Activity App Flashcards
1
Q
Known bad files
A
Detections
2
Q
Behaviorally suspicious activity
A
Detections
3
Q
Prevented actions
A
Detections
4
Q
Blocklisted hashes
A
Detections
5
Q
Manual detections
A
Detections
6
Q
In progress
A
Detection status option
7
Q
True positive
A
Detections status option
8
Q
False positive
A
Detections status option
9
Q
Ignored
A
Detections status option
10
Q
Steps to assign a detection
A
- Select checkbox
- Update & assign
- Select assign to and Set Status
- Update
11
Q
What is included in an incident?
A
- Detections
- Associated processes
- Connections between detections and associated processes
- Tactics & Techniques involved
- Killed or blocked activities
- Hosts/users involved
- Whether the attack is active
- Timeline
- Incident status