CrowdStrike Falcon Control Drift
Provides the Falcon policies, exclusions, rules, and automations that changed since a baseline the team approved.
What this agent does
This read-only agent detects changes to the security controls in CrowdStrike Falcon. It fingerprints each policy, host group, custom IOA rule group, exclusion, correlation rule, workflow, and scheduled report. It compares the fingerprints with a baseline the team approved. It then reports each control that was deleted, disabled, modified, or created.
The challenge
Falcon controls change through the console, the API, and integrations, often with no review. A new exclusion or a disabled prevention policy can remove protection from thousands of hosts. Nobody compares the result with what the team intended. Teams find unapproved changes only when a detection fails to fire.
The solution
The agent compares current controls only against a baseline that a person approved. It treats a control surface with no approved baseline as a candidate, never as drift. It ranks deleted and disabled controls above modified and created ones. It never approves a baseline itself, to enable defenders to catch unapproved control changes before a detection fails because of them.
Workflow
- 01
Fingerprint controls
Read each control surface and fingerprint each control, ignoring timestamps and editor metadata.
- 02
Compare with the baseline
Compare each surface with its approved baseline, and mark surfaces without one as candidates.
- 03
Rank drift
Rank deleted and disabled controls above modified and created ones.
- 04
Report
Publish the drift queue and the candidate surfaces with controls replaced by stable pseudonyms.
Agent template
# CrowdStrike Falcon Control Drift
## Measurable outcomes
Every Falcon control that differs from its approved baseline is in the drift queue with its change type. Every surface without an approved baseline is listed. Track the drift count for each change type on every run.
## Procedure
Read these Falcon control surfaces: host groups, prevention, sensor update, content update, device control, response, and firewall policies, custom IOA rule groups, IOA, machine learning, sensor visibility, and certificate exclusions, correlation rules, Fusion workflow definitions, and scheduled reports. Fingerprint each control from its configuration, and ignore timestamps and the identity of the last editor. Compare each surface with its approved baseline. A control in the baseline and absent now is deleted. A control that is new is created. A control with a changed fingerprint is disabled when it is now off, and modified otherwise. Rank deleted and disabled above modified and created. A surface with no approved baseline is a candidate, never drift. I approve a baseline for a named run and surface only after I review it. Never approve a baseline to clear drift.
## Requirements
It needs read access to each control surface, and nothing more. A surface that returns access denied is not assessed, not absent. It never changes Falcon configuration and never approves a baseline. Reports show the surface and change type, with controls replaced by stable pseudonyms. Related templates
-
CrowdStrike Falcon Posture Report
Delivers a weekly report on Falcon sensor coverage, policy and exclusion changes, and anything in the tenant that needs attention, from failing automations to license use.
Reporting and Compliance / Endpoint Security 1 tools -
CrowdStrike Falcon Sensor Remediation
Provides a ranked queue of Falcon sensors that are stale, degraded, unprovisioned, or missing a core policy.
Endpoint Security 1 tools -
SentinelOne Posture Report
Delivers a weekly report on SentinelOne agent coverage, what changed, and anything in the console that needs attention, from detect-only policies to license seats.
Reporting and Compliance / Endpoint Security 1 tools