joshhighet / csfalcon

crowdstrike hunting, tips & triccs πŸ¦… πŸ–₯ πŸ˜Άβ€πŸŒ«οΈ

Home Page:https://csfalcon.thetadev.services

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

SPL/FQL Threat Hunting Reference Guide

A number of searches in Falcon Query Language (FQL), intended for use when hunting within Crowdstrike Falcon's Threat Graph - served by docsify

These searches may not represent all data available within your tenant and searches should be reviewed before they're operationalised.

Searches may create strange values for time fields due to Splunk transforms - this can be resolved with convert ctime(timestamp/1000)

⚠️ You'll need to login to Crowdstrike before using any of the direct-search buttons.

CrowdStrike Community Work

spaceinvaders.mp4

csfalcon.thetadev.services

About

crowdstrike hunting, tips & triccs πŸ¦… πŸ–₯ πŸ˜Άβ€πŸŒ«οΈ

https://csfalcon.thetadev.services


Languages

Language:HTML 100.0%