r/crowdstrike • u/BradW-CS • 6h ago
r/crowdstrike • u/BradW-CS • 22h ago
Fal.Con 2026 Day 1 Fal.Con 2026 LIVE: Securing Al | George Kurtz, Jensen Huang, Lip-Bu Tan, & Greg Brockman
r/crowdstrike • u/BradW-CS • 3h ago
Fal.Con 2026 Day 2 Fal.Con 2026 LIVE: Platform Innovation | Mike Sentonas, Adam Meyers, & CJ Moses
r/crowdstrike • u/emetphronesis • 1h ago
General Question Does anyone use Crowdstrike to scan network devices for vulnerability?
I understand that Falcon sensor passively collects vulnerability data from endpoints, however I want to start using the network scanning feature for network devices (routers, switches etc) however I am running into an issue:
- Looks like it needs a confirmed network range first, but it does not allow manual addition? I tried to add a network but got an error.
- a test discovery scan on an existing confirmed network does not yield any results (says there are no hosts)
Firewall rules are not the issue since i can see the traffic being allowed.
Has anyone had success getting their network devices scanned?
r/crowdstrike • u/BradW-CS • 7h ago
Securing AI x Interactive Challenge Agents of Chaos: A New $100K Agentic Security Challenge
crowdstrike.comr/crowdstrike • u/wendigibii • 14h ago
Threat Hunting just wanted to gush about how much fun I've had with the AI Unlocked event
don't even care about winning at this point, I hope you guys are enjoying act 2 as much as me!
r/crowdstrike • u/myothercarisatardis_ • 1d ago
General Question At Fal.Con looking for friends
Company is paying me to be here, checked in and don't have much to do, I'm in Vegas and kinda bored, anyone else want to have more fun than the conference promises?
r/crowdstrike • u/Beautiful-Bunch9695 • 1d ago
Next Gen SIEM Falcon AIDR - Spotting the bad
Hi All,
I've been working with Falcon AIDR for some time now and I wanted to share some details on how I've been building an actually valuable detection pipeline. I say this because the product has a lot of valuable features but the documentation can sometimes lack the necessary insight required to make a finding into an alert a human needs to look at.
Basics
As this post is focused on genuine attempts to abuse an AI tool under protection by falcon AIDR rather than someone just not complying with business processes (which AIDR can help with) it's first important to understand what a malicious prompt finding is.
AIDR processes prompts sent to it's endpoints and evaluates the text for key properties. Of course the most intuitive one is sematic meaning where if you provide an instruction, a sense of urgency and an method of output that aligns to a known pattern of abuse it will very likely trigger a malicious prompt finding.
These patterns can and will also have intersectionality with normal human interactions where someone might be frustrated that Copilot won't write a script or in some cases a user might have a legitimate but peculiar request like building a database of identifies from LinkedIn. These contexts lend to sentence content and text structure that can look a lot like prompt injection attempts.
Prompt injection attempts in short are inputs that aim to illicit the language model to act outside a defined set of boundaries. Their shape can vary greatly and Crowdstrike maintains a large database of techniques which you can find for free on their website.
Turn a finding into an alert
Falcon AIDR will likely generate many malicious prompt findings over the course of a month especially if your business is one that provides services to other businesses (B2B). The volume of findings will likely overwhelm any team of analysts but Crowdstrike affords us a few controls and key areas to increase the quality of signals we get out from AIDR and protect analysts from alert fatigue.
Centre to any work you do in this area for Falcon AIDR will be the confidence score. It ranges from 0-1 where zero is no finding and 1 is an exact match. Now if you remember what I detailed earlier that exact match may not be a perfectly bonified adversary on their way to your crown jewels it very well be legitimate user still. However with the confidence score we apply some logic such that more interesting signals are raised and investigated.
I won't explore basic statistical analysis as hopefully everyone can Intuit it's value. If a user generates a hundred confidence 1 malicious prompt findings it's probably worth looking at.
Going further than statistical analysis we can start capturing how entire threads or conversations take shape over time in our logic that generates an alert. To do this we have to consider what adversaries typically do to bypass AI controls.
Looking at past public incidents at the heart of adversary playbooks is the general idea of an interative approach. No single prompt is distinctly or obtusely abusive however the total sum of the conversation as it's processed by the language model ultimately leads to compromise.
Luckily thanks to the verbosity of Falcon AIDR we can build detection logic that covers this. For each malicious prompt finding we can aggregate on a common anchor such as the conversation URL or user and track how that users conversation changes and develops.
In a given conversation Falcon AIDR might rate the first prompt with no findings then it may identify confidential PII through it's classifiers in prompt two and perhaps a non English language in prompt 5. It's these smaller and independently shallow findings that gradually build and develop into a picture that will be very obviously abusive.
