SOC 2 CrowdStrike Falcon CC6.1CC7.3CC7.4

SOC 2 Evidence from CrowdStrike Falcon

Why this matters for SOC 2

The security trust services criteria are, at their core, asking whether you can detect a compromise and whether you do something about it when you find one. Endpoint detection and response telemetry from CrowdStrike Falcon is some of the strongest evidence for both, because it is generated continuously and independently of whether anyone was watching the console. A SuspiciousActivity on a credential-theft tool, or a DetectionSummaryEvent for a Cobalt Strike beacon, is the kind of concrete finding an examiner wants to see paired with a documented response.

What evidence Falcon telemetry provides

  • Evidence that logical access controls are monitored and enforced — a credential-dumping detection is a direct challenge to CC6.1 (Logical and Physical Access Controls)
  • Documented threat evaluation for high-severity endpoint findings, supporting CC7.3 (Threat and Vulnerability Evaluation)
  • A record of incident response activation for critical detections, supporting CC7.4 (Incident Response)
  • A per-finding severity score and MITRE ATT&CK technique mapping that shows triage was consistent and defensible, not ad hoc

How LogTriage maps this to SOC 2 controls

The compliance mapper takes each finding’s MITRE tactic, severity, and attack pattern and looks up the matching controls. A credential-access finding — LSASS access or a Mimikatz execution, both of which LogTriage floors to a high risk score via its host-attack signatures — maps to CC6.1. A high-severity finding maps to CC7.3, and a critical-severity finding (score in the critical band, or any single confirmed-malicious threat-intelligence verdict) maps to CC7.4, with the report’s remediation steps doubling as response-plan documentation. Because the mapping is static and runs on every report, the same finding always produces the same control citation.

Evidence checklist

  • Maintain Falcon sensor coverage records — a coverage gap is itself an access-monitoring finding
  • Retain the LogTriage report (review + detection evidence) alongside the raw FDR export (completeness evidence) for each cited finding
  • Document the severity-scoring methodology so the CC7.3 threat-evaluation evidence is reproducible
  • For any critical finding, retain the full incident timeline from detection through containment as CC7.4 evidence
  • Confirm access reviews and least-privilege enforcement for any account implicated in a credential-access finding

Frequently Asked Questions

Which SOC 2 Common Criteria does CrowdStrike telemetry map to?
It depends on what the telemetry shows. LogTriage's compliance mapper keys on the finding's MITRE tactic and severity: a credential-access finding (for example LSASS dumping or Mimikatz) maps to CC6.1 (Logical and Physical Access Controls), a high-severity finding maps to CC7.3 (Threat and Vulnerability Evaluation), and a critical-severity finding maps to CC7.4 (Incident Response). The mapping is deterministic and appears on every report.
Can endpoint telemetry alone satisfy a SOC 2 audit?
No single source can. CrowdStrike Falcon is strong evidence for the monitoring and incident-response side of the security trust criteria, but a SOC 2 examination also wants access reviews, change management, vendor management, and availability evidence that endpoint logs do not contain. Falcon telemetry is one well-supported pillar, not the whole package.
How does a rule-based LogTriage report still produce SOC 2 evidence?
The compliance mapping runs independently of whether Claude was invoked. Even a low-signal analysis that never calls the AI model still carries the correct control mapping derived from the detected tactic and severity, so the evidence note is present on every report regardless of routing.
What retention should we apply to Falcon evidence for SOC 2?
At least the audit period, typically 12 months, plus enough prior history to establish a behavioral baseline. Retain the raw FDR exports or their storage references alongside the LogTriage reports — the report demonstrates review and detection, the raw telemetry demonstrates completeness and availability. Auditors generally want both.

Related Resources

See your compliance mapping generated automatically

Every LogTriage report includes a deterministic compliance mapping — SOC 2, PCI DSS, HIPAA, NIST CSF, and ISO 27001 — stamped on every report, AI-generated or rule-based.