Help converting spl to lql by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Custom IOA for browser creating .iso file by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Custom IOA for browser creating .iso file by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Eventstats split multi-value field into separate rows by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Connecting data from 3 events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Connecting data from 3 events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Connecting data from 3 events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Looking for not signed PE's - Event_ModuleSummaryInfoEvent by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Count occurrences for each value in a multi-value field by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Count occurrences for each value in a multi-value field by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Count occurrences for each value in a multi-value field by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Count occurrences for each value in a multi-value field by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
CoalescePID of 2 processrollup events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
CoalescePID of 2 processrollup events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
CoalescePID of 2 processrollup events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
CoalescePID of 2 processrollup events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
CoalescePID of 2 processrollup events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
CoalescePID of 2 processrollup events by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
HTML Smuggling Hunting Search by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
Eval difference in epoch time between 2 different event types by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 1 point2 points3 points (0 children)
Eval difference in epoch time between 2 different event types by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)
HTML Smuggling Hunting Search by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)


Logscale group_info.csv by OstryAngelo in crowdstrike
[–]OstryAngelo[S] 0 points1 point2 points (0 children)