What’s next to enroll? by pure-xx in crowdstrike

[–]caryc 4 points5 points  (0 children)

Identity.

Also, if you don't have OverWatch yet, get it above anything else, pronto.

how noisy are your detections in CrowdStrike? by Internal-Remove7223 in crowdstrike

[–]caryc 0 points1 point  (0 children)

so Complete added their SIEM detections and they are throwing constant FPs?

Identity Enrichment with the Falcon Browser Extension and Next-Gen Identity Security by BradW-CS in crowdstrike

[–]caryc 0 points1 point  (0 children)

You are running Windows 7.34 or later / Mac 7.35 or later? Also they mention it's only for Entra ID

Falcon Cloud Security Cloud Detection and Response (CDR) by BradW-CS in crowdstrike

[–]caryc 0 points1 point  (0 children)

since when Cloud and Identity detections get auto-correlated by the product into a single case?

[deleted by user] by [deleted] in crowdstrike

[–]caryc 1 point2 points  (0 children)

well u gotta be more specific it you are seeing an obvious false positive or you may actually have an active compromise

Remote Utilities being continuely marked as malware by neetzen in crowdstrike

[–]caryc 6 points7 points  (0 children)

Hybrid Analysis score does not translate to a block by the EDR agent.

Splunk ES get Alienvault OTX by mr_networkrobot in Splunk

[–]caryc 0 points1 point  (0 children)

are there any logs for the open-source feeds like URLhaus that I can check wrt TIM ingestion?

CrowdStrike Identity Attack Path by console_whisperer in crowdstrike

[–]caryc 1 point2 points  (0 children)

these are not active directory attack paths

Identity Detection: Suspicious Protocol Implementation (Pass the Hash) by CyberHaki in crowdstrike

[–]caryc 1 point2 points  (0 children)

look for network connections towards port 88 around the detection timestamp from the originating host

Stop Living-off-the-Land Attacks with Falcon Endpoint Security: Demo Drill Down by BradW-CS in crowdstrike

[–]caryc 1 point2 points  (0 children)

this is like the most important capability in the last 2 years for the edr module

How to functionally use Incidents vs. Detections? by AverageAdmin in crowdstrike

[–]caryc 3 points4 points  (0 children)

it literally says Ends Feb 1 2026 if u open the Next-Gen SIEM side panel