This document and video will demonstrate how to use Falcon Spotlight to find vulnerabilities in your environment while overcoming the challenges with traditional vulnerability management solutions.
Spotlight for Reporting
Falcon Spotlight leverages CrowdStrike’s single management platform and lightweight agent to provide organizations with access to vulnerability assessment information. The sensor provides real time results on protected systems with no time consuming, impactful system scans or a requirement for any network hardware. In this demonstration, we are going to review three different use cases for Falcon Spotlight and how this solution can add value to your organization.
To access Spotlight, find the Spotlight App in the menu on the left.
On the main dashboard, you have a top level overview of the vulnerabilities in your environment. The dashboard updates as you pivot and filter the vulnerability data with the Falcon search bar, providing the bigger picture. Clicking on the dashboard tables brings you into a detailed overview for that area of interest.
Clicking into the “Critical” CVEs, you are presented with the backing evidence – the list of applicable CVE’s being reporting in your environment. Those details include the specific CVE, a brief description, the published date and the count of vulnerable hosts in the environment. That report also offers the opportunity to drill down further to see a detailed list of vulnerable hosts. On each page, there is an option to export the list making it easy to share the information with patch management teams.
From the Falcon Spotlight Dashboard, statistics regarding “Closed vs Open” vulnerabilities is provided. These statistics give a good understanding of how quickly patches are being applied as well as vulnerability trends over time.
Spotlight for Research
Falcon Spotlight includes the functionality to research a specific vulnerability and the potential exposure in your environment. Here, we see the option to search by vulnerability. The results include the summary details of the CVE, a count of vulnerable hosts, and a detailed list of those systems that need to be patched.
Like before, there is an option to download the list of systems that are lacking the required patch. Sharing this list with the patch management team would help them prioritize this patch and target the correct systems.
Spotlight for Investigations
In the situation of an incident or compromised system, Spotlight can also be used to assess the health of a given host. The search can be done by KB or CVE. Here, we see a search by hostname to understand what patches are missing from this specific system.
In this example, the system is missing one high – medium CVE. This information could provide insight into how the system was compromised and how it can be better protected in the future.
Falcon Spotlight provides holistic access to the vulnerability status of your environment with simple reporting and real time results without introducing complex hardware or time consuming scans. It provides complete, actionable reporting to help make your organization more secure.
How to Contain an Infected System
Hi, there. My name’s Peter Ingebrigtsen. And today, we’ve logged into the falcon.crowdstrike.com, or the Falcon User Interface.
And what we’re going to do is take a look at some of our systems and recognize that some of them are either currently under attack or recently been under attack, and may have been compromised. And we’d like to contain that system until we can further get to it, get our hands on it, and get a little bit more information out of it, or just prevent it from doing any more damage than it’s already done.
In order to do that, you need to be on your Detections app. You can do that by going to the radar here on the left-hand side. If you’re not already, or if your user interface doesn’t open that when you first log in, head there. And then just select the Recent Detections.
When that opens, you’ll notice that you can filter by any number of criteria, but we’re looking at some of the more recent events or situations that are going on. And you’ll notice that the same single machine has noticed a lot of different scenarios with privilege escalation or web exploits. And these severities are high to critical.
And we’d like to log in there, maybe do a little something, take a little closer look, and see if there’s something we should do. Obviously, we should do something. And as we start to dig through here, we see that there’s a lot of detection patterns, whether that be known malware, credential theft, or web exploits. We can see in the process tree a lot of different commands that were issued that look at that privilege escalation that we noticed earlier– or start to set that up.
So, we know that there’s something bad going on, and we’d like to take action right away. So, what we want to do is network contain this machine. But what I want to show you, as well, is that as we do this– I’m going to go to the machine itself. And I’d like to start a continuous ping so that you can watch the behavior and how long it takes to respond to this network containment.
Now, while we contain this– or take this machine off the network– we don’t kill the connection to the CrowdStrike Cloud. So, that as we get our hands on it– we clean it up, we feel comfortable putting it back on to the network– we can still operate or control that machine through the user interface that we have here.
The other thing I’d like to do is start a large download, so that we initiate with a single TCP connection– and there happens to be one in process– as opposed to the ping, where there may be multiple TCP resets or individual TCP threads going every time. So that you can see that as we contain this machine, it literally just knocks it off the network.
Forgive my screen, but I’ve changed the resolution for YouTube and for appearance purposes.
But as I come in here– and this will be right at the middle of the screen– this actually says Device Actions. And I’d like to contain it.
Now, as we do that, we have some options to make some notes. Contained by Peter. Multiple threats observed. Whatever notes you’d like to make– and then select Contain.
Now, the second we do this, on the left-hand side, you’ll see how quickly it takes for that to respond. So, immediately, almost in real time, you see a network failure on the download, and the ping test– or the continuous ping fail. So, we can close that.
Now, let’s say we’re a couple days later, this machine’s cleaned up, ready to go, and be put back in the network. You can go ahead and lift the network containment, again, from the user interface. We still have that connection to the machine, even though all the other network connections have been terminated.
So, as we do that, all good. Uncontain. And you’ll notice that almost immediately that ping starts to fire right back up again.
So, network containment is a powerful tool that we can use if we see something immediately taking action or if we see something recently in the past, and we’d like to get that machine off the network– almost quarantine it– so that it can’t do any more damage.
So, this has been network containment of network devices in the Falcon Sensor User Interface platform. Thanks again for watching.