CrowdStrike Falcon Vulnerable Software Context
Provides the context of each vulnerable software finding on Falcon hosts, from system-installed to active or inactive development.
What this agent does
This read-only agent explains where the vulnerable software on CrowdStrike Falcon hosts comes from. It samples open Spotlight findings and joins them to Falcon Discover application data. It then labels each finding as system-installed software, an active or inactive development dependency, mixed, or unknown.
The challenge
A Spotlight finding can be operating system software, a dependency a developer uses every day, or stale project files nobody touches. Each one needs a different fix, but Spotlight shows them all the same way. Loose name matching joins the wrong evidence, and missing Discover access can look like inactivity. Teams cannot tell which findings need a patch and which need a cleanup, so every finding gets the same treatment instead.
The solution
The agent joins Spotlight and Discover evidence only on an exact host and product, plus an exact version, path, or unique version prefix. It treats ambiguous matches as unmatched. It reports missing Discover access as not assessed, never as inactive. It calls a dependency active when Discover shows use within the last 30 days, to enable defenders to route each finding to the right fix.
Workflow
- 01
Sample findings and evidence
Take a stratified sample of open Spotlight findings across platform and severity. Read Discover application data for the sampled hosts, and record missing access as not assessed.
- 02
Join exactly
Match on the exact host and product, then an exact version, an exact path, or a unique version prefix.
- 03
Classify
Label each record system-installed, active or inactive development, mixed, or unknown, using a 30-day activity window.
- 04
Report
Publish aggregate results and per-record classifications with hosts and paths pseudonymized.
Agent template
# CrowdStrike Falcon Vulnerable Software Context
## Measurable outcomes
Every sampled vulnerable-software finding gets one context class: system-installed, active development dependency, likely active development dependency, inactive development dependency, mixed, present with unknown context, or not assessed. Track the count in each class on every run.
## Procedure
Take a stratified sample of open Spotlight findings across Windows, Linux, and Mac and across severities. Fill spare capacity with the most recently updated findings. Read Falcon Discover application data for the sampled hosts. Join a finding to Discover evidence only on the exact host and exact product name, then an exact version, an exact install path, or a unique numeric version prefix. Treat several remaining candidates as unmatched, and never fall back to fuzzy name matching. Package-manager, registry, or system-path evidence marks software as system-installed. Call a development dependency active when Discover shows use within the last 30 days, unless I set another window. Report missing Discover permission, entitlement, or data as not assessed, never as inactive. Inactive means no use within the window, not safe to remove.
## Requirements
It needs read access to Spotlight vulnerabilities and Falcon hosts, and Assets: READ for Discover application data, and nothing more. It never removes software, quarantines files, runs Real Time Response, or changes Falcon state. Reports show CVEs and software names and versions, with hosts and paths replaced by stable pseudonyms. A Spotlight finding shows Falcon evaluated a vulnerable-software condition, not that the code runs or is reachable. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools