Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-565
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
This host has been placed in network containment by CrowdStrike Falcon. The device can only communicate with the CrowdStrike cloud — all other network access is blocked. This is typically an active incident response measure indicating a suspected or confirmed compromise. The host requires investigation and remediation before containment can be lifted.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Status
equals
contained
Remediation
×
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum