Welcome to the CrowdStrike® Falcon CompleteTM team’s first “Tales from the Trenches” blog, where we describe a recent intrusion that shows how the Falcon Complete managed detection and response (MDR) service operates as an extension of the customer’s security team to quickly detect, investigate and contain an active attacker before they’re able to complete their goal. Once this … [Read more...] about How the Falcon Complete Team Stopped an RDP Attack [Part 1]
Falcon
How the Falcon Complete Team Stopped an RDP Attack [Part 2]
In Part 1 of this two-part “Tales from the Trenches” blog, we examined a stealthy Remote Desktop Protocol (RDP) intrusion uncovered by CrowdStrike® Falcon CompleteTM experts. In this installment, we’ll walk you through remediation efforts, highlighting Falcon Complete’s ability to directly eject a threat actor and bring the customer’s environment back to a clean, operational … [Read more...] about How the Falcon Complete Team Stopped an RDP Attack [Part 2]
PowerShell Hunting with CrowdStrike Falcon
Introduction Threat hunting is the active search for new and novel attack behaviors that aren’t detected by current automated methods of prevention and detection. Threat hunting starts with human analysts, who approach their challenge with the assumption that active intrusions are underway but hidden from the view of their layers of detection technology such as NGAV, network … [Read more...] about PowerShell Hunting with CrowdStrike Falcon
How to Use Custom Filters in Falcon Spotlight
Introduction This article and video will provide an overview of the power of custom filters in Falcon Spotlight. Spotlight provides customers with realtime data about the vulnerabilities in the environment. With custom filters, organizations can quickly sort that data to focus on critical assets, vulnerabilities and remediations. Those filters can then be saved for repeat use … [Read more...] about How to Use Custom Filters in Falcon Spotlight
2020 Fal.Con for Public Sector Conference Offered On Demand
The CrowdStrike® 2020 Fal.Con for Public Sector Virtual Cybersecurity Conference was held on June 24 — the second year for this one-day event and the first year it was a completely digital experience. More than 1,000 security professionals attended an exciting array of keynote addresses, breakout sessions and partner tech talks that were streamed online throughout the day. I’m … [Read more...] about 2020 Fal.Con for Public Sector Conference Offered On Demand
Sneak Peek: 2020 Fal.Con for Public Sector
Although the global COVID-19 pandemic has required the cancellation of many events this year, the CrowdStrike® 2020 Fal.Con for Public Sector conference is moving forward as an exciting, free online event — and it’s easier than ever to participate. Now in its second year, the conference will be held on Wednesday, June 24 at 11:00 a.m. ET. Sign up now on our 2020 Fal.Con for … [Read more...] about Sneak Peek: 2020 Fal.Con for Public Sector
Keynotes and Workshops to Attend at Fal.Con Unite 2019
The CrowdStrike® annual cybersecurity conference for customers is only weeks away and it promises to be the biggest and best yet! Fal.Con UNITE 2019, CrowdStrike Cybersecurity Conference will bring together the best and brightest cybersecurity specialists and IT professionals from organizations and industries around the world. They will gather on November 4-6 in San Diego, … [Read more...] about Keynotes and Workshops to Attend at Fal.Con Unite 2019
How to Get Better Protection with Falcon Prevent
Introduction This document and video will demonstrate how CrowdStrike’s Falcon Prevent offers superior next generation AV protection against all types of attacks through a single, lightweight agent and cloud delivered console. Video Simplified Management from the Cloud On the main Falcon dashboard, you see an overview of the events in our environment. On the right … [Read more...] about How to Get Better Protection with Falcon Prevent
How to Get Better Visibility with Falcon Insight
Introduction Falcon Insight is CrowdStrike’s EDR solution. Falcon Insight monitors endpoint activity and captures events and details that are critical to swiftly and effectively conduct investigations and forensic analysis. In addition to delivering automatic detection of attacker activity, it provides real time and historical visibility into endpoint activities. This enables … [Read more...] about How to Get Better Visibility with Falcon Insight
How to use Falcon Indicator Graph
X How to Contain an Infected System Hi, there. My name’s Peter Ingebrigtsen. And today, we’ve logged into the falcon.crowdstrike.com, or the Falcon User Interface. And what we’re going to do is take a look at some of our systems and recognize that some of them are either currently under attack or recently been under attack, and may have been compromised. And we’d like to … [Read more...] about How to use Falcon Indicator Graph