FALCON REPORTS Flashcards

1
Q

What information is contained in a Machine Learning Prevention Monitoring Report?

A

-Shows malware that would have been blocked in your environment based on different ML Prevention Settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What information is in the Falcon UI Audit Trail Report

A

-List of Analyst Login Activity, Falcon UI Audit Trail

-Analyst log on activity/access granting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What information is in the API Audit Trail?

A

-API Audit Trail Report: List of actions taken via Falcon OAuth2 based APIs, list of API Actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What information is in the Prevention Policy Debug Report?

A

-Report used to confirm prevention policy settings were applied to a host. Use to debug issues with prevention settings not being set.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What information a Linux Sensor Report will provide?

A

-Provides a list of Firewall Commands issued from the command line, Hosts by Kernel Version, Shells spawned by Root, Wget/Curl Usage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What information does a Mac Sensor Report provide?

A

-Chart of the MAC OS Versions as well as a variety of queries related to potentially suspicious activity on MAC Hosts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What information can be found in hunting reports?

A

-Hunting Reports: Various built-in reports and queries of potentially suspicious activity on hosts such as executables running from the recycle bin or temporary directories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What information is shown in the Remote Logon Activity Report?

A

-Provides a list of users and the count of times they remotely logged on to hosts based on terminal or network server logons

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What information is shown on the Remote Access Graph Report?

A

-Shows a graph of the nodes and the users connecting to the nodes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What information is shown on the Geo Location Activity Report?

A

-Users connecting to countries map (can include IP’s and Exclude Destination IP’s, and include Destination Ports and Exclude Dest Ports)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What information can be found in Visibility Reports?

A

-Logon Activities, Remote Access Graph, Remote/Network Logon Activities, and Geo Location Activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a custom alert rule?

A

Custom Alert Rule:

  • Configure email alerts using predefined templates so you’re notified about specific activity in environment. When alert runs/finds results – sends email to specified recipients instead of generating a new detection.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What information is in the Prevention Policy Audit Trail?

A

-The audit trail for all policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who can view the custom alerts page?

A

Role required:

-Falcon Admin
-Falcon Security Lead
-Falcon Investigator
-Falcon Analyst
-Falcon Analyst (Read Only)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What predefined templates could a custom Falcon report be generated for?

A
  • Sensor entering RFM,
    -Real Time Response Session Initiation
    -Mobile host Detections
    -Analyst contained a host
    -Analyst repeatedly fails login
    -OS security Settings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What triggers a custom alert?

A

-Custom_Alert: Trigger when UserName=* failed to log on to ComputerName =* more than 3 times in one hour span for cid=* from Account Type=* using logon type=*

17
Q

What does Preview Results do prior to scheduling the alert?

A

-Preview results helps you see what your results are found before your schedule the alert.

**Adjust search parameters as needed until satisfied with activity being found

18
Q

What are the 3 steps to creating a Falcon Report?

A

-Choose the template
-Preview the search results
-Schedule the alert

19
Q

How to configure a custom alert?

A

-Investigate> custom alerts> Preview Alert next to template you’d like to configure> input search criteria> run search>Configure Alert> input Email Recipients/Email Subject/Severity/Alert Email Body> select if you’d like a preview of alert results included in email**multiple email addresses, separate them with commas>
Schedule Alert

20
Q

How many custom alerts can be scheduled for an environment at one time?

A

-Up to 50 custom alerts can be scheduled at one time

21
Q

Where can scheduled alerts be edited, disabled, or re-enabled?

A

-Schedule Alerts application

22
Q

When creating multiple alerts…

A

-Enter multiple search parameters in one Custom Alert instead of creating many similar alerts

**Duplicate alerts are not allowed

23
Q

What information is in the Prevention Hashes Ignore Report?

A
24
Q

What are 3 types of alerts?

A

-Detection and incident email alerts, notification workflow alerts, custom alerts

25
Q

How to access the custom alerts in falcon?

A

Investigate> custom alerts> alerts

26
Q

Which alert lets you setup email alerts based on predefined templates that cover a wide range of topics?

A

-Custom Alerts

27
Q

How to access Notification workflow alerts in Falcon?

A

Host setup and management> Automated workflows> fusion workflows

28
Q

Notification workflows allow you to?

A

-Customize falcon notifications
-Define what falcon will send notifications about
-Define which individuals and channels it will send them to

29
Q

When are detection email alerts sent?

A

Emails are sent once per day for:

-Detection at medium severity

-Incident at 1.0 and above

30
Q

How to setup detection and incident email alerts?

A

Falcon Menu> support and resources>resources and tools>general settings>scroll down to manage list for detection and incident email section>enter email to send notifications to>Enter>

31
Q

Where can scheduled alerts be edited, disabled, or re-enabled?

A

-Under Scheduled Alerts