Falcon Remediation Process Loads Attacker DLL During Quarantine Action
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
Microsoft Sentinel (KQL)

