USER MANAGEMENT Flashcards
Describe capabilities of RTR Read Only Analyst role?
-RTR Read Only Analyst - Can run a core set of read-only response commands to perform reconnaissance
How to create a new user
Falcon Menu> Host setup and Management> Falcon Users > User Management > Input domain email/ First name/ Last Name/ Role
**To add users, you must have an administrative role for your Falcon subscription (Falcon Administrator or Falcon Intel Admin).
How to delete a user
Click on Falcon > Falcon Users > User Management > Additional Actions > Delete user
**Must have an administrative role for your Falcon subscription (Falcon Administrator or Falcon Intel Admin).
How to edit a user
Falcon Menu> Host setup and Management> Falcon Users > User Management
- Edit User name – make changes to the user’s first and last
name – a user’s email address can NOT be modified - Click > Additional Actions to Reset 2 factor authentication,
reset passwords, or delete user - Click > Assign Roles to assign one or more new roles to the
user, or remove a role
What does RTR do?
Real Time Response: Runs commands on Windows, Mac, Linux host directly from Falcon Console and can remotely connect to host from any location.
What capabilities does RTR provide Windows hosts?
- Retrieve memory dumps
- Query, create or modify registry keys
- Collect diagnostic logs and stateful information about a
host
What are some of the remediation tasks that RTR can perform?
RTR can perform many common response and remediation tasks:
- List running processes and kill processes
- Show network connections
- Navigate the file system, get or delete files, and perform many
file system operations
- Upload files
- Remotely restart or shut down a host
- Manage and run your own custom scripts or executables
Describe the capabilities of RTR Active Responder role?
RTR Active Responder - Can run all of the commands RTR Read Only Analyst can and more, including the ability to: extract files using the get command, run commands that modify the state of the remote host, and run certain custom scripts
Describe the capabilities of RTR Administrator role?
RTR Administrator - Can do everything RTR Active Responder can do, plus create custom scripts, upload files to hosts using the put command, and directly run executables using the run command
What determines a user’s permissions in the falcon console?
users role
How to manage user roles?
falcon menu> Host setup and management> Falcon users> User management>locate the user you want to manage>select 3 dots>view user details>assign roles>select roles as necessary> assign
To get falcon setup, what must be created?
Falcon admins