You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Hash Execution Search tool allows you to search for one or more SHA256 hashes and view a summary of information from Falcon events that contain those hashes1.The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that loaded or executed those hashes1.You can also see a count of detections and incidents related to those hashes1.
Lakeesha
4 days agoArminda
9 days agoStephanie
14 days agoCelestina
19 days agoHaley
25 days agoMaryrose
30 days agoHoa
1 month agoJackie
1 month agoMarilynn
2 months agoNoah
2 months agoGerald
2 months agoLatonia
3 months agoLavonna
4 months agoShawna
4 months agoMerilyn
4 months agoDenise
4 months agoJesusita
5 months ago