What problem does it solve?
Rolling out endpoint detection and response across a fleet of endpoints is error-prone: sensors installed without a CID never connect, prevention policies left in detect-only mode never block malware, and macOS system extensions get silently blocked. This Skill provides a verified, step-by-step deployment workflow for CrowdStrike Falcon that avoids these common misconfigurations.
Core Features & Use Cases
- Cross-platform sensor deployment: Silent installation commands for Windows (SCCM, Intune, GPO), Linux (deb/rpm with falconctl), and macOS (pkg with MDM system extension approval).
- Policy configuration: Recommended prevention policy settings for machine learning, behavioral protection, exploit mitigation, and ransomware, with separate policies for workstations, servers, and critical infrastructure.
- Validation and SIEM integration: Verification steps including RFM state checks, CsTestDetect test detections, and streaming telemetry to Splunk or Elastic via Falcon Event Streams and FDR.
- Use Case: An IT administrator needs to onboard 500 Windows laptops to CrowdStrike via Intune, confirm each host reports Online with blocking prevention policies, and forward detections to the corporate Splunk instance.
Quick Start
Deploy the CrowdStrike Falcon sensor to my Windows endpoints via Intune and verify each host reports Online with prevention policies set to block.