What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?
Which of the following is TRUE about a Hash Search?
To view Files Written to Removable Media within a specified timeframe on a host within the Host Search page, expand and refer to the _______dashboard panel.
Which of the following Event Search queries would only find the DNS lookups to the domain: www randomdomain com?
What do you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search?
What elements are required to properly execute a Process Timeline?
What type of attack would this process tree indicate?
You are reviewing a list of domains recently banned by your organization's acceptable use policy. In particular, you are looking for the number of hosts that have visited each domain. Which tool should you use in Falcon?
Which pre-defined reports offer information surrounding activities that typically indicate suspicious activity occurring on a system?
The Process Timeline Events Details table will populate the Parent Process ID and the Parent File columns when the cloudable Event data contains which event field?