CrowdStrike Falcon Posture Report
Delivers a weekly report on Falcon sensor coverage, policy and exclusion changes, and anything in the tenant that needs attention, from failing automations to license use.
What this agent does
This read-only agent checks the health of a CrowdStrike Falcon tenant every week. It summarizes how many hosts are fully protected and which are stale, degraded, or missing a core policy. It lists policy, exclusion, and rule changes since last week, and Fusion workflows or scheduled reports that failed. It flags anything that needs an admin, such as a failing integration or module use close to the subscription's limits.
The challenge
Falcon only protects hosts where the sensor is current, healthy, and covered by the right policies. Sensors stop checking in, a prevention policy loses its assignment, and an exclusion added for one application weakens protection across a host group. Automations and integrations fail without anyone noticing. Admins find these gaps after an incident, not before.
The solution
The agent checks sensors, policies, exclusions, automations, and subscription use in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check sensors
Count protected hosts, and find stale, degraded, or unprovisioned sensors and hosts missing a core policy.
- 02
Check controls
Compare policies, exclusions, and custom rules with last week, and flag anything that weakens protection.
- 03
Check the tenant
Check Fusion workflows, scheduled reports, API clients, and module use against the subscription.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# CrowdStrike Falcon Posture Report
## Measurable outcomes
Every week, the admin knows which hosts Falcon is not fully protecting, what changed in the tenant, and what needs action before it matters. Track protected and unprotected hosts and open action items on every run.
## Procedure
Once a week, check every host in the Falcon tenant. Count the hosts that are fully protected, and list the ones whose sensor has not checked in for 7 days, runs in reduced functionality mode, never finished provisioning, or lacks an applied prevention, sensor update, or content update policy, unless I set other values. Compare policies, host groups, exclusions, and custom IOA rules with last week's, and call out any change that weakens protection, with who made it. List Fusion workflows and scheduled reports that failed or missed their schedule this week. Check each API client and integration, and flag any that are failing. Compare module and host use with the subscription, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine. Replace hostnames and user names with stable pseudonyms in the report.
## Requirements
It needs read-only Falcon API access to hosts, policies, host groups, exclusions, custom IOA rules, workflows, scheduled reports, API clients, integrations, and subscription details, and nothing more. It never changes sensors, policies, exclusions, or Falcon configuration. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools