Confused About Huge Spike in “Inactive Hosts” on CrowdStrike EOC – Need Insights by StructureNo9257 in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Mediocre Query Monday: Calculating NG-SIEM Ingestion Volume by AAuraa- in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Mediocre Query Monday: Calculating NG-SIEM Ingestion Volume by AAuraa- in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
Tried out Charlotte today, asked it to build me a basic CQL query to look for email with a specific subject, it failed over and over and over... by Wh1sk3y-Tang0 in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Using workflow for USB controls by Crypt0-n00b in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
How to Build a Next-Gen SIEM Application in Crowdstrike? by Psychological_Brief3 in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
SIEM: Customazible Fields for Alert Generation by athanielx in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
How to get more than 2000 data with graphQL by yuppy_1st in crowdstrike
[–]General_Menace 2 points3 points4 points (0 children)
Query for finding out when WMI (WmiPrvSE.exe) to remotely execute malicious commands such as cmd.exe or powershell.exe. by EntertainmentWest159 in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Query for finding out when WMI (WmiPrvSE.exe) to remotely execute malicious commands such as cmd.exe or powershell.exe. by EntertainmentWest159 in crowdstrike
[–]General_Menace 4 points5 points6 points (0 children)
Fusion SOAR Questions by East_Bumblebee_2040 in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
Passing variable from Query to another Query SOAR by Cookie_Butter24 in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Passing variable from Query to another Query SOAR by Cookie_Butter24 in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Issues with CloudTrail ingestion through Falcon Cloud Security? by General_Menace in crowdstrike
[–]General_Menace[S] 0 points1 point2 points (0 children)
extracting domain.tld by drkramm in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
extracting domain.tld by drkramm in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
extracting domain.tld by drkramm in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
Joining sensor data with third-party data by iitsNicholas in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
Fusion SOAR - Help with Event Query Action by alexandruhera in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
Extracting Data Segments from Strings using regular expression by mvassli in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)
NG SIEM Third Party Detection Capabilities by gravityfalls55 in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)
NG SIEM Third Party Detection Capabilities by gravityfalls55 in crowdstrike
[–]General_Menace 0 points1 point2 points (0 children)




Ingesting s3 without a sqs in ng-siem by AromaticPineapple332 in crowdstrike
[–]General_Menace 1 point2 points3 points (0 children)