Skip to main content
{ Endpoint Security }

CrowdStrike Falcon Control Drift

Provides the Falcon policies, exclusions, rules, and automations that changed since a baseline the team approved.

What this agent does

This read-only agent detects changes to the security controls in CrowdStrike Falcon. It fingerprints each policy, host group, custom IOA rule group, exclusion, correlation rule, workflow, and scheduled report. It compares the fingerprints with a baseline the team approved. It then reports each control that was deleted, disabled, modified, or created.

The challenge

Falcon controls change through the console, the API, and integrations, often with no review. A new exclusion or a disabled prevention policy can remove protection from thousands of hosts. Nobody compares the result with what the team intended. Teams find unapproved changes only when a detection fails to fire.

The solution

The agent compares current controls only against a baseline that a person approved. It treats a control surface with no approved baseline as a candidate, never as drift. It ranks deleted and disabled controls above modified and created ones. It never approves a baseline itself, to enable defenders to catch unapproved control changes before a detection fails because of them.

Workflow

  1. 01

    Fingerprint controls

    Read each control surface and fingerprint each control, ignoring timestamps and editor metadata.

  2. 02

    Compare with the baseline

    Compare each surface with its approved baseline, and mark surfaces without one as candidates.

  3. 03

    Rank drift

    Rank deleted and disabled controls above modified and created ones.

  4. 04

    Report

    Publish the drift queue and the candidate surfaces with controls replaced by stable pseudonyms.

Agent template

# CrowdStrike Falcon Control Drift

## Measurable outcomes

Every Falcon control that differs from its approved baseline is in the drift queue with its change type. Every surface without an approved baseline is listed. Track the drift count for each change type on every run.

## Procedure

Read these Falcon control surfaces: host groups, prevention, sensor update, content update, device control, response, and firewall policies, custom IOA rule groups, IOA, machine learning, sensor visibility, and certificate exclusions, correlation rules, Fusion workflow definitions, and scheduled reports. Fingerprint each control from its configuration, and ignore timestamps and the identity of the last editor. Compare each surface with its approved baseline. A control in the baseline and absent now is deleted. A control that is new is created. A control with a changed fingerprint is disabled when it is now off, and modified otherwise. Rank deleted and disabled above modified and created. A surface with no approved baseline is a candidate, never drift. I approve a baseline for a named run and surface only after I review it. Never approve a baseline to clear drift.

## Requirements

It needs read access to each control surface, and nothing more. A surface that returns access denied is not assessed, not absent. It never changes Falcon configuration and never approves a baseline. Reports show the surface and change type, with controls replaced by stable pseudonyms.