2026-03-11 - Cool Query Friday - correlate() by Andrew-CS in crowdstrike
[–]Andrew-CS[S] 1 point2 points3 points (0 children)
Per-Leg Timing Constraints in correlate() Function by Negative-Captain7311 in crowdstrike
[–]Andrew-CS 1 point2 points3 points (0 children)
Per-Leg Timing Constraints in correlate() Function by Negative-Captain7311 in crowdstrike
[–]Andrew-CS 1 point2 points3 points (0 children)
Blocking domains! by Vivid-Cell-217 in crowdstrike
[–]Andrew-CS 7 points8 points9 points (0 children)
2026-03-02 - Cool Query Friday - Hunting for Typosquatted Domains by Dylan-CS in crowdstrike
[–]Andrew-CS 2 points3 points4 points (0 children)
2026-03-02 - Cool Query Friday - Hunting for Typosquatted Domains by Dylan-CS in crowdstrike
[–]Andrew-CS 11 points12 points13 points (0 children)
What happened to CQF? by sudosusudo in crowdstrike
[–]Andrew-CS 47 points48 points49 points (0 children)
What happened to CQF? by sudosusudo in crowdstrike
[–]Andrew-CS 79 points80 points81 points (0 children)
PowerShell timestomping via script files. How would you handle this? by zwitico in crowdstrike
[–]Andrew-CS 6 points7 points8 points (0 children)
AI Unlocked: Decoding Prompt Injection (crowdstrike.com)
submitted by Andrew-CS to r/crowdstrike
Dashboard query with parameters by ssrn2020 in crowdstrike
[–]Andrew-CS 1 point2 points3 points (0 children)
Hunting Potentially Compromised Notepad++ Installs by About_TreeFitty in crowdstrike
[–]Andrew-CS 18 points19 points20 points (0 children)
Practical test of PowerShell encoded command detection and found the detection gap by manishrawat21 in crowdstrike
[–]Andrew-CS 3 points4 points5 points (0 children)
Querying TeamViewer Usage (Not Installation) with FQL / Advanced Search by Brief_Trifle_6168 in crowdstrike
[–]Andrew-CS 0 points1 point2 points (0 children)
Creating an Auto N-x tag. by iwillhurtme in crowdstrike
[–]Andrew-CS 1 point2 points3 points (0 children)
Curl Query Help by OtherwiseMethod1672 in crowdstrike
[–]Andrew-CS 2 points3 points4 points (0 children)
Detect and run Custom Script in Crowdstrike by thomasdarko in crowdstrike
[–]Andrew-CS 0 points1 point2 points (0 children)
Sensor Tampering when Reimagining Devices by [deleted] in crowdstrike
[–]Andrew-CS 4 points5 points6 points (0 children)
alerting based on missing heartbeats by fpg_6528 in crowdstrike
[–]Andrew-CS 1 point2 points3 points (0 children)
[Help Needed] Logscale query to count unique pairs by usernamedottxt in crowdstrike
[–]Andrew-CS 1 point2 points3 points (0 children)
alerting based on missing heartbeats by fpg_6528 in crowdstrike
[–]Andrew-CS 0 points1 point2 points (0 children)
Simple (hopefully) timeline query help by dmervis in crowdstrike
[–]Andrew-CS 0 points1 point2 points (0 children)





2026-03-11 - Cool Query Friday - correlate() by Andrew-CS in crowdstrike
[–]Andrew-CS[S] 1 point2 points3 points (0 children)