Skip to main content
{ Endpoint Security }

CrowdStrike Falcon Sensor Remediation

Provides a ranked queue of Falcon sensors that are stale, degraded, unprovisioned, or missing a core policy.

What this agent does

This read-only agent finds the CrowdStrike Falcon sensors that do not protect their hosts as expected. It checks every Falcon host for staleness, reduced functionality mode, provisioning status, and core policy assignment. It then ranks the unhealthy sensors into one remediation queue.

The challenge

A host with an installed sensor looks protected in most reports. The sensor can stop checking in, fall into reduced functionality mode, or never finish provisioning. A host can also run without its prevention or update policy applied. A console count still includes these hosts as protected, so teams find the gaps only after an incident.

The solution

The agent checks each Falcon host against a small set of health conditions and ranks the failures by severity and age. It groups the queue by platform and age, so each owner gets the hosts they can fix. It reports a host that leaves Falcon as out of scope, never as fixed, to enable defenders to close sensor gaps before an attacker finds them.

Workflow

  1. 01

    Read hosts

    Read every host Falcon manages, with its last-seen time, sensor mode, provisioning status, and policy assignments.

  2. 02

    Check health

    Flag stale sensors, reduced functionality mode, incomplete provisioning, and core policies that are not applied.

  3. 03

    Rank

    Order the queue by severity, then by age, and group it by platform for routing.

  4. 04

    Report

    Publish the queue and condition counts with hosts replaced by stable pseudonyms.

Agent template

# CrowdStrike Falcon Sensor Remediation

## Measurable outcomes

Every Falcon host with an unhealthy sensor is in the ranked remediation queue with the condition that put it there. Track the count for each condition on every run. The counts fall as teams remediate sensors.

## Procedure

Read every host Falcon manages. Mark a sensor stale when Falcon has not seen it for more than 7 days, and critical when it is more than 30 days, unless I set other thresholds. Flag reduced functionality mode and any provisioning status other than provisioned. Flag each host where the prevention, sensor update, or content update policy is not applied. A missing applied value is an assignment gap, not proof that the policy settings are weak. Rank reduced functionality, unprovisioned, critically stale, and unapplied core policy conditions above warning-level staleness and missing fields. Break ties by age. Group the queue by platform and age for routing. A host that disappears from Falcon has left scope. Never count it as remediated.

## Requirements

It needs read access to Falcon hosts, and nothing more. Falcon-visible hosts are the denominator, so it never claims to find unmanaged assets. It never changes sensors, host groups, or policies. Reports replace hosts with stable pseudonyms.