The help desk is reporting an increase in calls related to user accounts being locked out over the last few days. You suspect that this could be an attack by an adversary against your organization. Select the best hunting hypothesis from the following:
You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc.Which command would be the appropriate choice?
What do you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search?
Which of the following is a recommended technique to find unique outliers among a set of data in the Falcon Event Search?
Which of the following is a way to create event searches that run automatically and recur on a schedule that you set?