CrowdStrike Falcon Sensor Remediation
Provides a ranked queue of Falcon sensors that are stale, degraded, unprovisioned, or missing a core policy.
What this agent does
This read-only agent finds the CrowdStrike Falcon sensors that do not protect their hosts as expected. It checks every Falcon host for staleness, reduced functionality mode, provisioning status, and core policy assignment. It then ranks the unhealthy sensors into one remediation queue.
The challenge
A host with an installed sensor looks protected in most reports. The sensor can stop checking in, fall into reduced functionality mode, or never finish provisioning. A host can also run without its prevention or update policy applied. A console count still includes these hosts as protected, so teams find the gaps only after an incident.
The solution
The agent checks each Falcon host against a small set of health conditions and ranks the failures by severity and age. It groups the queue by platform and age, so each owner gets the hosts they can fix. It reports a host that leaves Falcon as out of scope, never as fixed, to enable defenders to close sensor gaps before an attacker finds them.
Workflow
- 01
Read hosts
Read every host Falcon manages, with its last-seen time, sensor mode, provisioning status, and policy assignments.
- 02
Check health
Flag stale sensors, reduced functionality mode, incomplete provisioning, and core policies that are not applied.
- 03
Rank
Order the queue by severity, then by age, and group it by platform for routing.
- 04
Report
Publish the queue and condition counts with hosts replaced by stable pseudonyms.
Agent template
# CrowdStrike Falcon Sensor Remediation
## Measurable outcomes
Every Falcon host with an unhealthy sensor is in the ranked remediation queue with the condition that put it there. Track the count for each condition on every run. The counts fall as teams remediate sensors.
## Procedure
Read every host Falcon manages. Mark a sensor stale when Falcon has not seen it for more than 7 days, and critical when it is more than 30 days, unless I set other thresholds. Flag reduced functionality mode and any provisioning status other than provisioned. Flag each host where the prevention, sensor update, or content update policy is not applied. A missing applied value is an assignment gap, not proof that the policy settings are weak. Rank reduced functionality, unprovisioned, critically stale, and unapplied core policy conditions above warning-level staleness and missing fields. Break ties by age. Group the queue by platform and age for routing. A host that disappears from Falcon has left scope. Never count it as remediated.
## Requirements
It needs read access to Falcon hosts, and nothing more. Falcon-visible hosts are the denominator, so it never claims to find unmanaged assets. It never changes sensors, host groups, or policies. Reports replace hosts with stable pseudonyms. Related templates
-
CrowdStrike Falcon Control Drift
Provides the Falcon policies, exclusions, rules, and automations that changed since a baseline the team approved.
Endpoint Security 1 tools -
CrowdStrike Falcon Posture Report
Delivers a weekly report on Falcon sensor coverage, policy and exclusion changes, and anything in the tenant that needs attention, from failing automations to license use.
Reporting and Compliance / Endpoint Security 1 tools -
SentinelOne Posture Report
Delivers a weekly report on SentinelOne agent coverage, what changed, and anything in the console that needs attention, from detect-only policies to license seats.
Reporting and Compliance / Endpoint Security 1 tools