When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the ParentProcessld_decimal field contains the decimal value of the process ID of the parent process that spawned or injected into the target process1.This field can be used to trace the process lineage and identify malicious or suspicious activities1.
What are Event Actions?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, Event Actions are automated searches that can be used to pivot between related events and searches1.They are available in various tools, such as Event Search, Process Timeline, Host Timeline, etc1.You can select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1.These actions can help you investigate and analyze events more efficiently and effectively1.
You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc1.The tool requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID)1.You can jump to a Process Timeline from many views, such as Hash Search, Host Timeline, Event Search, etc., by clicking on either the Process ID or Parent Process ID fields in those views1.This will automatically populate the aid and TargetProcessId_decimal parameters for the Process Timeline tool1.
What does the Full Detection Details option provide?
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Full Detection Details option allows you to view detailed information about a detection, such as detection ID, severity, tactic, technique, description, etc1.You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity1.The process tree view provides a visualization of program ancestry, which shows the parent-child and sibling relationships among the processes1.You can also see the event types and timestamps for each process1.
How long are quarantined files stored on the host?
According to theCrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, quarantined files are never deleted from the host unless you manually delete them or release them from quarantine2.When you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization2.This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud2.
Emily Flores
3 days agoAshley Martinez
22 days agoChristopher Hill
1 month agoLaura Wilson
2 months agoJohn Nguyen
2 months agoOlivia Garcia
3 months agoAshley Peterson
3 months agoEmma Lewis
3 months agoMelissa Perez
3 months agoMonica Ramirez
3 months agoGerald Morris
3 months agoHarold Collins
2 months agoMicheal
4 months agoLizette
4 months agoRozella
4 months agoLenna
5 months agoGerman
5 months agoIzetta
5 months agoGalen
5 months agoMiriam
6 months agoGiovanna
6 months agoNoemi
6 months agoRodolfo
6 months agoJade
7 months ago