
index 00000000..fb5bbe06
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/event-logs-upload.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/execute-now.png b/docs/images/integrations/crowdstrike/falcon-for-it/execute-now.png
new file mode 100644
index 00000000..59d4cf0e
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/execute-now.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/file-ingest.png b/docs/images/integrations/crowdstrike/falcon-for-it/file-ingest.png
new file mode 100644
index 00000000..63eb114a
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/file-ingest.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/installation-success.png b/docs/images/integrations/crowdstrike/falcon-for-it/installation-success.png
new file mode 100644
index 00000000..595d6f62
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/installation-success.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/query-input.png b/docs/images/integrations/crowdstrike/falcon-for-it/query-input.png
new file mode 100644
index 00000000..66535cae
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/query-input.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/run-live-query.png b/docs/images/integrations/crowdstrike/falcon-for-it/run-live-query.png
new file mode 100644
index 00000000..6275d5d1
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/run-live-query.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/schedule-query.png b/docs/images/integrations/crowdstrike/falcon-for-it/schedule-query.png
new file mode 100644
index 00000000..d723c56e
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/schedule-query.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/validate-and-save.png b/docs/images/integrations/crowdstrike/falcon-for-it/validate-and-save.png
new file mode 100644
index 00000000..705d4e97
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/validate-and-save.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/verify-telemetry.png b/docs/images/integrations/crowdstrike/falcon-for-it/verify-telemetry.png
new file mode 100644
index 00000000..3cb0ed09
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/verify-telemetry.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/view-workflow-run.png b/docs/images/integrations/crowdstrike/falcon-for-it/view-workflow-run.png
new file mode 100644
index 00000000..4cf200e0
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/view-workflow-run.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/workflow-action-menu.png b/docs/images/integrations/crowdstrike/falcon-for-it/workflow-action-menu.png
new file mode 100644
index 00000000..211c1130
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/workflow-action-menu.png differ
diff --git a/docs/images/integrations/crowdstrike/falcon-for-it/workflows.png b/docs/images/integrations/crowdstrike/falcon-for-it/workflows.png
new file mode 100644
index 00000000..dd3cd9bf
Binary files /dev/null and b/docs/images/integrations/crowdstrike/falcon-for-it/workflows.png differ
diff --git a/docs/integrations/crowdstrike/falcon-for-it/configure.mdx b/docs/integrations/crowdstrike/falcon-for-it/configure.mdx
new file mode 100644
index 00000000..b79f69dd
--- /dev/null
+++ b/docs/integrations/crowdstrike/falcon-for-it/configure.mdx
@@ -0,0 +1,313 @@
+---
+title: Integrate BloodHound with Falcon for IT
+description: Learn how to install and configure the CrowdStrike Falcon for IT integration for BloodHound Enterprise.
+sidebarTitle: Install and configure
+---
+
+
+
+The BloodHound Enterprise CrowdStrike Falcon Foundry Application is a native, serverless integration that automatically collects sessions, local groups, user rights assignment (LSA), and registry key data from CrowdStrike Falcon agents installed on endpoint hosts. The application then sends that data to your BloodHound Enterprise tenant.
+
+This guide shows you how to install the Foundry application, configure the BloodHound Enterprise connection, set up the required queries, and confirm that telemetry reaches Falcon Next-Gen SIEM.
+
+Use this integration to:
+
+- Install the app from CrowdStrike Marketplace and configure the BloodHound Enterprise connection
+- Scope Falcon for IT (FFIT) query collection to specific Falcon host groups
+- Route endpoint telemetry into Falcon Next-Gen SIEM for ingestion into BloodHound Enterprise
+
+After configuration is complete, the application handles the following actions automatically:
+
+| Automated behavior | Description |
+| --- | --- |
+| **Provision and schedule FFIT queries** | Deploys the required query set and runs it on the configured schedule for the selected Falcon host groups |
+| **Route collected data to LogScale** | Sends the collected endpoint telemetry into Falcon Next-Gen SIEM (LogScale) for processing |
+| **Run serverless ingestion** | Uses Foundry Functions to fetch, transform, and ingest data into BloodHound Enterprise |
+| **Track host reporting state** | Uses a Daily Status Table in Foundry Collections to track which hosts reported during the current cycle |
+| **Retry incomplete collection** | Retries and reconciles incomplete runs to improve host coverage |
+
+## Prerequisites
+
+Before you begin, ensure that you have the following:
+
+| Requirement | Details |
+| --- | --- |
+| **CrowdStrike Falcon access** | A CrowdStrike Falcon account with permission to manage FFIT live asset queries, install Foundry apps, execute Fusion SOAR workflows, and access Next-Gen SIEM Event Search |
+| **Windows device** | At least one Windows device with the [CrowdStrike Falcon sensor installed](https://www.crowdstrike.com/en-us/resources/videos/how-to-install-falcon-sensor/) and visible in the Falcon host management console |
+| **Host grouping** | Add the target Windows devices to an existing or newly created Host Group. This group defines the scope of RTR script execution. |
+| **Group ID** | Locate and save your Host Group ID. You need this parameter during Managed Application configuration. |
+| **BloodHound Enterprise access** | A BloodHound Enterprise tenant URL and a BloodHound Enterprise [non-personal API key/ID pair](/integrations/bloodhound-api/working-with-api#create-a-non-personal-api-key%2Fid-pair) with the **Auditor** role |
+
+## Install the application
+
+Install the CrowdStrike Foundry application and configure credentials for BloodHound Enterprise.
+
+
+
+ 1. Log in to CrowdStrike Falcon with an account that has permission to install Foundry applications.
+
+ 1. Go to **Foundry** > **App catalog**.
+
+
+
+
+
+ 1. Select the **SpecterOps BloodHound Enterprise - Data Collector** application.
+
+ 1. Click **Install Now**.
+
+ 1. After installation completes, click **Open App**.
+
+
+ Configure the connection values that the Foundry application uses to validate credentials and upload data to BloodHound Enterprise.
+
+ | Field | Description |
+ | --- | --- |
+ | **BloodHound Enterprise Domain** | The URL of your BloodHound Enterprise tenant |
+ | **Token ID** | The API token ID used to authenticate requests |
+ | **Token Key** | The API token key used to sign and authorize requests |
+
+
+ This integration supports a maximum of one BloodHound Enterprise instance.
+
+
+
+
+
+
+
+ 1. Click **Validate & Save Credentials**.
+
+ The application stores the validated BloodHound Enterprise API credentials in the Foundry Secret Store.
+
+ 1. Confirm that validation succeeds before you continue.
+
+
+
+ After the credentials are saved successfully, click **Next** to open the **Installation Success** page.
+
+ Use this page to review the integration status, data collection schedules, and verification steps.
+
+
+
+
+
+
+ After installation and configuration are complete, the BloodHound Enterprise NG SIEM Workflow runs automatically every hour.
+
+ The workflow retrieves CrowdStrike endpoint event logs from Next-Gen SIEM, transforms them to the BloodHound Enterprise schema, and uploads the data to your BloodHound Enterprise tenant.
+
+
+
+
+## Configure queries
+
+Before the Foundry workflow can upload data to BloodHound Enterprise, the required Windows endpoint telemetry must exist in Falcon Next-Gen SIEM.
+
+This section shows you how to save and schedule the required queries in the CrowdStrike Falcon console so your target Windows hosts continuously send data to Next-Gen SIEM.
+
+### Required queries
+
+Use the following four queries when you configure collection in CrowdStrike Falcon. Copy, save, and schedule each query separately.
+
+
+
+ ```sql
+ SELECT
+ 'bloodhound_enterprise_windows_endpoint_osquery_result' AS event_type,
+ 'session' AS data_type,
+ logon_id,
+ user,
+ logon_domain,
+ logon_type,
+ logon_time
+ FROM logon_sessions;
+ ```
+
+
+
+ ```sql
+ SELECT
+ 'bloodhound_enterprise_windows_endpoint_osquery_result' AS event_type,
+ 'local_groups' AS data_type,
+ g.groupname,
+ u.username
+ FROM groups g
+ JOIN user_groups ug ON g.gid = ug.gid
+ JOIN users u ON ug.uid = u.uid;
+ ```
+
+
+
+ ```sql
+ SELECT
+ 'bloodhound_enterprise_windows_endpoint_osquery_result' AS event_type,
+ 'user_rights_assignment' AS data_type,
+ g.groupname,
+ u.username
+ FROM groups g
+ JOIN user_groups ug ON g.gid = ug.gid
+ JOIN users u ON ug.uid = u.uid
+ WHERE g.groupname = 'Remote Desktop Users'
+ OR g.groupname = 'Administrators';
+ ```
+
+
+
+ ```sql
+ SELECT
+ 'bloodhound_enterprise_windows_endpoint_osquery_result' AS event_type,
+ 'registry_key' AS data_type,
+ name,
+ type,
+ data
+ FROM registry
+ WHERE path IN (
+ 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\ClientAllowedNTLMServers',
+ 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\NtlmMinClientSec',
+ 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\NtlmMinServerSec',
+ 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\RestrictReceivingNTLMTraffic',
+ 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\RestrictSendingNTLMTraffic'
+ );
+ ```
+
+
+
+
+
+ 1. Log in to CrowdStrike Falcon.
+
+ 1. Click **IT Automation** > **Run live query**.
