What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
What is an advantage of using the IP Search tool?
What happens when you open the full detection details?
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
Which of the following is NOT a valid event type?
When examining raw event data, what is the purpose of the field called ParentProcessId_decimal?