Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-588
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
The Falcon sensor is disabled AND the asset is not IT-managed (shadow IT). This creates a dangerous blind spot because the asset has no endpoint protection AND no assigned owner responsible for its security. On a managed asset, a disabled sensor would likely be noticed and remediated by the assigned IT team. On an unmanaged asset, a disabled sensor can persist indefinitely with no one aware of or accountable for the gap.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Agent Enabled (True/False)
equals
False
IT Managed (True/False)
equals
False
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
×
+ Add item
Save Changes
Export Lucidum