Expert agent for CrowdStrike Falcon Surface EASM. Covers internet asset discovery, exposure scoring, CrowdStrike Falcon platform integration, EDR-to-EASM correlation, and attack surface reduction workflows. WHEN: \"Falcon Surface\", \"CrowdStrike EASM\", \"CrowdStrike attack surface\", \"Falcon Surface exposure\", \"external attack surface CrowdStrike\".
Scanned 9/24/2026
npx -y skills add chrishuffman5/domain-expert --skill falcon-surface --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Falcon Surface?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/chrishuffman5-falcon-surface)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: falcon-surface
description: "Expert agent for CrowdStrike Falcon Surface EASM. Covers internet asset discovery, exposure scoring, CrowdStrike Falcon platform integration, EDR-to-EASM correlation, and attack surface reduction workflows. WHEN: \"Falcon Surface\", \"CrowdStrike EASM\", \"CrowdStrike attack surface\", \"Falcon Surface exposure\", \"external attack surface CrowdStrike\"."
license: MIT
---
# CrowdStrike Falcon Surface
This skill covers CrowdStrike Falcon Surface (formerly Reposify, acquired by CrowdStrike in 2021). It has expertise in Falcon Surface's internet asset discovery, exposure scoring, integration with the CrowdStrike Falcon platform, EDR-to-EASM correlation, and attack surface reduction workflows.
## How to Approach Tasks
1. **Classify** the request:
- **Asset discovery / onboarding** -- Seed data, initial discovery, attribution
- **Exposure analysis** -- Exposure scoring, risky services, open ports
- **CrowdStrike integration** -- Falcon platform correlation, EDR data
- **Remediation workflow** -- Closing exposures, ticketing integration
- **Monitoring / alerts** -- New asset alerts, exposure change notifications
2. **Apply CrowdStrike ecosystem context** -- Falcon Surface's key differentiator is correlation with CrowdStrike endpoint data. Organizations already using Falcon EDR get additional context: "This internet-exposed server is ALSO running outdated CrowdStrike sensor version and has active threat detections."
## Product Overview
**Falcon Surface:** CrowdStrike's EASM module within the Falcon platform.
**Key differentiators:**
- Native integration with Falcon platform (same console as EDR, threat intelligence, exposure management)
- Correlation of EASM findings with endpoint sensor data (EDR + ASM convergence)
- CrowdStrike threat intelligence enrichment -- known attack patterns against exposed technologies
- Falcon Exposure Management: broader than ASM alone, maps EASM to internal exposure
**Deployment:** SaaS, no infrastructure to deploy. Onboard via domain/IP seeds.
## Asset Discovery
### Onboarding / Seed Configuration
1. Log in to Falcon console
2. Navigate to: Exposure Management > Attack Surface Management
3. Add seeds:
- Primary domains (company.com, company.net)
- IP ranges (owned IP blocks, cloud-assigned ranges)
- Company names and subsidiaries
- Acquisition entities
### Discovery Process
Falcon Surface uses:
- **Certificate Transparency Logs:** Discovers subdomains via crt.sh and similar
- **DNS enumeration:** Subdomain brute force, zone transfers, passive DNS
- **Shodan/Censys data correlation:** Internet-wide scan data
- **Web crawling:** Links, JavaScript endpoints, sitemap exploration
- **WHOIS/BGP:** IP ownership attribution
- **CrowdStrike intel enrichment:** Threat actors known to target discovered technologies
### Attribution Confidence
Each discovered asset is scored for attribution confidence:
- **Confirmed:** Directly tied to seed domain/IP (same certificate, direct DNS)
- **Probable:** Strong indicators (subdomain pattern, certificate with company name)
- **Possible:** Indirect link (technology fingerprint, content analysis)
Review "Possible" assets before accepting into monitored inventory.
## Exposure Analysis
### Exposure Score
Each asset receives an exposure score based on:
- Services running (RDP, SSH, Telnet, database ports -- high risk if exposed)
- Software versions (is this running EOL software?)
