CrowdStrike Falcon CVE Leverage
Provides the Spotlight CVEs whose remediation removes the most risk across a CrowdStrike tenant.
What this agent does
This read-only agent finds the host vulnerabilities in CrowdStrike Spotlight that remove the most risk when remediated. It ranks CVEs by severity, CISA KEV status, and how many open findings each one has across the tenant. It then maps the top CVEs to the remediation campaigns that fix them.
The challenge
Spotlight reports vulnerabilities one host at a time. A large tenant holds millions of open Critical and High findings, and Spotlight has no view that groups them by CVE ranked by aggregate risk. Teams cannot see which fix closes the most findings, so remediation effort goes to whatever looks worst on one host instead.
The solution
The agent samples findings in bounded passes to find candidate CVEs. It counts the exact open findings for each candidate and ranks them by a transparent leverage score. It marks the ranking provisional, because the samples can leave out a CVE. It groups sampled findings into remediation campaigns to enable defenders to maximize their remediation efficiency.
Workflow
- 01
Find candidates and counts
Sample open findings from CISA KEV, recent Critical and High updates, and a rotating set of hosts. Count the open findings for each shortlisted CVE, including those on internet-exposed or high-criticality hosts.
- 02
Rank by leverage
Score each CVE by severity, KEV status, and finding counts, and mark the ranking provisional.
- 03
Map campaigns
Group sampled findings by the remediation that fixes them, and note developer context where Falcon has it.
- 04
Report
Publish the ranked queue with CVEs visible and hosts, paths, and remediation IDs pseudonymized.
Agent template
# CrowdStrike Falcon CVE Leverage
## Measurable outcomes
The ranked queue names the CVEs whose remediation closes the most risk-weighted open findings in the tenant. Each ranked CVE carries its exact open finding count at collection time. Track the count for each ranked CVE on every run. The counts fall as teams remediate.
## Procedure
Spotlight has no view that groups host findings by CVE, and reading every finding in a large tenant costs too much. Find candidate CVEs through bounded samples: open CISA KEV findings, the most recently updated Critical and High findings, and a rotating daily sample of hosts. For the strongest candidates, get the exact open finding count and the count on internet-exposed or high-criticality hosts. Score each CVE with this leverage heuristic, so a widespread High CVE can outrank a rare Critical one:
```text
score = severity_weight * open_occurrences
+ 8 * open_occurrences when CISA KEV
+ 2 * high_context_occurrences
```
Severity weights are Critical 8, High 4, Medium 2, Low 1, and Unknown 1. A high-context occurrence is an open finding on an internet-exposed host or on a host with Critical or High asset criticality, counted once. Break ties by open occurrences, then severity, then KEV status, then CVE ID. Call the ranking provisional, because a CVE outside the samples can be missed. Exclude suppressed findings from the scores and report their count separately. Group sampled findings into remediation campaigns by the fix that closes them. Record developer context where Falcon Discover has it, and keep developer-associated software at full weight in the score. Present campaign and context numbers as sample evidence, never as tenant-wide counts.
## Requirements
It needs read access to Falcon hosts and Spotlight vulnerabilities, and Assets: READ for Discover application data, and nothing more. Missing Discover access means developer context is not assessed, not that it is absent. It never patches hosts, closes or suppresses findings, runs Real Time Response, or changes Falcon configuration. Reports show CVEs and software names, with hosts, paths, and remediation IDs replaced by stable pseudonyms. A Spotlight finding shows vulnerable software is present, not that it runs or is reachable. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools