CrowdStrike
Enriching OT and IT asset visibility in Nozomi Vantage with endpoint detection, software inventory and vulnerability data from CrowdStrike Falcon.

CrowdStrike Falcon is a cloud-native endpoint detection and response platform delivering real-time threat detection, investigation, and response across managed endpoints. By integrating CrowdStrike Falcon with Nozomi Vantage, security teams gain a consolidated view of managed assets across IT and OT environments — importing endpoint detection, software inventory and vulnerability data directly into Vantage. This enriches the asset registry with authoritative data from the CrowdStrike management plane, accelerating incident investigation, reducing blind spots in critical infrastructure environments and enabling analysts to correlate edr xdr telemetry with OT network observations without switching consoles.

Features
Importer Data Types
Asset Details Enrichment and Create New in Vantage
Asset Software Inventory Import
Asset CPE and CVE Import
Joint Use Cases
Correlating CrowdStrike signals with OT network alerts
Closing asset inventory gaps across IT and OT
Prioritizing vulnerability remediation on critical OT assets
Integration Prerequesites
- Active Nozomi Vantage tenant with the connector-configuration role assigned to the administering account
- CrowdStrike Falcon tenant with API client credentials scoped for Hosts, Software Inventory and Spotlight read access
- CrowdStrike Falcon license tier and feature set that includes software-inventory collection
- CrowdStrike Falcon module or license that produces per-asset CVE findings enabled in the source tenant
- Consistent hostname, IP or MAC addressing between CrowdStrike Falcon-recorded assets and Vantage-observed assets to enable accurate asset correlation and deduplication
