Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-586
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
Asset has active critical-severity CrowdStrike detections AND a public IP address making it reachable from the internet. This represents an active compromise or critical threat on an externally accessible asset. The internet exposure means the attacker may have direct C2 communication channels, can exfiltrate data without traversing internal network controls, and the compromised asset can be used as a pivot point from the internet into the internal network.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Critical Severity Threat List
not_empty
Public IP Address
not_empty
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
×
+ Add item
Save Changes
Export Lucidum