Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CrowdStrike Falcon
FIN-613
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 18:14
Verified
What It Detects
A Falcon sensor operating in Reduced Functionality Mode (RFM) is installed on an asset with known CVE vulnerabilities. The sensor's degraded state means it cannot provide full exploit prevention and behavioral detection capabilities, while the CVE vulnerabilities provide known attack paths. This creates a multiplicative risk: attackers have documented exploitation techniques (CVEs) and the primary defensive sensor cannot fully detect or block exploitation attempts. The RFM condition may also prevent vulnerability-specific prevention policies from executing.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Status
equals
rfm
CVE List
not_empty
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum