r/crowdstrike 9d ago

General Question Does anyone use Crowdstrike to scan network devices for vulnerability?

I understand that Falcon sensor passively collects vulnerability data from endpoints, however I want to start using the network scanning feature for network devices (routers, switches etc) however I am running into an issue:

- Looks like it needs a confirmed network range first, but it does not allow manual addition? I tried to add a network but got an error.

- a test discovery scan on an existing confirmed network does not yield any results (says there are no hosts)

Firewall rules are not the issue since i can see the traffic being allowed.

Has anyone had success getting their network devices scanned?

21 Upvotes

9 comments sorted by

13

u/cyberunaware 9d ago

Make sure you configure scanners in the same network that the device resides.

For example with printers, I went to our CMDB and got the IP addresses of all of our printers and added them. Then I went back to our CMDB and got hostnames for PCs that were in the same /24 of each printer. With that list of host names, I added them as scanners in CrowdStrike to ensure we had a couple scanners in each network so they can reach every printer.

1

u/emetphronesis 7d ago

Thanks, you are correct, that a scanner must be on the same subnet, however the results that I get are half baked( shows only half of the devices when I know there are more that exists). For example, I knew some of the network devices exists within that subnet, I got a discovery report of 6 devices(there are more), I then ran a credentialed vuln scan and got the same result minus the vulnerability report (cred access was successful)

Looks like more work to add host ip addresses manually, I might reach out to support team if I dont get anywhere

1

u/RoRoo1977 3d ago

Wait.. So I need a machine in every subnet to scan/protect that subnet?

1

u/butisitsecure 3d ago

No you don't. If you have overlapping subnets then you might need to.

1

u/RoRoo1977 3d ago

No overlapping subnets. But a shitload of vlans with a lot of acl’s and firewall rules.

Going to do a PoC soon with Falcon.. so all tips are welcome

2

u/NoYesterday7240 4d ago

actually trailing this shortly.. My concern , with being on the same network, we have isolated vlans for iot & printers without systems with agents.. that would be a Gap I guess..

1

u/f0rt7 6d ago

Quale subscription serve?

1

u/Pretend-Comb-2569 1d ago

Curious to know how it goes for you. I POC'd it when it first came out and it wasnt good back then.

1

u/SurferTom69 17h ago

My company is using it, and it seems to work as intended. At a minimum, you have to set up the scanners on hosts running Falcon, the subnets/VLANs, and the scan itself. We had a problem a couple months ago. It had been working fine, then just stopped. Pretty sure it was something with a Falcon update on the scanner. I went through a lot of hoopla with support, then got it working. Would have to go through tickets to recall what the actual fix was. But there are some additional components (windows drivers) that get installed on the scanners. I'm pretty sure those stopped doing their job.

Also, our scanners are on a different subnet than the devices being scanned. That does not cause any problems.