Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-595
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
This host has not reported to CrowdStrike Falcon in over 30 days AND is not registered in IT asset management. This is a ghost asset — it has no security monitoring, no designated owner, and no management oversight. Without both a functioning sensor and IT ownership, this host is invisible to security operations and IT governance. If compromised, there is no one responsible for investigating or remediating the incident.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Last Time Seen
older_than_days
30
IT Managed (True/False)
equals
False
Remediation
×
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum