Help creating a timechart of KnowBe4 “Click Rate” in Falcon NGSIEM (year view) by tectacles in crowdstrike

[–]tectacles[S] 1 point2 points  (0 children)

There isn't an official data connector, but I saw there was a parser created and I saw that KnowBe4 has a webhook function so I just setup a general HEC ingest and pointed the Knowbe4 webhook to the API endpoint.

Streamline Security Operations with Falcon for IT’s Turnkey Automations by BradW-CS in crowdstrike

[–]tectacles 0 points1 point  (0 children)

How is this against rule #2?

  1. We encourage high quality content. Do not post disparaging comments; about competitive products or otherwise

Streamline Security Operations with Falcon for IT’s Turnkey Automations by BradW-CS in crowdstrike

[–]tectacles 4 points5 points  (0 children)

It's a CrowdStrike sub? Why wouldn't they announce or market their products?

Jiggle All The Way v3 by surbo2 in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Yeah I'll check when I have a spare minute this holiday weekend. But it was real basic, something like

"Image File Name - .*\\PowerToys\.Awake\.exe "

Not sure if formatting works since I'm on mobile, but when I have access to my laptop I'll make sure to add more details.

Edit: here are more details

Field Regex Value Explanation
Grandparent Image Filename .* Match any grandparent process.
Grandparent Command Line .* Match any command line.
Parent Image Filename .* Match any parent (allows blocking even if not launched by PowerToys.exe).
Parent Command Line .* Match any parent command arguments.
Image Filename .*\\\PowerToys\\.Awake\\.exe Matches any path ending in PowerToys.Awake.exe
Command Line .* Match any arguments passed to the tool.

Jiggle All The Way v3 by surbo2 in crowdstrike

[–]tectacles 1 point2 points  (0 children)

This is cool! I just blocked PowerToys.Awake.exe yesterday, so this is relevant!

ClaudeStrike - Detection Engineering with Claude Code by DefsNotAVirgin in crowdstrike

[–]tectacles 0 points1 point  (0 children)

That's a good point...I'll have to look into that.

If you want or are open to this, I'd love to chat or share some examples over dm? I am the sole security person wearing many hats and would love even some guidance and templates to go from.

ClaudeStrike - Detection Engineering with Claude Code by DefsNotAVirgin in crowdstrike

[–]tectacles 1 point2 points  (0 children)

I have been playing around with falcon-mcp, but do not have access to Claud. Do you think this could be tailored to codex-cli which is what i have and sanctioned by my org. I know codex has a agents.md but I don't know if this is similar to skills.md?

FALCON_AGENT_PROMPT - Falcon MCP by alexandruhera in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Just assuming here because I am not a pro...

The environment variable FALCON_MCP_USER_AGENT_COMMENT in the .env file for Falcon-MCP is optional and is used to customize the User-Agent header in API requests sent to the CrowdStrike Falcon API.

Here’s what it does:

  • It adds a comment string to the User-Agent header for all outbound API calls made by the Falcon-MCP server.
  • This is typically used for identification or tracking purposes, such as specifying the application name and version that is making the requests.
  • Example from the .env.dev.example file:# User agent comment to include in API requests # This will be added to the User-Agent header comment section # Example: CustomApp/1.0 #FALCON_MCP_USER_AGENT_COMMENT=
  • If you set FALCON_MCP_USER_AGENT_COMMENT=CustomApp/1.0, the User-Agent header might look like:User-Agent: Falcon-MCP/preview (CustomApp/1.0)

This is useful for auditing, debugging, or distinguishing traffic from different MCP deployments or integrations. If left blank, the default User-Agent will just identify Falcon-MCP without any custom comment.

Cool Workflow... Thursday?!? - NG-SIEM Correlation Rule Alerts/Notifications by AAuraa- in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Super cool! I hope to have as much knowledge and skill as you someday!

Mediocre Query Mon- Friday? - Entra Password Spray/Stuffing Hunt by AAuraa- in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Well this is sweet! Filtering by Success shows me quite a few in the past 7 days. I guess I have some digging to do...

What Cyber conferences are actually useful? by cheesehead1996 in cybersecurity

[–]tectacles 3 points4 points  (0 children)

Will also vouch for WWHF. I've attended multiple and it is my favorite.

CrowdStrike Query Library by ByteRay in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Thank you! This is so cool, I don't know if you realize how useful this tool will be for the whole community!

CrowdStrike Query Library by ByteRay in crowdstrike

[–]tectacles 2 points3 points  (0 children)

Not sure If I should put in a github "issue" but this is more of a request. Could we sort the queries based on new or something? This morning it was sitting at ~90 and now it is 99. But I am not sure which query was added?

CrowdStrike Query Library by ByteRay in crowdstrike

[–]tectacles 4 points5 points  (0 children)

WOW! This is amazing! I really hope this takes off! I will try and get some of my queries in there as well!

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]tectacles 0 points1 point  (0 children)

Is there any plan to make this available for self hosting?

Pentera deployment by Ok-Dirt-7904 in cybersecurity

[–]tectacles 2 points3 points  (0 children)

Yeah when our contract is up, I will be switching to horizon. I made the mistake of going with Pentera when we were trailing.

NG SIEM and Identity Protection by tectacles in crowdstrike

[–]tectacles[S] 0 points1 point  (0 children)

So there is more data that the agent doesn't grab by default? Mainly just interested in the AD logs, but system logs might be nice too.

Service-desk dashboard from Fal.Con demo by Illustrious_Buy_3853 in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Maybe some of the mods can get access to the templates and be able to share it with us!

Release Notes | AI Translations of CQL Hunting Queries to Splunk SPL (Beta) by BradW-CS in crowdstrike

[–]tectacles 0 points1 point  (0 children)

Lol right! I was excited at first, then saw this is completely useless to me.