Skip to main content
{ Reporting and Compliance / Endpoint Security }

CrowdStrike Falcon Posture Report

Delivers a weekly report on Falcon sensor coverage, policy and exclusion changes, and anything in the tenant that needs attention, from failing automations to license use.

What this agent does

This read-only agent checks the health of a CrowdStrike Falcon tenant every week. It summarizes how many hosts are fully protected and which are stale, degraded, or missing a core policy. It lists policy, exclusion, and rule changes since last week, and Fusion workflows or scheduled reports that failed. It flags anything that needs an admin, such as a failing integration or module use close to the subscription's limits.

The challenge

Falcon only protects hosts where the sensor is current, healthy, and covered by the right policies. Sensors stop checking in, a prevention policy loses its assignment, and an exclusion added for one application weakens protection across a host group. Automations and integrations fail without anyone noticing. Admins find these gaps after an incident, not before.

The solution

The agent checks sensors, policies, exclusions, automations, and subscription use in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check sensors

    Count protected hosts, and find stale, degraded, or unprovisioned sensors and hosts missing a core policy.

  2. 02

    Check controls

    Compare policies, exclusions, and custom rules with last week, and flag anything that weakens protection.

  3. 03

    Check the tenant

    Check Fusion workflows, scheduled reports, API clients, and module use against the subscription.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# CrowdStrike Falcon Posture Report

## Measurable outcomes

Every week, the admin knows which hosts Falcon is not fully protecting, what changed in the tenant, and what needs action before it matters. Track protected and unprotected hosts and open action items on every run.

## Procedure

Once a week, check every host in the Falcon tenant. Count the hosts that are fully protected, and list the ones whose sensor has not checked in for 7 days, runs in reduced functionality mode, never finished provisioning, or lacks an applied prevention, sensor update, or content update policy, unless I set other values. Compare policies, host groups, exclusions, and custom IOA rules with last week's, and call out any change that weakens protection, with who made it. List Fusion workflows and scheduled reports that failed or missed their schedule this week. Check each API client and integration, and flag any that are failing. Compare module and host use with the subscription, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine. Replace hostnames and user names with stable pseudonyms in the report.

## Requirements

It needs read-only Falcon API access to hosts, policies, host groups, exclusions, custom IOA rules, workflows, scheduled reports, API clients, integrations, and subscription details, and nothing more. It never changes sensors, policies, exclusions, or Falcon configuration.