All templates

Automated CrowdStrike Sensor Coverage Audits

Every Monday, WebRun opens CrowdStrike Falcon host management, lists every host whose sensor has not checked in recently or is running an old version, writes the findings into a Notion coverage register with the change since last week, and opens a Trello card for each machine that needs a person to act.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 CrowdStrike audit host sensor coverage
2 Notion update the coverage register
3 Trello raise a card for each host to fix
In short

How do I find endpoints where the security sensor has stopped reporting?

WebRun audits your CrowdStrike Falcon coverage every Monday. It lists hosts whose sensor has stopped checking in or is running an outdated version, updates a Notion register with the week on week change, and opens a Trello card for each machine, so unprotected endpoints get fixed rather than forgotten.

  • Unprotected machines surface in days instead of at audit time
  • Every stale host gets a tracked, assigned card
  • Repeat offenders stop hiding inside a long host list

Built for security teams · IT operations · managed service providers · compliance managers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens falcon.crowdstrike.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    CrowdStrike - audit host sensor coverage
    crowdstrike.com
    WebRun in CrowdStrike: audit host sensor coverage
    WebRun opens CrowdStrike to audit host sensor coverage.
    • Open Falcon and go to host management
    • List hosts by last seen and flag anything that has not checked in for longer than your threshold
    • Record the sensor version on each host and mark versions behind your current standard
    • Note the host name, operating system, owner group, and last seen time for every flagged machine

    Done when Every stale or out-of-date host is listed with its sensor version and last check-in.

  3. 2
    Notion - update the coverage register
    notion.so
    WebRun in Notion: update the coverage register
    WebRun opens Notion to update the coverage register.
    • Open the sensor coverage database
    • Add or update a row per flagged host with the sensor version, last seen time, and owner group
    • Mark hosts that were flagged last week and are still flagged as repeat offenders
    • Close out rows for hosts that have come back online

    Done when The Notion register matches this week's Falcon host list.

  4. 3
    Trello - raise a card for each host to fix
    trello.com
    WebRun in Trello: raise a card for each host to fix
    WebRun opens Trello to raise a card for each host to fix.
    • Open the IT remediation board
    • Create a card for each newly flagged host with the machine name, the problem, and a link to the Notion row
    • Put repeat offenders at the top of the list and label them
    • Do not close or move existing cards. A person decides when a machine is fixed

    Done when Every host needing action has a card on the remediation board.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
falcon.crowdstrike.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Sensor coverage register · Notion
OutputWhat each run produces - A weekly coverage audit: hosts with stale check-ins, hosts on old sensor versions, repeat offenders, and the cards raised for each.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change anything in Falcon?

No. WebRun reads your CrowdStrike host list and never contains a host, uninstalls a sensor, changes a policy, or deletes a record. Every action it takes happens in Notion and Trello.

Can it uninstall or reinstall a sensor for me?

No, and it should not. WebRun raises a Trello card naming the machine and the problem so an engineer decides what to do, because reinstalling a sensor on the wrong host takes a machine offline.

How does it decide a host is stale?

By the last seen time in Falcon against the threshold you set, commonly seven days. Anything quieter than that, plus anything on a sensor version behind your standard, is flagged.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.