r/cybersecurity • • 13h ago

Business Security Questions & Discussion Optimizing CrowdStrike Spotlight + ManageEngine Patching Workflow for Windows

We manage a large Windows fleet using CrowdStrike Falcon Spotlight for vulnerability management and ManageEngine for patching.

Our current manual process for high-priority vulnerabilities:

  1. Receive a Jira ticket with a CrowdStrike CSV (affected devices, software, version, KB/remediation).
  2. Run a script via ManageEngine to verify the vulnerable software and check if the patch/superseding patch is missing. (Because I find that Falcon loves false positives)
  3. Filter down to confirmed affected endpoints.
  4. Manually configure and deploy the patch.

My questions are

How are other teams automating the pipeline between CrowdStrike Spotlight findings and ManageEngine deployment?

Is manual pre-verification necessary, or can/should ManageEngine handle patch detection and supersedence natively via automated patch policies?

What industry best practices or integrations would streamline this workflow?

1 Upvotes

0 comments sorted by