What does the Full Detection Details option provide?
What do IOA exclusions help you achieve?
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
From the Detections page, how can you view 'in-progress' detections assigned to Falcon Analyst Alex?
What happens when a quarantined file is released?
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
The primary purpose for running a Hash Search is to:
What information does the MITRE ATT&CK®Framework provide?
Where are quarantined files stored on Windows hosts?
A list of managed and unmanaged neighbors for an endpoint can be found:
The function of Machine Learning Exclusions is to___________.
What happens when a hash is set to Always Block through IOC Management?
Which of the following is NOT a valid event type?
In the Hash Search tool, which of the following is listed under Process Executions?
You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?
What is the difference between a Host Search and a Host Timeline?
What are Event Actions?