Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-608
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:15
Verified
What It Detects
A host with pending network containment is also internet-facing. The asset has been flagged for isolation due to detected threats, but containment has not yet completed. While containment is pending, the compromised host retains full internet connectivity, allowing threat actors to maintain command-and-control channels, exfiltrate data, or pivot externally. This is a critical escalation: the combination of active compromise and internet reachability during the containment delay window creates maximum exposure.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Status
equals
containment_pending
Public IP Address
not_empty
Remediation
×
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum