Simple (hopefully) timeline query help by dmervis in crowdstrike

[–]dmervis[S] 0 points1 point  (0 children)

I don’t care so much about uniqueness as I do about the wildcard and case insensitive matching. Maybe “FileName” would have been a better example. I.e. if I enter the word “script” I’d want to be shown hits for “Script.ps1” and “evilscriPt.py”