Identify Linux Systems Vulnerable to CVE-2025-1146 with Last Logged-On User Information
The query below will look for Linux systems (Linux, K8, Containers) that need to be updated against CVE-2025-1146. The query is based on the event OsVersionInfo which is generated every 24-hours, at sensor start, or at sensor update. It attempts to merge in LogonType 2 and 10 to determine the last logged on user.
CQL · Falcon Next-Gen SIEMCopy query
Loading query…CVE-2025-1146_System_Scoping.yml
CrowdStrike
Detection
Endpoint
Insight
