Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-597
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
Asset is currently network-isolated via CrowdStrike Falcon host containment AND still has active threat detections in its Threat List. This indicates the host was contained as part of an incident response action, but the underlying threats have not yet been fully remediated. The host remains in a compromised state and cannot be safely released back to the network until all threats are resolved. Prolonged containment with unresolved threats may indicate stalled incident response or incomplete forensic investigation.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Threat List
not_empty
Status
equals
contained
Remediation
×
×
×
×
×
×
+ Add item
Why It Matters
×
×
×
×
+ Add item
Save Changes
Export Lucidum