+
+
+
+
+
+
+
+ 1. Open a new tab and click **Add Filters**.
+
+
+
+
+
+ 1. Set the filter key to **Host Group**.
+
+ 1. Select the Falcon host group that contains the Windows devices you want to query.
+
+
+
+ You must configure each query individually.
+
+ 1. In the [Required queries](/integrations/crowdstrike/falcon-for-it/configure#required-queries) tabs above, select a query.
+
+ 1. Copy the full query text.
+
+ 1. Paste the query into the CrowdStrike query input.
+
+
+
+
+
+
+
+ 1. Click the ellipsis (three-dot) menu.
+
+ 1. Click **Save As**.
+
+ 1. Enter a name for the query and click **Save**.
+
+
+
+ 1. Open the dropdownmenu next to **Run** and click **Schedule**.
+
+ 1. Select the **Recurring** option.
+
+ 1. Set the frequency unit to **Minutes** and the interval to `60`.
+
+ 1. Click **Schedule**.
+
+
+
+
+
+
+
+ Return to the [Required queries](/integrations/crowdstrike/falcon-for-it/configure#required-queries) tabs and repeat the copy, paste, save, and schedule steps for all required queries.
+
+
+
+ 1. Confirm that the target hosts are online.
+
+ 1. Run the saved queries individually.
+
+ 1. Review the results pane to confirm that each query returns data.
+
+
+
+## Verify query results
+
+Confirm that CrowdStrike routes the query results into Falcon Next-Gen SIEM before you run the BloodHound Enterprise workflow.
+
+
+
+ 1. Log in to CrowdStrike Falcon.
+
+ 1. Go to **Next-Gen SIEM** > **Log management** > **Event Search**.
+
+
+
+
+
+
+
+ Apply a custom filter with the following values:
+
+ | Field | Value |
+ | --- | --- |
+ | **Field** | `result.event_type` |
+ | **Operator** | `is equal to` |
+ | **Value** | `bloodhound_enterprise_windows_endpoint_osquery_result` |
+
+
+
+ Confirm that matching events appear in the search results.
+
+ These events show that the required endpoint telemetry is available for the Foundry workflow to retrieve and upload to BloodHound Enterprise in real time.
+
+
+
+
+
+
+
+## Next steps
+
+After verifying the query results, you can [run the workflow and verify ingestion](/integrations/crowdstrike/falcon-for-it/use) in BloodHound Enterprise.
diff --git a/docs/integrations/crowdstrike/falcon-for-it/use.mdx b/docs/integrations/crowdstrike/falcon-for-it/use.mdx
new file mode 100644
index 00000000..b1ff6325
--- /dev/null
+++ b/docs/integrations/crowdstrike/falcon-for-it/use.mdx
@@ -0,0 +1,163 @@
+---
+title: Use Falcon for IT with BloodHound Enterprise
+description: Learn how to run the CrowdStrike Falcon for IT workflow, review telemetry, and verify ingestion in BloodHound Enterprise.
+sidebarTitle: Run and verify
+---
+
+
+
+After you complete the [installation and configuration](/integrations/crowdstrike/falcon-for-it/configure), the CrowdStrike Foundry workflow can retrieve endpoint telemetry from Falcon Next-Gen SIEM, transform it to the BloodHound Enterprise schema, and upload it to your BloodHound Enterprise tenant.
+
+This page shows you how to run the workflow, review the available dashboard views, and verify a successful upload.
+
+The integration uses Foundry Functions and Falcon Fusion to automate BloodHound Enterprise data collection and ingestion.
+
+| Workflow stage | Description |
+| --- | --- |
+| **Fetch telemetry** | Retrieves new endpoint telemetry from Falcon Next-Gen SIEM |
+| **Transform data** | Converts the collected data to the BloodHound Enterprise schema before upload |
+| **Track host coverage** | Uses a Daily Status Table to track which hosts reported during the current cycle |
+| **Retry incomplete work** | Reconciles incomplete collection runs to improve host coverage |
+
+## Run the workflow manually
+
+The workflow runs automatically on an hourly schedule, but you can also run it manually after installation and configuration to confirm that data reaches BloodHound Enterprise successfully.
+
+
+
+ 1. Log in to CrowdStrike Falcon.
+
+ 1. Go to **Fusion SOAR** > **Workflows**.
+
+
+
+
+
+ 1. Locate the **BloodHound Enterprise NG SIEM Workflow**.
+
+
+
+ 1. Open the workflow action menu and click **Execute Workflow**.
+
+
+
+
+
+ 1. In the confirmation dialog, click **Execute now**.
+
+
+
+
+
+
+
+ 1. When CrowdStrike displays the workflow execution notification, click **View**.
+
+
+
+
+
+ 1. Review the real-time execution results for the run.
+
+
+ Record the reported job ID. You can use it to verify data ingestion in BloodHound Enterprise.
+
+
+
+
+## Review the dashboard
+
+The CrowdStrike dashboard provides visibility into the data that the integration collects and uploads to BloodHound Enterprise.
+
+To navigate to the dashboard in CrowdStrike Falcon, go to **Next-Gen SIEM** > **Dashboard**.
+
+The dashboard displays the following visualizations to monitor host activity and data ingestion:
+
+| Visualization | Description |
+| --- | --- |
+| **Event Count - Data Types** | Displays a single-value metric highlighting the volume of specific BloodHound data types filtered by recent detection IDs |
+| **Top Active Hosts** | Displays a bar chart of the top five hostnames that generated the most OS query events during the selected time range |
+| **Active Interactive Logon Sessions Tracking** | Displays a pie chart of interactive user logon sessions grouped by hostname and logon domain |
+| **Job Execution Audit Trail** | Displays a table of upload events, including job IDs, processed event counts, and upload status |
+
+
+ The dashboard includes a global time filter that lets you adjust the reporting range across all visualizations.
+
+
+## Verify upload events
+
+The application writes an audit event to Falcon Next-Gen SIEM after it uploads data successfully to BloodHound Enterprise.
+
+After the workflow completes successfully, confirm the upload in both Falcon Next-Gen SIEM and BloodHound Enterprise.
+
+
+
+ 1. Log in to CrowdStrike Falcon.
+
+ 1. Go to **Next-Gen SIEM** > **Log management** > **Event Search**.
+
+
+
+
+
+
+
+ Apply a custom filter with the following values:
+
+ | Field | Value |
+ | --- | --- |
+ | **Field** | `event_type` |
+ | **Operator** | `is equal to` |
+ | **Value** | `bloodhound_enterprise_data_collector_upload` |
+
+
+
+ 1. Confirm that a matching event appears for the workflow run.
+
+ 1. Review the event details for the job ID, computer count, Next-Gen SIEM event counts, and checkpoint details.
+
+ 1. Record the job ID to verify data ingestion in BloodHound Enterprise.
+
+
+
+
+
+
+
+ 1. Log in to your BloodHound Enterprise tenant.
+
+ 1. Go to **Administration** > **Data Collection** > **File Ingest**.
+
+
+
+ Locate the latest ingestion entry and verify it against the job ID from the Falcon Next-Gen SIEM audit event.
+
+ - Confirm that the upload start time matches the workflow execution time.
+ - Confirm that the status of the job is **Complete**.
+
+
+
+
+
+
diff --git a/docs/integrations/overview.mdx b/docs/integrations/overview.mdx
index f078b25a..58cde5c5 100644
--- a/docs/integrations/overview.mdx
+++ b/docs/integrations/overview.mdx
@@ -60,6 +60,21 @@ The following integrations are officially supported by SpecterOps.
| **Integration instructions** | Configure the Axonius adapter for BloodHound |
+
+ The BloodHound Enterprise CrowdStrike Falcon Foundry Application is a native, serverless integration that automatically collects Sessions, Local Groups, User Rights Assignment (LSA), and Registry Keys data from CrowdStrike Falcon agents installed on endpoint hosts.
+
+ The app then ingests that data into BloodHound Enterprise (BHE). This integration enables security teams to enrich their Active Directory and Azure Attack Path analysis with real-time endpoint telemetry gathered directly from their existing CrowdStrike Falcon deployment.
+
+ | | |
+ | --- | --- |
+ | **Supported actions** | - Install directly from the CrowdStrike Marketplace with a guided setup wizard.
- Securely configure BHE API credentials via the Foundry Secret Store.
- Automate provisioning and scheduling of Falcon for IT (FFIT) queries for Sessions, Local Groups, LSA, and Registry data.
- Scope collection to specific Falcon Host Groups.
- Route collected data into Falcon Next-Gen SIEM (LogScale) in real time.
- Use Foundry Functions to fetch, transform, and ingest data into BHE.
- Track host reporting state via a Daily Status Table in Foundry Collections / KV Store.
- Retry and reconcile incomplete collection runs to ensure 100% host data coverage.
|
+ | **Common use cases** | - Enrich BHE attack path analysis with live endpoint session and privilege data.
- Ensure continuous, hands-off data collection across the entire endpoint fleet.
- Automatically track and reconcile which hosts reported data within a 24-hour cycle.
- Extend BHE coverage to hosts as soon as they come online, with no manual intervention.
- Reduce manual configuration effort with pre-built, auto-provisioned FFIT query workflows.
- Maintain data freshness in BHE without relying on manual data pipelines or external storage.
|
+ | **Integration instructions** | Configure the CrowdStrike Falcon for IT integration |
+
+