- TLS/SSL configuration (expired cert, weak cipher, self-signed)
- CVEs on detected software/versions
- CrowdStrike threat intelligence: Is this technology actively targeted?
### High-Risk Exposure Categories
| Exposure Type | Risk | Action |
|---|---|---|
| RDP exposed (port 3389) | Critical | Close immediately or put behind VPN/Bastion |
| SSH exposed (port 22) | High | Restrict to known IPs; enforce key auth |
| Database ports exposed (3306, 5432, 1433, 27017) | Critical | Move behind firewall |
| Telnet/FTP (23/21) | Critical | Disable; replace with SSH/SFTP |
| Expired SSL certificates | High | Renew immediately |
| Self-signed certificates | Medium | Replace with trusted CA cert |
| Admin panels exposed (phpmyadmin, Jenkins, etc.) | Critical | Restrict or disable |
| S3 buckets publicly accessible | High-Critical | Enable Block Public Access |
| Development environments | High | Shut down or restrict to VPN |
## CrowdStrike Falcon Platform Integration
### EDR + ASM Correlation
Falcon Surface correlates with Falcon EDR data:
**Correlation use cases:**
- "This internet-exposed host: Does it have a Falcon sensor? What version?"
- "Host A is externally exposed AND has active detections in Falcon Insight"
- "This exposed web server has a critical finding in Falcon Discover (unmanaged asset)"
- "Alert: New external exposure detected on host that has a high-severity active detection"
**Falcon Exposure Management:**
The broader exposure management context in CrowdStrike:
- External exposure (Falcon Surface / EASM)
- Internal exposure (CVEs on Falcon-protected endpoints)
- Identity exposure (compromised credentials, Falcon Identity Protection)
- Combines for holistic "What is our actual exposure to a real attacker?"
### Threat Intelligence Enrichment
CrowdStrike Adversary Intelligence enriches EASM findings:
- "Subdomain dev.company.com is running Apache 2.4.49 -- CVE-2021-41773 (actively exploited by eCrime actors)"
- Known threat actor TTPs mapped to discovered technologies
- "4 active threat groups are known to exploit exposed Jenkins instances"
## Remediation Workflows
### Remediation Tracking in Falcon Surface
1. Navigate to: Exposure Management > Attack Surface Management > Findings
2. Filter by: Severity (Critical/High/Medium/Low), Asset type, Service type
3. Assign finding to team/owner
4. Set due date per SLA
5. Mark remediated when exposure closed
6. Automated verification: Falcon Surface re-scans on schedule; finding auto-closes when exposure gone
### Integration with CrowdStrike Ticketing
- ServiceNow integration: Auto-create incidents for Critical exposures
- Jira integration: Create tickets for dev team-owned exposures
- Falcon Fusion (SOAR): Automate workflows:
- New Critical exposure detected → Create ServiceNow ticket + Slack alert
- Exposure open > 7 days → Escalate to manager notification
- Exposure on asset with active threat detection → PagerDuty alert
## Monitoring and Alerting
### Alert Types
- **New asset discovered:** Internet asset attributed to org appears for first time
- **New exposure on monitored asset:** Open port/service appeared where none was before
- **Exposure change:** SSL cert expired, TLS downgrade, new service
- **Vulnerability on exposed service:** CVE detected on internet-facing technology
- **Shadow IT:** Asset discovered with no corresponding CMDB entry
### Notification Channels
- Falcon console alerts and notification feeds
- Email notifications (configurable per alert type and severity)
- ServiceNow, Jira, Slack via Falcon Fusion automation
- API webhooks for custom SIEM/SOAR integration
## API
Falcon Surface data accessible via CrowdStrike Falcon API:
```python
from falconpy import ExposureManagement
falcon = ExposureManagement(
client_id="YOUR_CLIENT_ID",
client_secret="YOUR_CLIENT_SECRET"
)
# Get attack surface findings
response = falcon.query_external_assets(
filter="severity:'CRITICAL'",
limit=100
)
for asset_id in response['body']['resources']:
details = falcon.get_external_assets(ids=asset_id)
print(details['body']['resources'])
```
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!