Integrations / Security & monitoring
Screenata + CrowdStrikeHow do you turn CrowdStrike into SOC 2, ISO 27001, and HIPAA evidence?
Quick answer
CrowdStrike does the protecting. SOC 2 CC6.8, HIPAA 164.308(a)(5)(ii)(B), and ISO 27001 A.8.7 then ask you to prove the endpoint protection program around it operates, which is a different question from whether you bought the license. Having CrowdStrike is not the control. The control is the enforced configuration, such as the Falcon sensor deployed on every device in the asset register and prevention policies actually enforcing, plus the record that the configuration held across the whole audit period. Screenata runs 6 native checks against that configuration on a schedule and turns each result into signed evidence mapped to the control it satisfies.
Screenata connects to CrowdStrike read-only and runs 6 native checks against your Falcon environment: sensor coverage across your fleet and the prevention policies applied to it. Each finding becomes a signed, timestamped evidence artifact mapped to SOC 2, HIPAA, and ISO 27001 controls through a shared control catalog.
6 native checks · read-only · signed evidence
What it proves
CrowdStrike evidence, mapped to controls.
Whether the endpoints in your fleet actually run the Falcon sensor, so protection coverage matches the asset register.
The coverage gap report auditors ask for: every device your policy says is protected, shown protected.
The prevention policy configuration applied to sensor groups, verified against your endpoint security policy.
Configuration snapshot showing the protections in force on the scan date, not just that an agent is installed.
Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.
Compliance checks
What Screenata checks on CrowdStrike, and why each matters.
Sensor Coverage
Verifies the Falcon sensor is deployed across the endpoint fleet. Uncovered devices have no malware prevention or threat detection, and an auditor checks that endpoint protection coverage matches the asset register.
Prevention Policy Active
Confirms at least one prevention policy is enabled and enforced. An installed sensor with no active policy blocks nothing, and an auditor verifies the malware protections your endpoint policy names are in force.
Response Policy Active
Checks that a Real Time Response policy is configured for incident handling. Without it responders cannot contain a compromised host, and an auditor looks for the ability to act on a detection, not just record it.
Unresolved Critical Detections
Verifies no critical detections remain unresolved. Open criticals mean active threats are unremediated, and an auditor checks that detections are triaged and closed within your response timelines.
Sensor Update Policy Configured
Confirms an active sensor update policy keeps agents current. Stale sensors miss new detection logic and leave gaps, and an auditor verifies endpoint tooling is maintained on a defined schedule.
Spotlight Vulnerability Management
Verifies Spotlight is enabled for continuous vulnerability assessment and the open backlog stays within threshold. Without it, endpoint vulnerabilities go untracked, and an auditor checks that host-level weaknesses are identified and worked down.
Drawn from Screenata’s CrowdStrike check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.
How it connects
Read-only, revocable, yours.
Read-only by construction
OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.
Signed findings
SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.
Mapped to controls
Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.
What access does Screenata need to CrowdStrike?
Read-scoped API credentials that you create in the Falcon console. Screenata uses them for scheduled scans and never receives write access. You can revoke them at any time.
Does Screenata replace CrowdStrike?
No. CrowdStrike does the protecting; Screenata proves it. The integration turns sensor coverage and prevention policy state into signed compliance evidence mapped to the malware controls in SOC 2, HIPAA, and ISO 27001.
What happens when a CrowdStrike check fails?
Vera opens a ticket describing the gap, such as endpoints missing sensor coverage, and re-verifies after a human resolves it. Nothing in your environment is changed by Screenata; the connection is read-only by construction.
What are the steps to implement SOC 2 with CrowdStrike?
First, create read-scoped API credentials in the Falcon console and connect them. Second, let the first scan run so the baseline shows the real sensor and policy state across the fleet. Third, fix what fails: close the sensor coverage gaps so every device in the asset register runs the Falcon sensor, make sure at least one prevention policy is enabled and enforcing rather than sitting in detect-only, configure a Real Time Response policy so responders can contain a host, clear the unresolved critical detections, set a sensor update policy so agents stay current, and enable Spotlight so endpoint vulnerabilities are tracked. Fourth, leave the scheduled scans running so passing results accumulate as signed evidence across the observation window, which for a Type 2 report is usually three to twelve months. Fifth, hand the evidence package to an independent auditor. The audit is a separate engagement with a licensed CPA firm, which issues the report; Screenata prepares and holds the evidence it asks for.
What evidence do auditors ask for about endpoint protection?
Three things. That protection is deployed across every device in the asset register, which is where the common finding lands: the fleet count and the sensor count do not match, and the difference is a set of unprotected machines nobody was tracking. That prevention policies are actually enforcing rather than running in detect-only mode, since a sensor that only watches blocks nothing. And that detections were triaged and closed inside your response timelines, with the open criticals accounted for rather than left sitting in the console.
Do auditors accept evidence Screenata collects from CrowdStrike?
Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.