High

CA-26-034: FalconFlank Public PoC Targets CrowdStrike Falcon Office Macro Remediation

By Adversary Tactics and Intelligence Team

Estimated Reading Time: 7 minutes

CrowdStrike Falcon, Falcon Sensor, Windows, Local Privilege Escalation, Public PoC, Office Macro Remediation, FalconFlank

Source Material: CrowdStrike Tech Alert, CrowdStrike Release Notes, FalconFlank GitHub PoC | Technology: CrowdStrike Falcon Sensor for Windows with Microsoft Office File Suspicious Macro Removal Enabled  | Targeted Industries: Opportunistic/Agnostic

Executive Summary

A public proof-of-concept (PoC) dubbed FalconFlank has been publicly shared and claims local privilege escalation against CrowdStrike Falcon Sensor for Windows by abusing the Microsoft Office malicious macro remediation workflow. CrowdStrike published a September 3, 2026 customer tech alert stating it is actively investigating the researcher claim and that Counter Adversary Operations and OverWatch are hunting for signs of exploitation.

CrowdStrike has since advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows prevention policy setting while the investigation continues. CrowdStrike states that prevention remains available through Cloud Anti-malware for Microsoft Office Files when prevention policy settings are otherwise configured according to best practices.

Deepwatch recommends that customers treat FalconFlank as a critical defense directive because a public PoC exists and the affected workflow operates in a privileged endpoint security context. The PoC does not provide initial access by itself; an attacker would first need local code execution or user-level access on a vulnerable Windows host.

Threat Overview and Strategic Impact

FalconFlank was published on GitHub on September 3, 2026. The repository describes the issue as a zero-day privilege escalation affecting CrowdStrike Falcon Sensor when Office malicious macro remediation is enabled. The author claims the PoC works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 Optimal Protection and the Microsoft Office File Suspicious Macro Removal setting enabled.

The CrowdStrike release notes for Cloud ML Detection and Remediation of Malicious Office Macros explain that the feature analyzes macros embedded in Office files when they are written to disk. When prevention is enabled, Falcon can quarantine infected Office files and optionally replace them with remediated files in the same path. The FalconFlank claim centers on that privileged remediation path. Public reporting describes the issue as a local privilege escalation claim and notes that CrowdStrike had not publicly confirmed a CVE, patch, or full root-cause advisory at the time of publication.

The strategic risk is most relevant after an adversary has already obtained local execution on a Falcon-protected Windows host. Successful exploitation could convert a low-privileged foothold into SYSTEM-level execution, weakening endpoint containment and increasing the likelihood of credential theft, tampering, persistence, and lateral movement. Due to the fact that endpoint security agents are privileged and broadly deployed, customers should prioritize mitigation across Windows prevention policies even where exploitation has not been observed internally.

Security Hardening and Recommendations

Immediately review Windows prevention policies and disable the Microsoft Office File Suspicious Macro Removal setting in Next-gen antivirus settings under Clean infected Microsoft Office files, following CrowdStrike’s September 3, 2026 tech alert. Maintain other recommended prevention controls, including Detect on Write, Quarantine on Write, and Cloud Anti-malware for Microsoft Office Files prevention where applicable.

Prioritize policy validation for Windows 11 and Windows Server fleets that run Falcon Sensor and process Microsoft Office documents. Confirm whether the setting is enabled in Phase 3 / Optimal Protection or custom prevention policies, and document any temporary exceptions. Continue monitoring CrowdStrike communications for updated remediation guidance, sensor updates, detections, or a CVE assignment. Do not run the public PoC in production environments; if validation is required, restrict testing to an isolated lab and coordinate with CrowdStrike Support.

Detection Strategy

Review Falcon detections, endpoint telemetry, and Windows event data for unusual Office file remediation activity followed by file-system redirection behavior, unexpected writes to protected Windows directories, suspicious DLL replacement or creation under WindowsPowerShell paths, and Task Scheduler activity used to load a newly written DLL.

CrowdStrike release notes state that malicious macro detections can include macro name and hash, Office file name and hash, and writing process details. Use those events to identify Office files that triggered macro analysis or remediation shortly before suspicious privileged process activity. Also investigate PoC-specific artifacts such as temporary directories beginning with Flanker_, named pipe references containing FALCONFLANK, anomalous access to bcrypt.dll in WindowsPowerShell directories, and unexpected execution of the Microsoft\Windows\Application Experience\MareBackup scheduled task.

How Deepwatch Protects Our Customers

Deepwatch experts monitor customer environments for suspicious endpoint activity associated with privilege escalation, defense evasion, and anomalous file or process behavior. The Threat Intel team is actively monitoring and assessing reporting on this issue as more information becomes available. Additionally, Deepwatch is currently working with mEDR customers to notify them and implement the required configuration changes recommended by CrowdStrike.

Relevant Detections

Please visit the Guardian Platform to access the relevant detections for this activity and ask NEXA Detection Advisor for a breakdown of which detections are enabled in your environment.

Threat Hunting Leads

  • Identify Windows endpoints with Microsoft Office File Suspicious Macro Removal enabled and prioritize telemetry review for those hosts.
  • Search for Office file macro detections followed by privileged writes, DLL load events, or task execution within the same host session.
  • Hunt for PoC-oriented artifacts: Flanker_ temporary directories, named pipe string FALCONFLANK, writes to WindowsPowerShell\v1.0\bcrypt.dll, and MareBackup scheduled task execution.
  • Review recent local user activity on affected endpoints for suspicious process launches, newly compiled binaries, or unsigned tooling staged from user-writable directories.

Technical Artifacts 

Please visit the Guardian Platform to access the associated technical artifacts.

Threat Object Mapping

Intrusion Set:

  •  No in the wild exploitation confirmed at this time. Current evidence is limited to a public PoC and secondary reporting.

Attack Pattern (MITRE ATT&CK/MITRE ATLAS):

TacticTechniqueTechnique IDAssociated Threat Activity
Privilege EscalationExploitation for Privilege EscalationT1068PoC claims local privilege escalation against a privileged Falcon remediation workflow after local access is already present.
Defense Evasion / Privilege EscalationDLL Search Order HijackingT1574.001PoC-oriented hunting should monitor suspicious DLL creation or replacement in locations loaded by privileged processes.
Execution / Privilege EscalationScheduled TaskT1053.005PoC references use of this built-in scheduled task as a DLL load path during privilege escalation behavior.

Vulnerabilities:

  • FalconFlank – reported local privilege escalation affecting CrowdStrike Falcon Sensor for Windows when Microsoft Office File Suspicious Macro Removal is enabled. No public CVE identifier was identified as of September 3, 2026.

Malware/Tool:

  • FalconFlank public PoC – GitHub repository MSNightmare/FalconFlank

Additional Sources

Share

LinkedIn Twitter Facebook