The Bulk Domain Search tool contains Domain information along with which of the following?
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
From the Detections page, how can you view 'in-progress' detections assigned to Falcon Analyst Alex?
Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?
The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?