How long does detection data remain in the CrowdStrike Cloud before purging begins?
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?
The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?
In the "Full Detection Details", which view will provide an exportable text listing of events like DNS requests. Registry Operations, and Network Operations?
You receive an email from a third-party vendor that one of their services is compromised,thevendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?