Reports Flashcards
Filter by:
- API Client ID
- User IP
- API action
- Company
- Time Range
API Audit Trail Report
- Time
- API Action
- Activity Details
- UserIP
- City
- -Country
- API Client ID
- Company
API Audit Trail Report
Activity by Analyst Top Users Granting Access New User Report --> admin audit trail Audit Details -time -analyst -service -action -activity details -computer name -user IP -city -country -company
Falcon UI Audit Trail
Alert Templates
Scheduled Alerts
Custom Alerts
Configure:
- Email Recipients
- Email Subject
- Severity
- Email body
- Preview in email?
Custom Alerts
Country Map Users based on geolocation Time (UTC) Hostname ProcessID LocalIP/Local Port Destination IP/Remote Port
Geo Location Activity
Unique Host Connecting to Countries Map
ML Slider - Cloud anti-malware, sensor anti-malware, adware & PUP # of blocks last 7 days # blocked, if set to...
Machine Learning Monitoring Report
exe running from recycle bin cmd & ASEP activity from network capable process exe running from temp. directory files written to removable media firewall set rules powershell hunt scheduled tasks registered
hunting reports
Visibility = logon Hunt = events that happened
Visibility vs Hunting Reports
Logon Type (terminal, network) Min, Max Hosts Incl. Users Excl. Users Incl. Hosts Excl. Hosts
Remote Access Graph
Username Hostname Logon Type Count Trend Latest Event
Logon Activity Report (Remote or Network Logon Activities)
Logon Activities
Remote Access Graph
Remote or Network Logon Activities
Geo Location Activity
Visibility Reports
Filters:
- Company
- Time Range
- Timezone
PolicyID Policy Name Policy Description Policy Type Assignment Rule Policy Platform Policy Setting Changes Action Time (UTC) UserId Member Changes (#) User IP View
Prevention Policy Audit Trail
Filters:
- AID
- Company
- Time Range
- Timezone
Sensor heartbeat Prevention Settings on Host Hostname AID List of enabled settings Date settings enabled
Prevention Policy Debug
OS Version Device Type Machine Domain Site Name Agent Version Active Sensors - Map Active Sensors by Country (Country, Count) Host list info (hostname, mac, etc)
Sensor Report
Top 10 Sensor Update Policies
Top 10 Prevention Policies
Top 10 Device Control Policies
Sensor Policy Daily Report
Filters -
- Company
- Time range
includes all machines with sensors that have not communicated w/CS cloud within a specified time.
Inactive Sensors
search for a host to see if it has a FH sensor installed
Sensor Coverage Lookup