CrowdStrike Falcon Detection Telemetry QA
Provides a quality report on Falcon alert data, covering missing triage fields, missing ATT&CK mappings, and malformed ATT&CK IDs.
What this agent does
This read-only agent checks the quality of the alert data in CrowdStrike Falcon. It finds alerts that lack the fields analysts need to triage them. It finds alerts with no MITRE ATT&CK mapping or a malformed ATT&CK ID.
The challenge
Detection coverage reports depend on alert data that nobody checks. Third-party and custom detections often arrive without an ATT&CK mapping, or with an ID in the wrong format. Some alerts lack a severity, status, or timestamp. A coverage map built on that data shows false gaps and leaves out real ones.
The solution
The agent measures each quality problem separately across the alerts in the window. It separates missing mappings from malformed IDs, because each one has a different fix. It shows third-party alert volume as context for normalization work. It never reads an unobserved technique as missing coverage, to enable defenders to trust their ATT&CK coverage evidence.
Workflow
- 01
Read alerts
Read the Falcon alerts from the last 90 days.
- 02
Check fields
Count alerts that lack a product, type, severity, status, or created time.
- 03
Check ATT&CK
Count alerts with no tactic or technique, and alerts whose tactic or technique ID is malformed.
- 04
Report
Publish the counts by product, with third-party volume as context and no raw alert content.
Agent template
# CrowdStrike Falcon Detection Telemetry QA
## Measurable outcomes
Every quality problem in the Falcon alert data has a count: missing triage fields, missing ATT&CK mappings, and malformed ATT&CK IDs. Track each count on every run. The counts fall as teams fix connectors and mappings.
## Procedure
Read the Falcon alerts from the last 90 days, unless I set another window. Count the alerts that lack a product, type, severity, status, or created time, per field. Count the alerts with no tactic or no technique as unmapped. Count a tactic ID that is not in the form TA0000 and a technique ID that is not in the form T0000 or T0000.000 as malformed. Report missing and malformed mappings separately. Break the counts down by product, and show third-party alert volume as normalization context. An ATT&CK technique with no alerts is not observed. It is not proof that a detection is absent.
## Requirements
It needs read access to Falcon alerts, and nothing more. It never changes connectors, detections, or Falcon content. Reports show aggregate counts by product, with raw alert content, detection names, hosts, users, and alert IDs left out. Related templates
-
Datadog Detection Posture Report
Delivers a weekly report on Datadog Cloud SIEM log ingestion gaps, detection rules that are disabled, erroring, or blind, and anything in the organization that needs an admin, from Security Filter exclusions to silent Agents.
Reporting and Compliance / Security Operations 1 tools -
Datadog Detection Tuning
Finds the Datadog Cloud SIEM detection rules that produce the most noise, reads each one against the signals it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Elastic Security Detection Posture Report
Delivers a weekly report on Elastic Security data stream gaps, detection rules that are failing, warning, or blind, and anything in the deployment that needs an admin, from offline Elastic Agents to lifecycle errors.
Reporting and Compliance / Security Operations 1 tools -
Elastic Security Detection Tuning
Finds the Elastic Security detection rules that produce the most noise, reads each one against the alerts it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools