What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?
In the Powershell Hunt report, what does the filtering condition of commandLine! ="*badstring* " do?
You are reviewing a list of domains recently banned by your organization's acceptable use policy. In particular, you are looking for the number of hosts that have visited each domain. Which tool should you use in Falcon?
To view Files Written to Removable Media within a specified timeframe on a host within the Host Search page, expand and refer to the _______dashboard panel.
SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time Which eval function is correct^
When exporting the results of the following event search, what data is saved in the exported file (assuming Verbose Mode)? event_simpleName=*Written | stats count by ComputerName
Which Falcon documentation guide should you reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts?
Which field should you reference in order to find the system time of a *FileWritten event?
When performing a raw event search via the Events search page, what are Event Actions?
Which of the following is the proper method to quantify search results, enabling a hunter to quickly sort and identify outliers?
Which of the following would be the correct field name to find the name of an event?