EXPLORE

EXPLORE DETECTIONS

🔍
298 detections found

Falcon Sensor Heartbeat Timechart

This query plots a timechart showing the frequency of Falcon sensor heartbeat events across the environment.

CrowdStrike

Falcon Sensor Support Status

This query lists all active falcon sensors including their release date and support end date.

CrowdStrike

Falcon Sensor Support Status

This query lists all active falcon sensors including their release date and support end date.

CrowdStrike

Falcon Sensor Version Drift Monitoring (Linux)

Compares CrowdStrike Falcon sensor major/minor versions (x.xx) over time for each host. The query detects version changes, classifies them as upgrades or downgrades, and outputs the timestamp of the change along with the previous and current version values.

CrowdStrike

Falcon Sensor Version Drift Monitoring (Linux)

Compares CrowdStrike Falcon sensor major/minor versions (x.xx) over time for each host. The query detects version changes, classifies them as upgrades or downgrades, and outputs the timestamp of the change along with the previous and current version values.

CrowdStrike

Falcon Sensor Version Drift Monitoring (MacOS)

Compares CrowdStrike Falcon sensor major/minor versions (x.xx) over time for each host. The query detects version changes, classifies them as upgrades or downgrades, and outputs the timestamp of the change along with the previous and current version values.

CrowdStrike

Falcon Sensor Version Drift Monitoring (MacOS)

Compares CrowdStrike Falcon sensor major/minor versions (x.xx) over time for each host. The query detects version changes, classifies them as upgrades or downgrades, and outputs the timestamp of the change along with the previous and current version values.

CrowdStrike

Falcon Sensor Version Drift Monitoring (Windows)

Compares CrowdStrike Falcon sensor major/minor versions (x.xx) over time for each host. The query detects version changes, classifies them as upgrades or downgrades, and outputs the timestamp of the change along with the previous and current version values.

CrowdStrike

Falcon Sensor Version Drift Monitoring (Windows)

Compares CrowdStrike Falcon sensor major/minor versions (x.xx) over time for each host. The query detects version changes, classifies them as upgrades or downgrades, and outputs the timestamp of the change along with the previous and current version values.

CrowdStrike

File Write Events with Human-Readable File Sizes

The query lists file write events and converts the file size into readable units (KB, MB, GB, or TB), displaying timestamps, host details, filenames, and both raw and formatted file sizes. Reference: [GitHub CrowdStrike/logscale-community](https://github.com/CrowdStrike/logscale-community-content/blob/main/Queries-Only/Helpful-CQL-Queries/Case%20to%20convert%20Size%20to%20appropriate%20unit%20of%20measure.md)

CrowdStrike

File Write Events with Human-Readable File Sizes

The query lists file write events and converts the file size into readable units (KB, MB, GB, or TB), displaying timestamps, host details, filenames, and both raw and formatted file sizes. Reference: [GitHub CrowdStrike/logscale-community](https://github.com/CrowdStrike/logscale-community-content/blob/main/Queries-Only/Helpful-CQL-Queries/Case%20to%20convert%20Size%20to%20appropriate%20unit%20of%20measure.md)

CrowdStrike

Files Written to Removable Media

This query tracks files written to removable media (USB drives, external drives) across all platforms, aggregating the total data volume and file count per computer. It's useful for detecting potential data exfiltration attempts or monitoring removable media usage for compliance.

CrowdStrike

Files Written to Removable Media

This query tracks files written to removable media (USB drives, external drives) across all platforms, aggregating the total data volume and file count per computer. It's useful for detecting potential data exfiltration attempts or monitoring removable media usage for compliance.

CrowdStrike

Find events that are scheduled

T1053.005
CrowdStrike

Find events that are scheduled

T1053.005
CrowdStrike

Find events triggered at a specific time

T1053.005
CrowdStrike

Find events triggered at a specific time

T1053.005
CrowdStrike

Find events triggered at logon

T1053.005
CrowdStrike

Find events triggered at logon

T1053.005
CrowdStrike

Find events triggered at startup

T1053.005
CrowdStrike

Find events triggered at startup

T1053.005
CrowdStrike

Find events triggered on an event

T1053.005
CrowdStrike

Find events triggered on an event

T1053.005
CrowdStrike

Find hidden scheduled tasks

T1053.005
CrowdStrike
PreviousPage 6 of 13Next