Vulnerability Defense

Lab Overview

In this lab, you will use the pre-configured Windows 11 device to view vulnerabilities in multiple ways, prioritize views to understand criticality, and then remediate several apps.   

The preconfigured Windows 11 will be used for this lab because it is likely that the Windows Server device is still enrolling, installing apps, and syncing with CrowdStrike.  

Objectives

By completing this lab, you will be able to: 

  • Validate functionality of Windows devices and ensure that the devices are syncing with CrowdStrike. 
  • Validate CrowdStrike integration. 
  • View existing vulnerabilities by device, by vulnerability, and by product. 
  • Determine criticality of vulnerabilities based on filters. 
  • Step through remediation of several apps. 

Tasks in this Lab

Task 1 — Validate status of Windows 11 and Windows Server devices 

Task 2 -- Validate pre-configured CrowdStrike integration 

Task 3 — Vulnerability Defense familiarization 

Task 4 – Vulnerability remediation 

Task 1 - Device validation

Based on the configuration steps from the previous lab, Windows Server will first enroll into Workspace ONE, then Falcon Sensor and Notepad++ will be installed.  Windows Server validation will take a few minutes and may still be in progress when executing Step 2. 

We will first validate the Windows 11 device status.

Step 1 - Win11 device

  1. In the top left corner of the Workspace ONE UEM console, click the down arrow in the lilac box, and validate that you are in the parent OG. 
  2. Click Devices > Devices and click the Windows 11 device that appears on the list.  Note that this device was pre-enrolled, which is why it appears so quickly. 
  3. Click the Apps tab in the middle of the screen.  Under the Managed Apps tab, you should see Notepad++, PuTTY, 7-Zip, and Falcon Sensor.   
  4. If these apps do not appear on the list, go to the Summary tab and note the last Intelligent Hub check-in.  Log into the Win11 device and check whether the four applications have been installed. Right click the Intelligent Hub icon and select Sync to force Workspace ONE synchronization. 
  5. Optionally, on the Windows 11 device, you can manually validate that Falcon Sensor is running by entering the following commands from c:\Program Files\CrowdStrike 
  • sc.exe query csagent 
  • sc.exe sc query csfalconservice 

Both commands should show State 4, which indicates running. 

Step 2 - Windows Server device

Note: It’s possible that the Windows Server device has not yet completed enrollment and application installation.  If that is the case, please complete this validation after the Vulnerability Defense exercises. 

  1. In the upper left corner, click the downward arrow that appears with your parent OG  and ensure that the account role shows as the ServerOG, which is the child OG that you created previously.  
  2. Go to Devices > Devices and view the Windows Server device that you enrolled previously.  Note that Windows Server devices are identified by a server icon.  On the right side of the screen, validate that the Enrollment column shows a green check box. 
  3. Click the Windows Server device and observe the device information.  Click the Apps tab and validate that Falcon Sensor and Notepad++ appear under the Managed Apps tab.
  4. If the device has enrolled but the apps do not appear yet, log into the Windows Server device and validate whether Falcon Sensor and Notepad++ have been installed.  If so, right click the Intelligent Hub icon, then select Sync to force Workspace ONE synchronization.  If enrollment or app deployment has not yet been completed, you can still proceed to the next steps and check for validation again in a few minutes. 
  5. You can optionally manually validate that Falcon Sensor is running by entering the following commands from c:\Program Files\CrowdStrike 
  6. sc.exe query csagent 
  7. sc.exe. query csfalconservice 
  8. Both commands should show State 4, which indicates running. 
  9. Alternatively, click the ^ (show hidden icons) chevron in the Windows taskbar notification area — visible at the right of the taskbar in your image. 
  10. Hover the cursor over the CrowdStrike Falcon shield icon 
  11. The tooltip should read "CrowdStrike Falcon Sensor: Running" — that's the confirmation. 

Task 2: Validate pre-configured CrowdStrike integration

CrowdStrike Falcon must be integrated within the Workspace ONE UEM console in order to feed vulnerability data.  Once customer-specific data is provided within three fields, integration generally takes several hours to complete.  To save time, CrowdStrike integration has already been pre-configured for you at the global level.   

Step 1 – Validate CrowdStrike integration 

  1. In the top left corner of the Workspace ONE UEM console, click the down arrow in the lilac box, and validate that you are in the parent OG. 
  2. To validate the configuration, go to Groups & Settings > Configurations and enter Vulnerability Defense in the search bar or scroll down to Vulnerability Defense on the list and click it. 
  3. This is where you would configure integration.  In this lab, you cannot view or modify the CrowdStrike integration; you will see a yellow bar indicating that the provider configurations cannot be viewed at this OG level.   

Note: The settings page you’ve opened is scoped to a different OG than the one currently selected,  Provider configurations are defined and stored at a specific OG and are not viewable from a child OG that only inherits them. 

Task 3: Vulnerability Defense familiarization

Vulnerability Defense presents vulnerability data in an easy-to-digest dashboard.  By using filters and drilling down, pertinent vulnerabilities are surfaced. 

Because your Windows Server device is likely not yet be fully integrated with CrowdStrike, all exercises in this lab are based on the preconfigured Windows 11 device. 

Note that the following key data points are presented: 

  • Vulnerability ID: This is the CVE assigned to the vulnerability. 
  • ExPRT.AI Rating: This is the rating provided via the CrowdStrike feed. 
  • Vulnerability Type: Operating System or application 
  • Known Exploited Status: This is from the CISA KEV feed. 
  • CVSS Rating: This is the quantified severity based on an extensive algorithm. 

Step 1 – Become familiar with the vulnerability data by vulnerability and by product 

Vulnerability data can be viewed in three ways: by device, by vulnerability, and by product.   

  1. Go to Devices > Devices and select the Windows 11 devices as identified by the Windows logo. 
  2. In the List View screen, select the Vulnerabilities tab and view the data presented. 
  3. On the right side of the screen, click Filters and select one or more filters and click Apply at the bottom of the screen.  View the presented data. 
  4. Go to Security > Vulnerability Defense to open Vulnerability Defense.  Note the Total Vulnerabilities and scroll through the list of individual vulnerabilities.  Note the number of vulnerabilities listed. 
  5. Click Filters on the right side of the screen and expand each of the options.  Under CVSS Rating, select Critical and High and then Apply.  You may also wish to select other filters.  Note that the resulting number of filtered vulnerabilities is a subset of the total vulnerabilities.  Depending on your company security mandates, it is likely that business and technical decisions will mandate which vulnerabilities will be remediated. 
  6. Click the Vulnerable Products tab on the right half of the screen.  Note the Total Vulnerable Products and scroll through the list of vendors and products.  Click Filters on the right side of the screen and expand each of the options.  Under Product Type, select Application and then Apply. 
  7. Click on 7-Zip and then click x vulnerability.  Read the information presented.  Click the back button to return to the Vulnerability Defense dashboard. 

Vulnerability remediation

As you will see in the following steps, remediating vulnerabilities is straightforward. 

Step 1 – Remediate Notepad++ on Win11 device 

  1. Click Notepad++ and note the number of vulnerabilities presented.   
  2. Click the presented CVE.  Read through the Vulnerability Summary.  Click the NVD link.  Note that the concise summary presented within Vulnerability Defense is shorter than the NVD information. 
  3. Click the radio button next to Notepad++ and note that the Set Up Remediation button turns purple and a recommendation appears to upgrade the application. 
  4. Click Set Up Remediation.   
  5. Review the options presented in the Select Resolving Product screen and find the option that shows the App Sources as Enterprise App Repository.  Select Import. 
  6. When the Enterprise App Repository opens, select Notepad++.   
  7. Select the most recent version and ensure that the architecture is x64, installer type is MSI, and language is en-US.  Click Next. 
  8. Within the UEM Application Configuration screen, scroll down to Automatic Updates and enable.  Also enable Inherit Application Assignments.  Change Update Cadence to Weekly, and set to Every 1 Weeks on Sunday.  Note that Windows Servers are particularly sensitive to changes, and in this example, Sundays had been deemed the day of week for maintenance.  Click Save. 
  9. After the Summary screen completes, the Distribution screen is presented. 
  10. Designate the Assignment Name as Notepad++ EAR Distribution and create a description if desired.  
  11. Designate a name, in this case, Notepad++ Assignment. 
  12. Towards the bottom of the screen, note the two options to Keep Application on Device.  View the related informational verbiage, which shows that the default for Windows Server differs from Windows Desktops.  For Windows Server, the app is retained, whereas for Windows Desktop, it is not.   
  13. Within Deployment Method, select Phased Deployment. 
  14. Designate the Test, Prod, and Win11 Smart Groups that were created earlier and click Next. 
  15. Within Phase Name, designate First Phase. 
  16. Within Phase Target, select the Win11 and Test Smart Groups. 
  17. Select the Manual Progression dropdown and select Automatic Progression. 
  18. Within the Install Rate entry, enter 45%.  Disable Wait Time by clicking on the blue checkbox on the right.  It should turn black and show an X. 
  19. Click Save. 
  20. Click Create. 

