EDR/XDR deployment coverage review and configuration assessment for [REDACTED] across 4,820 endpoints including servers, workstations, and managed laptops. CrowdStrike Falcon deployment completeness and detection configuration reviewed. Engagement ref. ENG-2025-0563.
Plaidnox reviewed the CrowdStrike Falcon EDR/XDR deployment for [REDACTED] across 4,820 managed endpoints. Overall sensor deployment is at 94.2% (4,540 of 4,820 endpoints) . above the industry minimum of 90% but below the recommended 98% for financial services. The 280 uncovered endpoints are predominantly Linux application servers hosting payment-processing APIs and 48 legacy Windows Server 2012 R2 instances that CrowdStrike Sensor 7.x cannot support.
Configuration review identified 3 critical gaps: prevention policies are in detection-only mode for 40% of sensors, lateral movement detection (NTLM relay, Kerberoasting) is not enabled, and no custom IOA rules exist for Parkway-specific attack scenarios.
| Asset Type | Count | Covered | Coverage | Risk |
|---|---|---|---|---|
| Windows Workstations | 3,200 | 3,198 | 99.9% | Good |
| Windows Servers | 480 | 472 | 98.3% | Good |
| Linux App Servers | 740 | 522 | 70.5% | Critical |
| macOS Devices | 352 | 348 | 98.9% | Good |
| Legacy Server 2012 R2 | 48 | 0 | 0% | Critical |
| ID | Finding | Priority |
|---|---|---|
| EP-G01 | 218 Linux app servers hosting payment APIs uncovered . high-value target without EDR visibility | Critical |
| EP-G02 | 48 Windows Server 2012 R2 EOL . no EDR support and no Microsoft security patches since 2023 | Critical |
| EP-G03 | 40% of sensors in detection-only mode . ransomware and process injection not blocked, only alerted | High |
| EP-G04 | Lateral movement detection disabled . Kerberoasting, NTLM relay, Pass-the-Hash will not trigger | High |
| EP-G05 | No custom IOA rules . detection relies solely on Falcon's generic ruleset with no Parkway context | Medium |
| Action | Timeline | Owner |
|---|---|---|
| Deploy Falcon sensor to 218 uncovered Linux payment API servers | Wk 1-3 | IT / Plaidnox |
| Migrate workloads off 48 EOL Windows Server 2012 R2 instances | Wk 2-12 | IT / Management |
| Enable prevention mode for all 40% detection-only sensors via policy update | Wk 1 | IT |
| Enable lateral movement detection (Identity Protection module) | Wk 1-2 | Plaidnox / IT |
| Develop and deploy 12 custom IOA rules for Parkway-specific threat scenarios | Wk 3-6 | Plaidnox |