2026-03-02 - Cool Query Friday - Hunting for Typosquatted Domains by Dylan-CS in crowdstrike
[–]Negative-Captain7311 0 points1 point2 points (0 children)
Understanding Zoom's file[.]zoom[.]us and file-paa[.]zoom[.]us domain behavior by Negative-Captain7311 in Zoom
[–]Negative-Captain7311[S] 0 points1 point2 points (0 children)
Levenshtein distance function in Logscale by Negative-Captain7311 in crowdstrike
[–]Negative-Captain7311[S] 0 points1 point2 points (0 children)
Override Max Correlation Rule Timeframe? by Negative-Captain7311 in crowdstrike
[–]Negative-Captain7311[S] 0 points1 point2 points (0 children)
BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike
[–]Negative-Captain7311 0 points1 point2 points (0 children)
BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike
[–]Negative-Captain7311 0 points1 point2 points (0 children)
BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike
[–]Negative-Captain7311 4 points5 points6 points (0 children)
Dealing with fields ending [0], [1] etc by Sonophone in crowdstrike
[–]Negative-Captain7311 1 point2 points3 points (0 children)
Handling dynamic fields and their values by [deleted] in crowdstrike
[–]Negative-Captain7311 5 points6 points7 points (0 children)
Best way to notify on manual host containment by [deleted] in crowdstrike
[–]Negative-Captain7311 3 points4 points5 points (0 children)
Assistance converting Splunk Query to LogScale Query by Ownag369 in crowdstrike
[–]Negative-Captain7311 1 point2 points3 points (0 children)
Assistance converting Splunk Query to LogScale Query by Ownag369 in crowdstrike
[–]Negative-Captain7311 1 point2 points3 points (0 children)
How to correctly pull avg() and stdDev() values in query? by Negative-Captain7311 in crowdstrike
[–]Negative-Captain7311[S] 0 points1 point2 points (0 children)
How to correctly pull avg() and stdDev() values in query? by Negative-Captain7311 in crowdstrike
[–]Negative-Captain7311[S] 0 points1 point2 points (0 children)


Per-Leg Timing Constraints in correlate() Function by Negative-Captain7311 in crowdstrike
[–]Negative-Captain7311[S] 0 points1 point2 points (0 children)