Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-609
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:15
Verified
What It Detects
A Falcon sensor operating in Reduced Functionality Mode (RFM) is installed on an internet-facing asset. RFM occurs when the sensor encounters kernel or driver incompatibilities, leaving it unable to provide full endpoint protection. On an internet-facing asset, this creates a dangerous gap: the host is externally reachable by attackers but the sensor cannot deliver its complete detection and prevention capabilities. Unlike a disabled or stale sensor, RFM indicates the sensor is running but operating with significantly degraded protection.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Status
equals
rfm
Public IP Address
not_empty
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum