You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc.Which command would be the appropriate choice?
Which tool allows a threat hunter to populate and colorize all known adversary techniques in a single view?
In the Powershell Hunt report, what does the "score" signify?
An analyst has sorted all recent detections in the Falcon platform to identify the oldest in an effort to determine the possible first victim host What is this type of analysis called?
The Process Timeline Events Details table will populate the Parent Process ID and the Parent File columns when the cloudable Event data contains which event field?
Which Falcon documentation guide should you reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts?
What is the difference between a Host Search and a Host Timeline?
Lateral movement through a victim environment is an example of which stage of the Cyber Kill Chain?
What information is provided from the MITRE ATT&CK framework in a detection's Execution Details?
A benefit of using a threat hunting framework is that it:
PDF + Testing Engine
|
---|
$57.75 |
Testing Engine
|
---|
$43.75 |
PDF (Q&A)
|
---|
$36.75 |
CrowdStrike Free Exams |
---|
![]() |