Skip to content
Back to skills

Falcon Surface

ASecurity

Expert agent for CrowdStrike Falcon Surface EASM. Covers internet asset discovery, exposure scoring, CrowdStrike Falcon platform integration, EDR-to-EASM correlation, and attack surface reduction workflows. WHEN: \"Falcon Surface\", \"CrowdStrike EASM\", \"CrowdStrike attack surface\", \"Falcon Surface exposure\", \"external attack surface CrowdStrike\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopsjavascriptpythonrustgojavaphpapidatabase

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill falcon-surface --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Falcon Surface?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Falcon Surface
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-falcon-surface/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-falcon-surface)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: falcon-surface
description: "Expert agent for CrowdStrike Falcon Surface EASM. Covers internet asset discovery, exposure scoring, CrowdStrike Falcon platform integration, EDR-to-EASM correlation, and attack surface reduction workflows. WHEN: \"Falcon Surface\", \"CrowdStrike EASM\", \"CrowdStrike attack surface\", \"Falcon Surface exposure\", \"external attack surface CrowdStrike\"."
license: MIT
---

# CrowdStrike Falcon Surface

This skill covers CrowdStrike Falcon Surface (formerly Reposify, acquired by CrowdStrike in 2021). It has expertise in Falcon Surface's internet asset discovery, exposure scoring, integration with the CrowdStrike Falcon platform, EDR-to-EASM correlation, and attack surface reduction workflows.

## How to Approach Tasks

1. **Classify** the request:
   - **Asset discovery / onboarding** -- Seed data, initial discovery, attribution
   - **Exposure analysis** -- Exposure scoring, risky services, open ports
   - **CrowdStrike integration** -- Falcon platform correlation, EDR data
   - **Remediation workflow** -- Closing exposures, ticketing integration
   - **Monitoring / alerts** -- New asset alerts, exposure change notifications

2. **Apply CrowdStrike ecosystem context** -- Falcon Surface's key differentiator is correlation with CrowdStrike endpoint data. Organizations already using Falcon EDR get additional context: "This internet-exposed server is ALSO running outdated CrowdStrike sensor version and has active threat detections."

## Product Overview

**Falcon Surface:** CrowdStrike's EASM module within the Falcon platform.

**Key differentiators:**
- Native integration with Falcon platform (same console as EDR, threat intelligence, exposure management)
- Correlation of EASM findings with endpoint sensor data (EDR + ASM convergence)
- CrowdStrike threat intelligence enrichment -- known attack patterns against exposed technologies
- Falcon Exposure Management: broader than ASM alone, maps EASM to internal exposure

**Deployment:** SaaS, no infrastructure to deploy. Onboard via domain/IP seeds.

## Asset Discovery

### Onboarding / Seed Configuration

1. Log in to Falcon console
2. Navigate to: Exposure Management > Attack Surface Management
3. Add seeds:
   - Primary domains (company.com, company.net)
   - IP ranges (owned IP blocks, cloud-assigned ranges)
   - Company names and subsidiaries
   - Acquisition entities

### Discovery Process

Falcon Surface uses:
- **Certificate Transparency Logs:** Discovers subdomains via crt.sh and similar
- **DNS enumeration:** Subdomain brute force, zone transfers, passive DNS
- **Shodan/Censys data correlation:** Internet-wide scan data
- **Web crawling:** Links, JavaScript endpoints, sitemap exploration
- **WHOIS/BGP:** IP ownership attribution
- **CrowdStrike intel enrichment:** Threat actors known to target discovered technologies

### Attribution Confidence

Each discovered asset is scored for attribution confidence:
- **Confirmed:** Directly tied to seed domain/IP (same certificate, direct DNS)
- **Probable:** Strong indicators (subdomain pattern, certificate with company name)
- **Possible:** Indirect link (technology fingerprint, content analysis)

Review "Possible" assets before accepting into monitored inventory.

## Exposure Analysis

### Exposure Score

Each asset receives an exposure score based on:
- Services running (RDP, SSH, Telnet, database ports -- high risk if exposed)
- Software versions (is this running EOL software?)
- TLS/SSL configuration (expired cert, weak cipher, self-signed)
- CVEs on detected software/versions
- CrowdStrike threat intelligence: Is this technology actively targeted?

