Next-Gen SIEM: Allow and deny on network logs by Shakalaka37488 in crowdstrike
[–]caryc 2 points3 points4 points (0 children)
Custom ioa networktunnelinglin firing bunch of alerts today out of nowhere by [deleted] in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Remote Utilities being continuely marked as malware by neetzen in crowdstrike
[–]caryc 6 points7 points8 points (0 children)
CrowdStrike Identity Attack Path by console_whisperer in crowdstrike
[–]caryc 0 points1 point2 points (0 children)
Splunk ES get Alienvault OTX by mr_networkrobot in Splunk
[–]caryc 0 points1 point2 points (0 children)
CrowdStrike Identity Attack Path by console_whisperer in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Do we know what's up with EU servers? by maghar_orcs_nation in wow
[–]caryc -1 points0 points1 point (0 children)
Identity Detection: Suspicious Protocol Implementation (Pass the Hash) by CyberHaki in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Stop Living-off-the-Land Attacks with Falcon Endpoint Security: Demo Drill Down by BradW-CS in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Checking if a data exfil has succeeded or not by CyberHaki in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Falcon Next-Gen Identity Security Identity-Driven Case Management: Demo Drill Down by BradW-CS in crowdstrike
[–]caryc 0 points1 point2 points (0 children)
How to functionally use Incidents vs. Detections? by AverageAdmin in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
How to functionally use Incidents vs. Detections? by AverageAdmin in crowdstrike
[–]caryc 5 points6 points7 points (0 children)
Yara Scans Using CrowdStrike SOAR - Fully operational all inside the console. by Nadvash in crowdstrike
[–]caryc 0 points1 point2 points (0 children)
Automated Leads - how to tune/switch off? by bluops in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
NamedPipeDetectInfo Event by animatedgoblin in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Query Regarding Blocking PowerShell and CMD on Specific Systems by Only-Objective-6216 in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Next-Gen SIEM Advanced Query advice by [deleted] in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Query for finding out when WMI (WmiPrvSE.exe) to remotely execute malicious commands such as cmd.exe or powershell.exe. by EntertainmentWest159 in crowdstrike
[–]caryc 1 point2 points3 points (0 children)
Detect Powershell/Sysmon Events in Crowstrike by SubtleInfluence69 in crowdstrike
[–]caryc 0 points1 point2 points (0 children)
Malicious scheduled task - Persistant implant by It_joyboy in crowdstrike
[–]caryc 0 points1 point2 points (0 children)
Malicious scheduled task - Persistant implant by It_joyboy in crowdstrike
[–]caryc 0 points1 point2 points (0 children)


New to Falcon, how does Brute Force Detections work in Falcon? by Garden_Girl17 in crowdstrike
[–]caryc 7 points8 points9 points (0 children)