Thankfully this is easy to instrument because Falcon AIDR stores it's telemetry in NGSIEM (repo/view perms recently changed if you can't see it).
to be continued...
r/crowdstrike • u/BradW-CS • 1d ago
Fal.Con 2026 AI Is Nothing If It’s Not Secure
r/crowdstrike • u/Dylan-CS • 2d ago
Workflow Wednesday Workflow Wednesday: Live at Fal.Con
Workflow Wednesday is live at Fal.Con!
Join us Wednesday, Sep 2 at 2:30 PM in BK-1405 for Falcon Fusion SOAR: Developers Unleashed. We’ll discuss how to get more out of your workflows and highlight some of the latest capabilities.
Can’t make it? I’ll share some takeaways from the session here in the coming weeks.
r/crowdstrike • u/MSP-IT-Simplified • 2d ago
Troubleshooting Recent issues with CSNpcap.sys
I am about to create a ticket, but wanted to kick it around here real quick. We are getting a lot of issues with the CrowdStrike agent is triggering a service and the CSFalconContainer around the 'CSNpcap.sys' located in '\Device\HarddiskVolume3\Windows\System32\drivers\CSNpcap.sys'
This has happened over the last couple of days. I just marked it as a possible update as we have the probe running for at least 6 months now. However today, we are starting to see the same hostnames starting to come up with detections.
r/crowdstrike • u/PazzoBread • 4d ago
General Question First Fal.Con Event
First time going to Falcon (and Vegas!) Only one from my org going. My role isn’t completely CyberSecurity focused (I manage our Infrastructure, Identity, and Collaboration teams).
Trying to meet up with others who haven’t been before or similar roles! I’ll be arriving pretty early on Monday with plenty of time to kill. If anyone is interested in setting up a meetup (or if there is one already) lmk!
r/crowdstrike • u/Negative_Star7544 • 4d ago
Feature Question Exposure Management Application Packages
There is a section in Exposure management > Applications > Packages that I am wondering about. Does this section feed CVE information to the vulnerabilities portion? I’m not seeing any proof that it does so.
r/crowdstrike • u/hehe123exde • 4d ago
Feature Question Setting up a good EASM coverege
Hello!
I'm in a big need of help from everyone here. Is there any way to monitor EASM changes in an environment through Falcon? I've set up 2 different Workflows but I feel like these two are not enough when it comes to monitoring EASM changes happening. Imo there should be some kind of way to have a broader "auditing" or reporting on different kinds of changes in the EASM, or am I wrong? The only 2 triggers that I've found related to EASM (I think(?)) is "Asset management > New external asset" and "Asset management > New external service".
Is there anyone in here that know how I should go about it? Or maybe how I can set up more triggers than just these two when it comes to EASM monitoring...
Kind regards!
r/crowdstrike • u/BradW-CS • 5d ago
Next Gen SIEM Build Falcon Fusion Workflows with Claude Code
r/crowdstrike • u/PasaPutte • 5d ago
General Question Identity Conditional access
Hey Folks
We connected the Soar to Ms Entra , is it possible to create a conditional access enforcement so users are forced to use MS authenticator if they login to workstations
if yes , any assistance is appreciated on what we need to add or how to configure the rules and condition in CSconditional enforcement
Thx
r/crowdstrike • u/f0rt7 • 5d ago
General Question Fusion SOAR - waiting for "Cloud HTTP Request" response
Hi,
I'm creating a workflow in which I query the Microsoft Graph API. The list of users is displayed with pagination. I'm supposed to iterate through the requests, waiting for the response to each one, but it seems that Fusion SOAR moves on to the next HTTP request without waiting for the response. Is that correct? Because of this, I can't get the link to the next node.
What should I do?
r/crowdstrike • u/BradW-CS • 5d ago
Threat Hunting The Threat Intel Workflow is Broken
r/crowdstrike • u/straffin • 6d ago
General Question Does CrowdStrike host a status page?
We're seeing intermittent "500 Internal Server Error" responses to API calls. Is there a page we can check to find out if there's a wider issue at CrowdStrike?
r/crowdstrike • u/About_TreeFitty • 6d ago
Threat Hunting CVE-2026-21962 - Oracle WebLogic/HTTP Server Vulnerability Scanning
// SOURCE BINDING — pin to your WAF or Firewall URL/threat connectors.
// Confirm exact #event.module / #Vendor values live; they vary by connector build.
