Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-591
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
Asset has active malware or threat alerts AND a public IP address making it reachable from the internet. The internet exposure creates multiplicative risk because malware on an internet-facing asset has a direct path for command-and-control communication and data exfiltration without traversing internal network security controls. The public IP also means the malware infection may have originated from direct external exploitation.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Malware/Threat Alerts
not_empty
Public IP Address
not_empty
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
×
+ Add item
Save Changes
Export Lucidum