Skip to content
This repository was archived by the owner on Apr 10, 2024. It is now read-only.

joshhighet/csfalcon

ย 
ย 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

31 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

SPL/FQL Threat Hunting Reference Guide

A number of searches in Falcon Query Language (FQL), intended for use when hunting within Crowdstrike Falcon's Threat Graph - served by docsify

These searches may not represent all data available within your tenant and searches should be reviewed before they're operationalised.

Searches may create strange values for time fields due to Splunk transforms - this can be resolved with convert ctime(timestamp/1000)

โš ๏ธ You'll need to login to Crowdstrike before using any of the direct-search buttons.

CrowdStrike Community Work

spaceinvaders.mp4

csfalcon.thetadev.services

About

crowdstrike hunting, tips & triccs ๐Ÿฆ… ๐Ÿ–ฅ ๐Ÿ˜ถโ€๐ŸŒซ๏ธ

Resources

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages

  • HTML 100.0%