Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Falcon Surface

ASecurity

Expert agent for CrowdStrike Falcon Surface EASM. Covers internet asset discovery, exposure scoring, CrowdStrike Falcon platform integration, EDR-to-EASM correlation, and attack surface reduction workflows. WHEN: \"Falcon Surface\", \"CrowdStrike EASM\", \"CrowdStrike attack surface\", \"Falcon Surface exposure\", \"external attack surface CrowdStrike\".

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
devopsjavascriptpythonrustgojavaphpapidatabase

Works with

cliapi

Security Analysis

A100/100

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill falcon-surface --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Falcon Surface?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Falcon Surface
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-falcon-surface/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-falcon-surface)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: falcon-surface
description: "Expert agent for CrowdStrike Falcon Surface EASM. Covers internet asset discovery, exposure scoring, CrowdStrike Falcon platform integration, EDR-to-EASM correlation, and attack surface reduction workflows. WHEN: \"Falcon Surface\", \"CrowdStrike EASM\", \"CrowdStrike attack surface\", \"Falcon Surface exposure\", \"external attack surface CrowdStrike\"."
license: MIT
---

# CrowdStrike Falcon Surface

This skill covers CrowdStrike Falcon Surface (formerly Reposify, acquired by CrowdStrike in 2021). It has expertise in Falcon Surface's internet asset discovery, exposure scoring, integration with the CrowdStrike Falcon platform, EDR-to-EASM correlation, and attack surface reduction workflows.

## How to Approach Tasks

1. **Classify** the request:
   - **Asset discovery / onboarding** -- Seed data, initial discovery, attribution
   - **Exposure analysis** -- Exposure scoring, risky services, open ports
   - **CrowdStrike integration** -- Falcon platform correlation, EDR data
   - **Remediation workflow** -- Closing exposures, ticketing integration
   - **Monitoring / alerts** -- New asset alerts, exposure change notifications

2. **Apply CrowdStrike ecosystem context** -- Falcon Surface's key differentiator is correlation with CrowdStrike endpoint data. Organizations already using Falcon EDR get additional context: "This internet-exposed server is ALSO running outdated CrowdStrike sensor version and has active threat detections."

## Product Overview

**Falcon Surface:** CrowdStrike's EASM module within the Falcon platform.

**Key differentiators:**
- Native integration with Falcon platform (same console as EDR, threat intelligence, exposure management)
- Correlation of EASM findings with endpoint sensor data (EDR + ASM convergence)
- CrowdStrike threat intelligence enrichment -- known attack patterns against exposed technologies
- Falcon Exposure Management: broader than ASM alone, maps EASM to internal exposure

**Deployment:** SaaS, no infrastructure to deploy. Onboard via domain/IP seeds.

## Asset Discovery

### Onboarding / Seed Configuration

1. Log in to Falcon console
2. Navigate to: Exposure Management > Attack Surface Management
3. Add seeds:
   - Primary domains (company.com, company.net)
   - IP ranges (owned IP blocks, cloud-assigned ranges)
   - Company names and subsidiaries
   - Acquisition entities

### Discovery Process

Falcon Surface uses:
- **Certificate Transparency Logs:** Discovers subdomains via crt.sh and similar
- **DNS enumeration:** Subdomain brute force, zone transfers, passive DNS
- **Shodan/Censys data correlation:** Internet-wide scan data
- **Web crawling:** Links, JavaScript endpoints, sitemap exploration
- **WHOIS/BGP:** IP ownership attribution
- **CrowdStrike intel enrichment:** Threat actors known to target discovered technologies

### Attribution Confidence

Each discovered asset is scored for attribution confidence:
- **Confirmed:** Directly tied to seed domain/IP (same certificate, direct DNS)
- **Probable:** Strong indicators (subdomain pattern, certificate with company name)
- **Possible:** Indirect link (technology fingerprint, content analysis)

Review "Possible" assets before accepting into monitored inventory.

## Exposure Analysis

### Exposure Score

Each asset receives an exposure score based on:
- Services running (RDP, SSH, Telnet, database ports -- high risk if exposed)
- Software versions (is this running EOL software?)
- TLS/SSL configuration (expired cert, weak cipher, self-signed)
- CVEs on detected software/versions
- CrowdStrike threat intelligence: Is this technology actively targeted?

### High-Risk Exposure Categories

| Exposure Type | Risk | Action |
|---|---|---|
| RDP exposed (port 3389) | Critical | Close immediately or put behind VPN/Bastion |
| SSH exposed (port 22) | High | Restrict to known IPs; enforce key auth |
| Database ports exposed (3306, 5432, 1433, 27017) | Critical | Move behind firewall |
| Telnet/FTP (23/21) | Critical | Disable; replace with SSH/SFTP |
| Expired SSL certificates | High | Renew immediately |
| Self-signed certificates | Medium | Replace with trusted CA cert |
| Admin panels exposed (phpmyadmin, Jenkins, etc.) | Critical | Restrict or disable |
| S3 buckets publicly accessible | High-Critical | Enable Block Public Access |
| Development environments | High | Shut down or restrict to VPN |

## CrowdStrike Falcon Platform Integration

### EDR + ASM Correlation

Falcon Surface correlates with Falcon EDR data:

**Correlation use cases:**
- "This internet-exposed host: Does it have a Falcon sensor? What version?"
- "Host A is externally exposed AND has active detections in Falcon Insight"
- "This exposed web server has a critical finding in Falcon Discover (unmanaged asset)"
- "Alert: New external exposure detected on host that has a high-severity active detection"

**Falcon Exposure Management:**
The broader exposure management context in CrowdStrike:
- External exposure (Falcon Surface / EASM)
- Internal exposure (CVEs on Falcon-protected endpoints)
- Identity exposure (compromised credentials, Falcon Identity Protection)
- Combines for holistic "What is our actual exposure to a real attacker?"

### Threat Intelligence Enrichment

CrowdStrike Adversary Intelligence enriches EASM findings:
- "Subdomain dev.company.com is running Apache 2.4.49 -- CVE-2021-41773 (actively exploited by eCrime actors)"
- Known threat actor TTPs mapped to discovered technologies
- "4 active threat groups are known to exploit exposed Jenkins instances"

## Remediation Workflows

### Remediation Tracking in Falcon Surface

1. Navigate to: Exposure Management > Attack Surface Management > Findings
2. Filter by: Severity (Critical/High/Medium/Low), Asset type, Service type
3. Assign finding to team/owner
4. Set due date per SLA
5. Mark remediated when exposure closed
6. Automated verification: Falcon Surface re-scans on schedule; finding auto-closes when exposure gone

### Integration with CrowdStrike Ticketing

- ServiceNow integration: Auto-create incidents for Critical exposures
- Jira integration: Create tickets for dev team-owned exposures
- Falcon Fusion (SOAR): Automate workflows:
  - New Critical exposure detected → Create ServiceNow ticket + Slack alert
  - Exposure open > 7 days → Escalate to manager notification
  - Exposure on asset with active threat detection → PagerDuty alert

## Monitoring and Alerting

### Alert Types

- **New asset discovered:** Internet asset attributed to org appears for first time
- **New exposure on monitored asset:** Open port/service appeared where none was before
- **Exposure change:** SSL cert expired, TLS downgrade, new service
- **Vulnerability on exposed service:** CVE detected on internet-facing technology
- **Shadow IT:** Asset discovered with no corresponding CMDB entry

### Notification Channels

- Falcon console alerts and notification feeds
- Email notifications (configurable per alert type and severity)
- ServiceNow, Jira, Slack via Falcon Fusion automation
- API webhooks for custom SIEM/SOAR integration

## API

Falcon Surface data accessible via CrowdStrike Falcon API:

```python
from falconpy import ExposureManagement

falcon = ExposureManagement(
    client_id="YOUR_CLIENT_ID",
    client_secret="YOUR_CLIENT_SECRET"
)

# Get attack surface findings
response = falcon.query_external_assets(
    filter="severity:'CRITICAL'",
    limit=100
)

for asset_id in response['body']['resources']:
    details = falcon.get_external_assets(ids=asset_id)
    print(details['body']['resources'])
```

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

968770 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →