← All Findings
Vendor: CrowdStrike Falcon FIN-587 Weight: Confidence: Edited: 2026-03-06 18:14

What It Detects

MITRE ATT&CK Techniques

Comma-separated, e.g. T1078, T1190

Checks read-only

FieldOperatorValue
OS and Version matches_regex (Windows (XP|Vista|7|8|8\.1|Server 200[3-8]|Server 2012)|CentOS [6-8]\b|Ubuntu (14|16|18)\.04|RHEL 6\b|Red Hat.* 6\b|Debian (8|9|10)\b|Amazon Linux AMI|macOS 10\.(1[3-5]))
CVE List not_empty

Remediation

Why It Matters

Export Lucidum