### High-Risk Exposure Categories

| Exposure Type | Risk | Action |
|---|---|---|
| RDP exposed (port 3389) | Critical | Close immediately or put behind VPN/Bastion |
| SSH exposed (port 22) | High | Restrict to known IPs; enforce key auth |
| Database ports exposed (3306, 5432, 1433, 27017) | Critical | Move behind firewall |
| Telnet/FTP (23/21) | Critical | Disable; replace with SSH/SFTP |
| Expired SSL certificates | High | Renew immediately |
| Self-signed certificates | Medium | Replace with trusted CA cert |
| Admin panels exposed (phpmyadmin, Jenkins, etc.) | Critical | Restrict or disable |
| S3 buckets publicly accessible | High-Critical | Enable Block Public Access |
| Development environments | High | Shut down or restrict to VPN |

## CrowdStrike Falcon Platform Integration

### EDR + ASM Correlation

Falcon Surface correlates with Falcon EDR data:

**Correlation use cases:**
- "This internet-exposed host: Does it have a Falcon sensor? What version?"
- "Host A is externally exposed AND has active detections in Falcon Insight"
- "This exposed web server has a critical finding in Falcon Discover (unmanaged asset)"
- "Alert: New external exposure detected on host that has a high-severity active detection"

**Falcon Exposure Management:**
The broader exposure management context in CrowdStrike:
- External exposure (Falcon Surface / EASM)
- Internal exposure (CVEs on Falcon-protected endpoints)
- Identity exposure (compromised credentials, Falcon Identity Protection)
- Combines for holistic "What is our actual exposure to a real attacker?"

### Threat Intelligence Enrichment

CrowdStrike Adversary Intelligence enriches EASM findings:
- "Subdomain dev.company.com is running Apache 2.4.49 -- CVE-2021-41773 (actively exploited by eCrime actors)"
- Known threat actor TTPs mapped to discovered technologies
- "4 active threat groups are known to exploit exposed Jenkins instances"

## Remediation Workflows

### Remediation Tracking in Falcon Surface

1. Navigate to: Exposure Management > Attack Surface Management > Findings
2. Filter by: Severity (Critical/High/Medium/Low), Asset type, Service type
3. Assign finding to team/owner
4. Set due date per SLA
5. Mark remediated when exposure closed
6. Automated verification: Falcon Surface re-scans on schedule; finding auto-closes when exposure gone

### Integration with CrowdStrike Ticketing

- ServiceNow integration: Auto-create incidents for Critical exposures
- Jira integration: Create tickets for dev team-owned exposures
- Falcon Fusion (SOAR): Automate workflows:
  - New Critical exposure detected → Create ServiceNow ticket + Slack alert
  - Exposure open > 7 days → Escalate to manager notification
  - Exposure on asset with active threat detection → PagerDuty alert

## Monitoring and Alerting

### Alert Types

- **New asset discovered:** Internet asset attributed to org appears for first time
- **New exposure on monitored asset:** Open port/service appeared where none was before
- **Exposure change:** SSL cert expired, TLS downgrade, new service
- **Vulnerability on exposed service:** CVE detected on internet-facing technology
- **Shadow IT:** Asset discovered with no corresponding CMDB entry

### Notification Channels

- Falcon console alerts and notification feeds
- Email notifications (configurable per alert type and severity)
- ServiceNow, Jira, Slack via Falcon Fusion automation
- API webhooks for custom SIEM/SOAR integration

## API

Falcon Surface data accessible via CrowdStrike Falcon API:

```python
from falconpy import ExposureManagement

falcon = ExposureManagement(
    client_id="YOUR_CLIENT_ID",
    client_secret="YOUR_CLIENT_SECRET"
)

# Get attack surface findings
response = falcon.query_external_assets(
    filter="severity:'CRITICAL'",
    limit=100
)

for asset_id in response['body']['resources']:
    details = falcon.get_external_assets(ids=asset_id)
    print(details['body']['resources'])
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…