Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Hunting using Falcon CrowdStrike

  • By Telecommunications
  • on 07/26/2022

What do you like best about the product?
The telemetry can be leveraged for Threat Hunts. If logs are available in backwaters, it is easy to identify the root cause by correlating the process id. The installed Applications module acts as an organisation's inventory to identify and eliminate malicious/unwanted apps if needed
What do you dislike about the product?
It would be great if the Advanced search results could differentiate between servers and workstations
What problems is the product solving and how is that benefiting you?
Blocks Malicious/suspicious processes based on Signature/Machine Learning
New executables without any signatures/Inbuilt exe's are blocked if spawning unnecessary process based on Machine Learning
The RTR feature helps an Analyst grab the files required for Analysis and isolate device if Host is compromised