Task: View Vulnerabilities by device

Devices in child OGs present vulnerabilities in the same way as parent OGs because Vulnerability Defense is licensed based on all devices.  In this task, you will view per-device vulnerabilities for devices in a parent OG and in a child OG. 

Step 1 – View Windows Server vulnerabilities in child OG. 

  1. In the top left corner of the Workspace ONE UEM console, click the down arrow in the lilac box, and change to the Server OG. 
  2. Go to Devices > Devices and select the Windows Server device. 
  3. Select the Vulnerabilities tab.  Note that the 7-Zip vulnerability that you previously recorded does not appear.  This is because 7-Zip is not installed on the Window Server device. 
  4. Note: if your Windows Server device has not yet completed enrollment, app installation, and CrowdStrike integration, these steps may not be possible. 

Step 2 – View Windows 11 vulnerabilities in parent OG and remediate. 

  1. In the top left corner of the Workspace ONE UEM console, click the down arrow in the lilac box, and change to the parent OG. 
  2. Go to Devices > Devices and select the Win11 device. 
  3. Select the Vulnerabilities tab.   
  4. Find the 7-Zip vulnerability that you encountered earlier, CVE-xxx.  Select it and review the vulnerability summary. 
  5. Click the radio button next to 7-Zip and note that the Set Up Remediation button turns purple and a recommendation appears to upgrade the application. 
  6. Click Set Up Remediation.   
  7. Review the options presented in the Select Resolving Product screen and find the option that shows the App Sources as Enterprise App Repository.  Select Import. 
  8. When the Enterprise App Repository opens, select 7-Zip.   
  9. Select the most recent version and ensure that the architecture is x64, installer type is MSI, and language is en-US.  Click Next. 
  10. Within the UEM Application Configuration screen, scroll down to Automatic Updates and enable.  Also enable Inherit Application Assignments.   
  11. Change Update Cadence to Daily.  Because 7-Zip is only installed on desktops, there are no concerns about critical service interruptions.  Click Save. 
  12. After the Summary screen completes, the Distribution screen is presented. 
  13. Designate the Assignment Name as 7-Zip EAR Distribution and create a description if desired.  
  14. Designate a name, in this case, 7-Zip Assignment. 
  15. Towards the bottom of the screen, note the two options to Keep Application on Device.  Although the default would remove the app for Windows Desktop devices, you will explicitly configure these settings as Disabled. 
  16. Within Deployment Method, select Assignment Groups. 
  17. Designate the Win11 Smart Group that was created earlier and click Next. 
  18. Click Create. 
  19. If sufficient time, repeat these steps to remediate PuTTY. 

Task: Validate Remediation

Vulnerabilities have now been remediated.  Because the lab only contains two devices, remediation should complete within a few minutes, but it is possible that it will take longer. 

Step 1 – Check dashboard for vulnerability status. 

  1. In the top left corner of the Workspace ONE UEM console, click the down arrow in the lilac box, and change to the parent OG. 
  2. The Notepad++ remediation should be complete.  To verify, go to Security > Vulnerability Defense > and enter CVE-2025-15556 in the Search vulnerability identifier box to find the status of the Notepad++ vulnerability.  If the vulnerability has been remediated, it should disappear from the screen.  However, it is possible that this remediation is still in progress, so it may show as 1 or possibly 2 impacted devices.  Please recheck in a few minutes.  
  3. Likewise, the 7-Zip remediation should be complete.  To verify, go to Security > Vulnerability Defense > and enter CVE-xxx in the Search vulnerability identifier box to find the status of the 7-Zip vulnerability.  If the vulnerability has been remediated, it should disappear from the screen.  However, it is possible that this remediation is still in progress, so it may still appear and show as 1 impacted device.  Please recheck it in a few minutes.  If you had sufficient time to remediate PuTTY, repeat this step. 

This completes the Windows Server/Vulnerability Defense lab.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.