Crowdstrike

Use CLEAR within Crowdstrike

Overview

Use CLEAR within CrowdStrike Falcon to add verified human identity to your security operations.

CrowdStrike Falcon knows the device. It knows the account. It does not know the human. CLEAR verifies the human.

The integration delivers two use cases. Each one solves a different problem, serves a different workflow, and works on its own.

  • Charlotte SOAR Workflows. Falcon detects an identity threat. A workflow initiates a CLEAR verification. Your Security Operations Center (SOC) acts on the result.
  • Falcon Next-Gen SIEM. CLEAR verification session data flows into Falcon Next-Gen SIEM, where your analysts correlate it with the rest of their security telemetry.

Both use cases are instant on. Both install from a CrowdStrike catalog. Neither requires custom development, new infrastructure, or new software on the endpoint.

Each use case is documented in full below.


Charlotte SOAR Workflows

What SOAR Means

SOAR stands for Security Orchestration, Automation, and Response.

Charlotte SOAR is the automation engine inside CrowdStrike Falcon. The CLEAR workflow is prebuilt and available in the CrowdStrike catalog. Your team enables it. No code is required.

Every Charlotte SOAR workflow has three parts.

  • A trigger. The event that starts the workflow, such as a new high-severity identity detection.
  • Conditions. The tests the workflow applies to the event, such as whether the account belongs to a person rather than a service.
  • Actions. What the workflow does, such as send a message, call an external service, disable an account, or contain a device.

CLEAR verification is an action within that workflow.

The Problem

When Falcon raises a suspicious login, an analyst has to decide one thing: is this the real employee, or an attacker holding their credentials?

Today that answer comes from a phone call, a message to a manager, and a wait. The risk stays open while the analyst works. Often the alert closes without a firm answer, because a firm answer is not available.

How This Use Case Solves It

Charlotte SOAR Workflows turn that open question into a verified answer. The workflow asks the person directly. The person takes a selfie. The result returns in seconds.

Your team gains three things.

  • A firm answer on the alert. A pass is strong evidence of the real person. A failure is a strong signal.
  • Analyst time back. Most identity alerts are the real employee. The employee now proves it, without an investigation.
  • A response action that did not exist before. Falcon could already contain a device or disable an account. It could not confirm a human.

A stolen password transfers to an attacker. A face does not.

How It Works

Initiating a Verification

When CrowdStrike Falcon raises a high-severity identity detection, a Charlotte SOAR workflow initiates a CLEAR verification session for the associated user.

The verification session is delivered to the user through a channel your organization already uses, such as Slack, Microsoft Teams, or email. The message is white labeled with your logo and your details, so the request comes from the user's employer.

The Verification Experience

CLEAR automatically determines the appropriate verification experience based on whether a CLEAR User ID already exists for the user.

  • New Users complete a full identity verification and are matched to their user record.
  • Returning Users with an existing CLEAR User ID are routed through the Known User Key Flow, allowing them to complete verification in seconds using a selfie.

For the user, the experience is a selfie that takes seconds. No help desk call. No investigation.

Outcomes and Signals

The verification result is returned to CrowdStrike and surfaced to your security team. Every outcome produces a signal, including no response at all.

  • The user verifies and passes. The team has proof of the person and can clear the alert with confidence.
  • The user verifies and fails. The team receives a warning.
  • The user does not respond. The team receives a warning.

The team can then proceed with its standard response, including containing the device, revoking application access, disabling the account, or forcing re-authentication.

Use Cases

Prove the person before your team acts on an alert.

  • Identity Threat Response
  • Suspicious Login Verification
  • Account Takeover Prevention
  • Privileged Access Verification
  • Credential Theft Response
  • Alert Triage and False Positive Reduction

Works With

  • CrowdStrike Falcon
  • CrowdStrike Falcon Identity Threat Protection
  • Charlotte SOAR

CLEAR Responsibilities

Identity Verification

Identity verification requirements are determined by the settings configured within each project. To review the verification settings enabled for a specific project, navigate to the CLEAR Console.

CLEAR maintains a baseline identity assurance standard that requires verification across the following components at a minimum:

  • Biometric Verification
  • Document Verification
  • Source Validation

Projects may also be configured with additional verification controls to increase the level of identity assurance based on business or regulatory requirements.

User Profile Matching

In addition to verifying a user's identity, CLEAR assists with matching verified users to the user records you maintain within your systems. We refer to this process as User Profile Matching.

User Profile Matching is a critical component of the identity lifecycle. It helps ensure not only that a user is who they claim to be, but also that they are correctly associated with the corresponding user record in your environment.

Once a match has been established, CLEAR and CrowdStrike work together to map and store the CLEAR User ID against the user profile. This persistent identifier enables streamlined verification experiences for returning users while maintaining a high level of identity assurance.

Known User Key Flow

When a user interacts with CLEAR for the first time within your environment, they complete a full identity verification. As part of this process, CLEAR facilitates User Profile Matching and establishes a persistent association between the verified user and their corresponding user record by storing a CLEAR User ID.

Once this interoperable identifier has been established, future verification sessions can leverage the Known User Key Flow. In these experiences, users may only need to submit a selfie while CLEAR continues to perform identity proofing and security validation behind the scenes.

This enables returning users to complete verification in seconds while maintaining a high level of security.

CrowdStrike Responsibilities

Threat Detection

CrowdStrike Falcon monitors endpoints and user accounts, and raises the identity detections that initiate verification.

Detection-Initiated Verification

Charlotte SOAR initiates CLEAR verification sessions whenever a detection meets the criteria your team enables.

Session Delivery

CrowdStrike delivers verification links through the channel your organization already uses, such as Slack, Microsoft Teams, or email, using the contact information associated with the user's record.

Intelligent Routing

CrowdStrike determines whether a user should be routed through a full identity verification flow or a Known User Key Flow based on the presence of a stored CLEAR User ID.

User Profile Management

CrowdStrike stores and maintains the CLEAR User ID required to support future Known User Key Flows, and maps each verification result back to the detection that initiated it.

Verification Results

Once verification has been completed, CrowdStrike surfaces the outcome directly to your security team, allowing the response to proceed with a higher level of identity assurance.


Falcon Next-Gen SIEM

What SIEM Means

SIEM stands for Security Information and Event Management.

A SIEM is a single searchable store for an organization's security data. Evidence of an attack is spread across many systems, and no single system holds the full story. A SIEM brings the pieces together in one place.

A SIEM does six things.

  • Collects. Data arrives from many systems.
  • Normalizes. Each source format becomes one common format.
  • Stores. Data remains available for months or years.
  • Correlates. Events from different systems join together.
  • Alerts. Saved searches run on a schedule and raise alerts.
  • Supports investigation. An analyst searches the history to understand what happened.

Falcon Next-Gen SIEM is the CrowdStrike SIEM. Endpoint and identity data from the Falcon sensor is already there, so CLEAR data joins a populated data set rather than an empty one.

The Problem

Your organization already verifies its people at many moments, including onboarding, password resets, account recovery, factor resets, and sensitive profile changes.

That record of verified human activity lives outside your Security Operations Center. Analysts cannot correlate who verified, when, where, and how often against the rest of their security telemetry. The most durable identity signal your organization holds is the one signal its security team cannot search.

How This Use Case Solves It

Falcon Next-Gen SIEM turns verification activity into security telemetry. Verification records join the endpoint, identity, and business system data your analysts already query.

Your team gains three things.

  • A new signal class. Verified human presence, rather than device state or credential state.
  • Stronger existing queries. Every verification record makes the data your analysts already search more useful.
  • Threats that require history. Account sharing, impossible travel, synthetic identities, and payroll fraud only become visible across time.

This use case does not gate any action. No user acts. It is invisible to employees.

How It Works

How CLEAR Data Arrives

CLEAR verification session data flows into Falcon Next-Gen SIEM on the schedule your team enables.

Your analysts then query verified identity activity next to the endpoint, identity, and business system data already in the platform.

What Each Session Contributes

  • Outcome. Whether the verification passed or failed, and why.
  • Timing. When the session started, when it completed, and how long it took.
  • Location. Country, region, and city for each attempt.
  • Device and network. Device, browser, operating system, and IP address.
  • Frequency. How often the user verifies, and how many attempts each session required.

Why the Pattern Matters

One session shows very little. A year of sessions shows a pattern. Your SOC then alerts on the break in the pattern.

Consider one employee across one year. They onboard in January. They reset a password in March. They recover a locked account in May. They change a payroll record in June. They reset an authentication factor in July. CLEAR verified them at each moment, and recorded the place, the device, the time, and the outcome. Five records establish the normal pattern for that person.

