CrowdStrike RTR Scanner

Discover agent/skill artifacts via RTR (configurable regex patterns), scan content for prompt-injection phrases, and review malicious skills.

Status

0 Skills discovered
0 Malicious skills
0 Content scans completed
0 Queue depth
0 sha256 cache entries
0 Queue skipped (cache)

Worker: 2026-05-21T21:37:41.236344+00:00 · Endpoints sync:

Scan requests

Saved scan definitions (endpoints, folder, artifact patterns). Use Run to start a scan run.

Request Description Created Hosts Patterns Offline backoff Scan root Latest run
No scan requests yet. Create one below.

Scan runs

Pipeline executions (discovery → queue → content scan).

Run Request Status Created Started Finished Hosts Artifacts Queue Errors Scan root Endpoints
No scan runs yet.

Operation logs

CrowdStrike / RTR failures and timeouts from mvp_logs. scan_run_id is set for scan pipeline steps; List endpoints uses null.

Time Phase Scan run Endpoint Path / queue Message HTTP CrowdStrike body
No operation logs yet.

Skills discovered

Populated when Start scan runs ls -R. Malicious is pending until the scheduler finishes content analysis.

Remote path Endpoint UID sha256 Malicious Discovered at Content scanned
No skills discovered yet. Run Start scan.

Malicious skills

Select at most one row, then display file contents via RTR get.

Remote path Endpoint UID sha256 Flagged at
No malicious skills flagged yet.

Endpoints

No endpoints in database. Click List endpoints to sync from Falcon.