|
| 1 | + |
| 2 | +# CrowdStrike Falcon Receiver |
| 3 | + |
| 4 | +This directory contains the Axoflow CrowdStrike Falcon receiver which helps collecting alerts from the CrowdStrike Falcon platform. |
| 5 | + |
| 6 | +## Quickstart |
| 7 | + |
| 8 | +### Authentication with ClientID / ClientSecret |
| 9 | + |
| 10 | +Make sure the required environment variables are set before running the receiver. |
| 11 | + |
| 12 | +```bash |
| 13 | +UUID_FULL=$(uuidgen 2>/dev/null || cat /proc/sys/kernel/random/uuid 2>/dev/null || python3 -c "import uuid; print(uuid.uuid4())") |
| 14 | +AXOCLOUDCONNECTOR_DEVICE_ID=$(echo "$UUID_FULL" | cut -d'-' -f1) |
| 15 | + |
| 16 | +```bash |
| 17 | +docker run \ |
| 18 | + --rm \ |
| 19 | + -v "${STORAGE_DIRECTORY}":"${STORAGE_DIRECTORY}" \ |
| 20 | + -e CROWDSTRIKE_CLIENT_ID="${CROWDSTRIKE_CLIENT_ID}" \ |
| 21 | + -e CROWDSTRIKE_CLIENT_SECRET="${CROWDSTRIKE_CLIENT_SECRET}" \ |
| 22 | + -e CROWDSTRIKE_CLOUD="${CROWDSTRIKE_CLOUD}" \ |
| 23 | + -e AXOROUTER_ENDPOINT="${AXOROUTER_ENDPOINT}" \ |
| 24 | + -e STORAGE_DIRECTORY="${STORAGE_DIRECTORY}" \ |
| 25 | + -e AXOCLOUDCONNECTOR_DEVICE_ID="${AXOCLOUDCONNECTOR_DEVICE_ID}" \ |
| 26 | + ghcr.io/axoflow/axocloudconnectors:latest |
| 27 | +``` |
| 28 | + |
| 29 | +### Authentication with Access Token |
| 30 | + |
| 31 | +Make sure the required environment variables are set before running the receiver. |
| 32 | + |
| 33 | +```bash |
| 34 | +UUID_FULL=$(uuidgen 2>/dev/null || cat /proc/sys/kernel/random/uuid 2>/dev/null || python3 -c "import uuid; print(uuid.uuid4())") |
| 35 | +AXOCLOUDCONNECTOR_DEVICE_ID=$(echo "$UUID_FULL" | cut -d'-' -f1) |
| 36 | +
|
| 37 | +```bash |
| 38 | +docker run \ |
| 39 | + --rm \ |
| 40 | + -v "${STORAGE_DIRECTORY}":"${STORAGE_DIRECTORY}" \ |
| 41 | + -e CROWDSTRIKE_ACCESS_TOKEN="${CROWDSTRIKE_ACCESS_TOKEN}" \ |
| 42 | + -e CROWDSTRIKE_CLOUD="${CROWDSTRIKE_CLOUD}" \ |
| 43 | + -e AXOROUTER_ENDPOINT="${AXOROUTER_ENDPOINT}" \ |
| 44 | + -e STORAGE_DIRECTORY="${STORAGE_DIRECTORY}" \ |
| 45 | + -e AXOCLOUDCONNECTOR_DEVICE_ID="${AXOCLOUDCONNECTOR_DEVICE_ID}" \ |
| 46 | + ghcr.io/axoflow/axocloudconnectors:latest |
| 47 | +``` |
| 48 | + |
| 49 | + |
| 50 | +## Deploy with Helm-chart (ClientID / ClientSecret) |
| 51 | + |
| 52 | +```bash |
| 53 | +make minikube-cluster |
| 54 | +make docker-build |
| 55 | +make minikube-load-image |
| 56 | + |
| 57 | +kubectl create namespace cloudconnectors |
| 58 | +kubectl create secret generic crowdstrike-falcon \ |
| 59 | + --from-literal=client-id="<YOUR-CROWDSTRIKE-CLIENT-ID>" \ |
| 60 | + --from-literal=client-secret="<YOUR-CROWDSTRIKE-CLIENT-SECRET>" \ |
| 61 | + --from-literal=cloud="<YOUR-CROWDSTRIKE-CLOUD>" \ |
| 62 | + --namespace cloudconnectors \ |
| 63 | + --dry-run=client -o yaml | kubectl apply -f - |
| 64 | + |
