Skip to main content
{ Security Operations } Featured agent

CrowdStrike Falcon Alert Triage

Provides a ranked queue of open Critical and High Falcon alerts with their age, ownership, recurring signatures, and bursts.

What this agent does

This read-only agent reviews the open Critical and High alerts in CrowdStrike Falcon. It ranks them by severity and age, and it flags alerts with no owner. It groups alerts that share a signature and finds bursts of the same alert.

The challenge

An alert backlog grows faster than a team can read it. Old Critical alerts end up below new low-value alerts, and some alerts have no owner at all. One noisy detection can fill the queue in an hour. Without a daily view of age, ownership, and repetition, analysts work the newest alert instead of the most urgent one.

The solution

The agent ranks the open Critical and High alerts, with Critical first and older alerts first. It measures age against advisory thresholds and never presents them as an organizational SLA. It shows recurring signatures and bursts as tuning candidates, to enable defenders to work the oldest urgent alerts and cut repeated noise.

Workflow

  1. 01

    Read open alerts

    Read the open alerts from the last 90 days with their severity, created time, owner, product, type, and technique.

  2. 02

    Rank

    Order Critical before High, then older before newer, and flag alerts past the advisory aging thresholds.

  3. 03

    Find patterns

    Group alerts by product, type, and technique to find recurring signatures and hourly bursts.

  4. 04

    Report

    Publish the queue and pattern counts without detection names, hosts, users, or alert IDs.

Agent template

# CrowdStrike Falcon Alert Triage

## Measurable outcomes

Every open Critical and High Falcon alert is in the ranked queue with its age and whether it has an owner. Track the aging, unowned, recurring, and burst counts on every run.

## Procedure

Read the open Falcon alerts from the last 90 days. Rank Critical before High, then older before newer. Flag a Critical alert older than 24 hours and a High alert older than 72 hours, unless I supply our response SLAs. Call these thresholds advisory, never SLA breaches. Flag each Critical or High alert with no owner. Treat alerts that share a product, type, and technique as one signature. Call a signature recurring when it has 3 or more open alerts. Call it a burst when 5 or more of its alerts arrive in the same hour. Present recurring signatures and bursts as tuning candidates.

## Requirements

It needs read access to Falcon alerts, and nothing more. It never changes alert status, assignment, exclusions, or prevention policy. Reports show products, types, techniques, and counts, with detection names, hosts, users, and alert IDs left out.