CrowdStrike Falcon Alert Triage
Provides a ranked queue of open Critical and High Falcon alerts with their age, ownership, recurring signatures, and bursts.
What this agent does
This read-only agent reviews the open Critical and High alerts in CrowdStrike Falcon. It ranks them by severity and age, and it flags alerts with no owner. It groups alerts that share a signature and finds bursts of the same alert.
The challenge
An alert backlog grows faster than a team can read it. Old Critical alerts end up below new low-value alerts, and some alerts have no owner at all. One noisy detection can fill the queue in an hour. Without a daily view of age, ownership, and repetition, analysts work the newest alert instead of the most urgent one.
The solution
The agent ranks the open Critical and High alerts, with Critical first and older alerts first. It measures age against advisory thresholds and never presents them as an organizational SLA. It shows recurring signatures and bursts as tuning candidates, to enable defenders to work the oldest urgent alerts and cut repeated noise.
Workflow
- 01
Read open alerts
Read the open alerts from the last 90 days with their severity, created time, owner, product, type, and technique.
- 02
Rank
Order Critical before High, then older before newer, and flag alerts past the advisory aging thresholds.
- 03
Find patterns
Group alerts by product, type, and technique to find recurring signatures and hourly bursts.
- 04
Report
Publish the queue and pattern counts without detection names, hosts, users, or alert IDs.
Agent template
# CrowdStrike Falcon Alert Triage
## Measurable outcomes
Every open Critical and High Falcon alert is in the ranked queue with its age and whether it has an owner. Track the aging, unowned, recurring, and burst counts on every run.
## Procedure
Read the open Falcon alerts from the last 90 days. Rank Critical before High, then older before newer. Flag a Critical alert older than 24 hours and a High alert older than 72 hours, unless I supply our response SLAs. Call these thresholds advisory, never SLA breaches. Flag each Critical or High alert with no owner. Treat alerts that share a product, type, and technique as one signature. Call a signature recurring when it has 3 or more open alerts. Call it a burst when 5 or more of its alerts arrive in the same hour. Present recurring signatures and bursts as tuning candidates.
## Requirements
It needs read access to Falcon alerts, and nothing more. It never changes alert status, assignment, exclusions, or prevention policy. Reports show products, types, techniques, and counts, with detection names, hosts, users, and alert IDs left out. Related templates
-
Datadog Detection Posture Report
Delivers a weekly report on Datadog Cloud SIEM log ingestion gaps, detection rules that are disabled, erroring, or blind, and anything in the organization that needs an admin, from Security Filter exclusions to silent Agents.
Reporting and Compliance / Security Operations 1 tools -
Datadog Detection Tuning
Finds the Datadog Cloud SIEM detection rules that produce the most noise, reads each one against the signals it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Elastic Security Detection Posture Report
Delivers a weekly report on Elastic Security data stream gaps, detection rules that are failing, warning, or blind, and anything in the deployment that needs an admin, from offline Elastic Agents to lifecycle errors.
Reporting and Compliance / Security Operations 1 tools -
Elastic Security Detection Tuning
Finds the Elastic Security detection rules that produce the most noise, reads each one against the alerts it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools