diff --git a/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml b/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml index dfa8705551..c69af8428d 100644 --- a/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml +++ b/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml @@ -2143,4 +2143,22 @@ spec: 1 - +--- +apiVersion: v1 +kind: policy +spec: + name: CrowdStrike Falcon System Extension enabled and activated (macOS) + query: | + SELECT 1 + WHERE (EXISTS (SELECT 1 FROM system_extensions WHERE identifier = 'com.crowdstrike.falcon.Agent')) + AND EXISTS (SELECT 1 FROM system_extensions WHERE state = 'activated_enabled'); + bash: systemextensionsctl list | grep 'falcon' | grep 'activated enabled' + description: Checks to make sure that the CrowdStrike System Extension is enabled and activated on macOS devices. + resolution: "To activate the CrowdStrike Falcon System Extension, on the failing device, run the following command in the Terminal app: sudo /Applications/Falcon.app/Contents/Resources/falconctl load" + tags: compliance, hardening, critical + platform: darwin + contributors: spalmesano0 + script: | + #!/bin/sh + + /Applications/Falcon.app/Contents/Resources/falconctl load