Reports Flashcards

1
Q

Filter by:

  • API Client ID
  • User IP
  • API action
  • Company
  • Time Range
A

API Audit Trail Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  • Time
  • API Action
  • Activity Details
  • UserIP
  • City
  • -Country
  • API Client ID
  • Company
A

API Audit Trail Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Activity by Analyst
Top Users Granting Access
New User Report --> admin audit trail
Audit Details 
-time
-analyst
-service
-action
-activity details
-computer name
-user IP
-city
-country
-company
A

Falcon UI Audit Trail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Alert Templates

Scheduled Alerts

A

Custom Alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Configure:

  • Email Recipients
  • Email Subject
  • Severity
  • Email body
  • Preview in email?
A

Custom Alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
Country
Map
Users based on geolocation
Time (UTC)
Hostname
ProcessID
LocalIP/Local Port
Destination IP/Remote Port
A

Geo Location Activity

Unique Host Connecting to Countries Map

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
ML Slider - Cloud anti-malware, sensor anti-malware, adware & PUP
# of blocks last 7 days
# blocked, if set to...
A

Machine Learning Monitoring Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
exe running from recycle bin
cmd & ASEP activity from network capable process
exe running from temp. directory
files written to removable media
firewall set rules
powershell hunt
scheduled tasks registered
A

hunting reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
Visibility = logon
Hunt = events that happened
A

Visibility vs Hunting Reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
Logon Type (terminal, network)
Min, Max Hosts
Incl. Users
Excl. Users
Incl. Hosts
Excl. Hosts
A

Remote Access Graph

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
Username
Hostname
Logon Type
Count
Trend
Latest Event
A

Logon Activity Report (Remote or Network Logon Activities)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Logon Activities
Remote Access Graph
Remote or Network Logon Activities
Geo Location Activity

A

Visibility Reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Filters:

  • Company
  • Time Range
  • Timezone
PolicyID
Policy Name
Policy Description
Policy Type
Assignment Rule
Policy Platform
Policy Setting Changes
Action
Time (UTC)
UserId
Member Changes (#)
User IP
View
A

Prevention Policy Audit Trail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Filters:

  • AID
  • Company
  • Time Range
  • Timezone
Sensor heartbeat
Prevention Settings on Host
Hostname
AID
List of enabled settings
Date settings enabled
A

Prevention Policy Debug

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
OS Version
Device Type
Machine Domain
Site Name
Agent Version
Active Sensors - Map
Active Sensors by Country (Country, Count)
Host list info (hostname, mac, etc)
A

Sensor Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Top 10 Sensor Update Policies
Top 10 Prevention Policies
Top 10 Device Control Policies

A

Sensor Policy Daily Report

17
Q

Filters -

  • Company
  • Time range

includes all machines with sensors that have not communicated w/CS cloud within a specified time.

A

Inactive Sensors

18
Q

search for a host to see if it has a FH sensor installed

A

Sensor Coverage Lookup