Patterns a Single Check Cannot Reveal

  • Account sharing. The same user verifies from several devices and locations within a day.
  • Impossible travel. The user verifies in two cities that are too far apart for the time between them.
  • Synthetic or borrowed identity. A brand new identity with no endpoint history and a recently created directory account.
  • Payroll fraud. An HR record change alongside a burst of verification attempts.
  • Credential theft. Repeated verification failures while the endpoint behaves normally.
  • Insider threat. Unusual work hours, combined with device switching, multiple locations, and verification timing patterns.

How Your SOC Works With the Data

Once verification data is in Falcon Next-Gen SIEM, your SOC team decides how to see it and where it goes.

  • Dashboards. View verification volume, success and failure rates, locations, and device patterns across your workforce in a live dashboard.
  • Visualizations. Chart verification activity over time, map where your people verify from, and compare a single user against the workforce baseline.
  • Investigation. Search a specific user's verification history during an investigation, next to their endpoint and identity activity.
  • Scheduled alerts. Run a saved query on a schedule and raise an alert when a pattern appears.
  • Your preferred SOC tools. Forward alerts and verification context to the tools your team already works in, including ticketing, case management, chat, and on-call systems.

Your team is not limited to viewing this data inside Falcon. Verification signals can travel to wherever your response process already lives.

Use Cases

Find the pattern across every verification.

  • Insider Threat Detection
  • Remote Worker Assurance
  • Account Sharing Detection
  • Impossible Travel Investigation
  • Payroll and HR Change Correlation
  • Compliance and Audit Workflows

Works With

  • CrowdStrike Falcon Next-Gen SIEM
  • CrowdStrike Falcon LogScale

CLEAR Responsibilities

Verification Session Data

CLEAR makes verification session data available for your Security Operations Center to ingest, correlate, and analyze.

Data Scope

The project configuration your team enables in the CLEAR Console determines which data is returned. Most security teams want the outcome, the timing, the location, the device, and the network address.

Example Queries and Dashboards

CLEAR supplies example correlation queries and dashboards, so your team does not begin from nothing.

CrowdStrike Responsibilities

Data Ingestion

Falcon Next-Gen SIEM retrieves CLEAR verification session data on the schedule your team enables, then indexes and stores it alongside your other sources.

Ingestion Scope

Your ingestion configuration determines which of the returned fields are stored. This works together with your CLEAR project configuration to control exactly what enters your environment.

Correlation and Alerting

Falcon Next-Gen SIEM supports the searches, dashboards, and scheduled alerts your team enables on top of the verification data.

Visualization and Downstream Delivery

Falcon Next-Gen SIEM presents verification activity in dashboards and visualizations for your SOC team, and forwards alerts and verification context to the SOC tools your team already works in.


How to Use

Each use case has its own configuration guide.

Please navigate to the CLEAR documentation to determine how to configure either use case. Select the tab for the use case you want to deploy.

  • Charlotte SOAR Workflows
  • Falcon Next-Gen SIEM

Each tab covers the prerequisites, the required CLEAR credentials, the setup steps, and the recommended configuration for that use case.

Neither use case requires custom development, new infrastructure, additional endpoint software, or a change to your identity provider.


Resources

CLEAR

  • CLEAR Console, to review and configure your project settings
  • CLEAR documentation at https://docs.clearme.com
  • Example correlation queries and dashboards, available from your CLEAR representative

Terminology

  • Establish Identity. The CLEAR first-time verification flow. The user scans a government issued document and takes a selfie.
  • Known User Key Flow. The CLEAR returning-user verification flow. The user takes a selfie only.
  • CLEAR User ID. The persistent CLEAR identifier associated with a verified user record.
  • User Profile Matching. The process CLEAR uses to match a verified user to the correct user record in your environment.
  • Verification Session. One CLEAR verification.
  • SOAR. Security Orchestration, Automation, and Response.
  • SIEM. Security Information and Event Management.
  • SOC. Security Operations Center. The team that monitors for attacks.

Other Platforms

CLEAR verification session data is available to any platform that can retrieve it on a schedule. The prebuilt workflow and connector are specific to CrowdStrike. The underlying capability is not. Contact your CLEAR representative to discuss your environment.



Did this page help you?