| 65 | +UUID_FULL=$(uuidgen 2>/dev/null || cat /proc/sys/kernel/random/uuid 2>/dev/null || python3 -c "import uuid; print(uuid.uuid4())") |
| 66 | +AXOCLOUDCONNECTOR_DEVICE_ID=$(echo "$UUID_FULL" | cut -d'-' -f1) |
| 67 | + |
| 68 | +helm upgrade --install --wait --namespace cloudconnectors cloudconnectors ./charts/cloudconnectors \ |
| 69 | + --set image.repository="axocloudconnectors" \ |
| 70 | + --set image.tag="dev" \ |
| 71 | + --set 'env[0].name=AXOROUTER_ENDPOINT' \ |
| 72 | + --set 'env[0].value=axorouter.axoflow-local.svc.cluster.local:4317' \ |
| 73 | + --set 'env[1].name=AXOCLOUDCONNECTOR_DEVICE_ID' \ |
| 74 | + --set "env[1].value=${AXOCLOUDCONNECTOR_DEVICE_ID}" \ |
| 75 | + --set 'env[2].name=CROWDSTRIKE_CLIENT_ID' \ |
| 76 | + --set 'env[2].valueFrom.secretKeyRef.name=crowdstrike-falcon' \ |
| 77 | + --set 'env[2].valueFrom.secretKeyRef.key=client-id' \ |
| 78 | + --set 'env[3].name=CROWDSTRIKE_CLIENT_SECRET' \ |
| 79 | + --set 'env[3].valueFrom.secretKeyRef.name=crowdstrike-falcon' \ |
| 80 | + --set 'env[3].valueFrom.secretKeyRef.key=client-secret' \ |
| 81 | + --set 'env[4].name=CROWDSTRIKE_CLOUD' \ |
| 82 | + --set 'env[4].valueFrom.secretKeyRef.name=crowdstrike-falcon' \ |
| 83 | + --set 'env[4].valueFrom.secretKeyRef.key=cloud' |
| 84 | +``` |
| 85 | + |
| 86 | +## Deploy with Helm-chart (Access Token) |
| 87 | + |
| 88 | +```bash |
| 89 | +kubectl create secret generic crowdstrike-falcon \ |
| 90 | + --from-literal=access-token="<YOUR-CROWDSTRIKE-ACCESS-TOKEN>" \ |
| 91 | + --from-literal=cloud="<YOUR-CROWDSTRIKE-CLOUD>" \ |
| 92 | + --namespace cloudconnectors \ |
| 93 | + --dry-run=client -o yaml | kubectl apply -f - |
| 94 | + |
| 95 | +UUID_FULL=$(uuidgen 2>/dev/null || cat /proc/sys/kernel/random/uuid 2>/dev/null || python3 -c "import uuid; print(uuid.uuid4())") |
| 96 | +AXOCLOUDCONNECTOR_DEVICE_ID=$(echo "$UUID_FULL" | cut -d'-' -f1) |
| 97 | + |
| 98 | +helm upgrade --install --wait --namespace cloudconnectors cloudconnectors ./charts/cloudconnectors \ |
| 99 | + --set image.repository="axocloudconnectors" \ |
| 100 | + --set image.tag="dev" \ |
| 101 | + --set 'env[0].name=AXOROUTER_ENDPOINT' \ |
| 102 | + --set 'env[0].value=axorouter.axoflow-local.svc.cluster.local:4317' \ |
| 103 | + --set 'env[1].name=AXOCLOUDCONNECTOR_DEVICE_ID' \ |
| 104 | + --set "env[1].value=${AXOCLOUDCONNECTOR_DEVICE_ID}" \ |
| 105 | + --set 'env[2].name=CROWDSTRIKE_ACCESS_TOKEN' \ |
| 106 | + --set 'env[2].valueFrom.secretKeyRef.name=crowdstrike-falcon' \ |
| 107 | + --set 'env[2].valueFrom.secretKeyRef.key=access-token' \ |
| 108 | + --set 'env[3].name=CROWDSTRIKE_CLOUD' \ |
| 109 | + --set 'env[3].valueFrom.secretKeyRef.name=crowdstrike-falcon' \ |
| 110 | + --set 'env[3].valueFrom.secretKeyRef.key=cloud' |
| 111 | +``` |
| 112 | + |
0 commit comments