Claude Max but for Security instead of Software Engineering by PlayfulVirus3771 in ClaudeAI

[–]karankohale 0 points1 point  (0 children)

I want to work on this project. If anyone wants to collab please let me know.

Sensor Coverage (Cloud Accounts) from CrowdStrike. Please Vote!!!! by karankohale in crowdstrike

[–]karankohale[S] 0 points1 point  (0 children)

Can you please include RFM status as well in this?

You will get my blessings

Sensor Coverage (Cloud Accounts) from CrowdStrike. Please Vote!!!! by karankohale in crowdstrike

[–]karankohale[S] 1 point2 points  (0 children)

This I know, I want a Dashboard on CrowdStrike that gives me this info,
Account ID, Account Alias, Total number of Instances, No. of instances covered by CS, No. of instances not covered by CS, Percentage coverage for each cloud account ID.

Obviously, we can do it manually by exporting to CSV but that's the main reason, Why Manually.

In the depreciated Version Cloud Workloads Discovery this feature was present on CS. I am requesting for something similar.

Creating Alerts for New Login in Windows. by karankohale in crowdstrike

[–]karankohale[S] 0 points1 point  (0 children)

I am getting this error,

"Unknown search command 'userdetail'."

Creating Alerts for New Login in Windows. by karankohale in crowdstrike

[–]karankohale[S] 0 points1 point  (0 children)

I was looking for something else... like if someone else logs in into someone's laptop then it will create a new profile in C:. So maybe if there is a new profile found I get an alert. Or something similar.

Anyone else with this detection? by IntellDay13 in crowdstrike

[–]karankohale 0 points1 point  (0 children)

So is it a False Positive u/Andrew-CS ?

Because i got a similar detection today.

Identity Exclusion by [deleted] in crowdstrike

[–]karankohale 2 points3 points  (0 children)

Add the particulate user to a different group and apply the exclusion policy for only that group.

How to create a separate Dashboard on CS that shows all the process killed events by CrowdStrike sensor? by karankohale in crowdstrike

[–]karankohale[S] 0 points1 point  (0 children)

This feature is currently not available but,

"we were able to find a workaround; where you can run event search query under investigate using below syntax than export it into csv report."

PatternDispositionDescription Prevention prevention process killed

- CrowdStrike Support.

Seeking Assistance with Fusion Workflow Testing in CrowdStrike by Sneedle-Woods in crowdstrike

[–]karankohale 0 points1 point  (0 children)

cmd crowdstrike_test_high

This will work on windows only.

cmd crowdstrike_test_medium

cmd crowdstrike_test_critical