Skip to main content
{ Security Operations }

CrowdStrike Falcon Detection Telemetry QA

Provides a quality report on Falcon alert data, covering missing triage fields, missing ATT&CK mappings, and malformed ATT&CK IDs.

What this agent does

This read-only agent checks the quality of the alert data in CrowdStrike Falcon. It finds alerts that lack the fields analysts need to triage them. It finds alerts with no MITRE ATT&CK mapping or a malformed ATT&CK ID.

The challenge

Detection coverage reports depend on alert data that nobody checks. Third-party and custom detections often arrive without an ATT&CK mapping, or with an ID in the wrong format. Some alerts lack a severity, status, or timestamp. A coverage map built on that data shows false gaps and leaves out real ones.

The solution

The agent measures each quality problem separately across the alerts in the window. It separates missing mappings from malformed IDs, because each one has a different fix. It shows third-party alert volume as context for normalization work. It never reads an unobserved technique as missing coverage, to enable defenders to trust their ATT&CK coverage evidence.

Workflow

  1. 01

    Read alerts

    Read the Falcon alerts from the last 90 days.

  2. 02

    Check fields

    Count alerts that lack a product, type, severity, status, or created time.

  3. 03

    Check ATT&CK

    Count alerts with no tactic or technique, and alerts whose tactic or technique ID is malformed.

  4. 04

    Report

    Publish the counts by product, with third-party volume as context and no raw alert content.

Agent template

# CrowdStrike Falcon Detection Telemetry QA

## Measurable outcomes

Every quality problem in the Falcon alert data has a count: missing triage fields, missing ATT&CK mappings, and malformed ATT&CK IDs. Track each count on every run. The counts fall as teams fix connectors and mappings.

## Procedure

Read the Falcon alerts from the last 90 days, unless I set another window. Count the alerts that lack a product, type, severity, status, or created time, per field. Count the alerts with no tactic or no technique as unmapped. Count a tactic ID that is not in the form TA0000 and a technique ID that is not in the form T0000 or T0000.000 as malformed. Report missing and malformed mappings separately. Break the counts down by product, and show third-party alert volume as normalization context. An ATT&CK technique with no alerts is not observed. It is not proof that a detection is absent.

## Requirements

It needs read access to Falcon alerts, and nothing more. It never changes connectors, detections, or Falcon content. Reports show aggregate counts by product, with raw alert content, detection names, hosts, users, and alert IDs left out.