(#event.module="waf*" OR #event.module="firewall*" OR #Vendor="waf*" OR #Vendor="firewall*")
| url.combined := coalesce([url.original, url.path, url.full])
| default(field=[url.combined], value="-", replaceEmpty=true)
| src := coalesce([source.ip, client.ip, source.address])
| case {
url.combined=/(\.\.[\/\\]|%2e%2e[%2f%5c]|%252e%252e|\.\.%2f|%c0%ae|\/weblogic\/.*\.\.)/i | IOA := "CVE-2026-21962 proxy path traversal" ;
url.combined=/console\/(images|css|consolejndi)\/.*(%252e|%2e%2e|\.\.).*console\.portal/i | IOA := "CVE-2020-14882/883 Console RCE" ;
url.combined=/com\.tangosol\.coherence\.mvel2|weblogic\.work\.ExecuteThread/i | IOA := "CVE-2020-14882/883 Console RCE" ;
url.combined=/wls-wsat\/(CoordinatorPortType|RegistrationPortTypeRPC|ParticipantPortType)/i | IOA := "CVE-2017-10271 WLS-WSAT RCE" ;
url.combined=/\/(bea_wls_internal|_async\/AsyncResponseService|wls-wsat|console\/|weblogic\/)/i | IOA := "WebLogic internal path probe" ;
* | IOA := "-" ;
}
| IOA!="-"
| case {
in(field=src, values=["193.24.123.42","130.94.17.180","130.94.30.168","15.204.56.106","43.247.135.53"]) | KnownBad := "YES" ;
* | KnownBad := "-" ;
}
| !cidr(src, subnet=["10.0.0.0/8","172.16.0.0/12","192.168.0.0/16"])
| groupBy([src, IOA, KnownBad],
function=([count(as=Hits),
count(url.combined, distinct=true, as=DistinctURIs),
collect([url.combined, http.request.method, user_agent.original, destination.ip], separator=" || ", limit=25),
min(@timestamp, as=FirstSeen),
max(@timestamp, as=LastSeen)]),
limit=max)
| ipLocation(src)
| asn(src)
| formatTime(format="%F %T %Z", field=FirstSeen, as=FirstSeen)
| formatTime(format="%F %T %Z", field=LastSeen, as=LastSeen)
| sort(Hits, order=desc, limit=20000)
r/crowdstrike • u/Efficient-Drive-810 • 7d ago
General Question Can we get reserved sessions/workshops back for Fal.con this year?
It looks that unlike in the past, your session/workshop registration is no longer an entry pass, it is just a bookmark in your calendar. I believe this will make many returning fal.con attendees very confused when 1. They aren't allowed in to a session they pre-selected and 2. They pre-made an agenda which will almost certainly not work as the sessions will just fill up before they get to the next planned session.
I have chatted with returning attendees at a number of different companies who did a double-take when we saw that e-mail in the last 24 hours informing of this.
If possible, I would suggest Crowdstrike revert the change for this year's Fal.con, because those who know Fal.con know that without reserving sessions, this is likely to lead to a lot of disappointing outcomes.
r/crowdstrike • u/nav2203 • 7d ago
Query Help Getting Session ID (incl. Session 0) for RMM tools ,is there a CQF for this?
Im working on detection/hunting for RMM tool abuse and want to surface the session context each RMM agent and its child processes are running in specifically whether activity is originating from Session 0 (service/non-interactive) vs. an interactive user session. The idea is to flag hands-on-keyboard tooling spawning from a service-mode RMM agent.
Is there an existing Cool Query Friday that covers session context / RMM hunting I should start from?
r/crowdstrike • u/dark_prophet • 7d ago
General Question Why does CrowdStrike Falcon filter block my USB keyboard/mouse combination ?
All of a sudden it began to block them on my company issued MacOS laptop.
What is the point in ever blocking keyboard or mouse?
Do they present a security threat?
r/crowdstrike • u/cynocation • 7d ago
General Question Falcon Browser Extension - Incognito/InPrivate mode
For those who are using the DLP / Exposure Management module, how do you manage to roll this out to Incognito mode?
My understanding is that users have to individually enable it, but I would prefer to do this via a group policy, (we don't have Intune) so I am trying to avoid asking all our users to manually toggle this on, in the event they may circumvent policy.
From what I have read, Google and Edge block this automatic installation.
Appreciate any assistance.
r/crowdstrike • u/Strict_Event9682 • 8d ago
General Question Has anyone used AgentWorks in production workflows?
Posting from throwaway account:
We are considering trying AI Agents with Charlotte AgentWorks and would like to hear from people who have used it in production and not just for demos or experiments.
What are you using it for?
How easy was the initial setup and integration (for eaxmple with Falcon Fusion SOAR)?
How reliable is it?
How much value has it added to your workflows?
What are the ongoing costs, and do you feel the ROI is worth it?
Are there any limitations that we should be aware of?
Any honest experiences (positive or negative) would be helpful.
Thank you!