Which of the following is an example of actor actions during the RECONNAISSANCE phase of the Cyber Kill Chain?
The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because:
When performing a raw event search via the Events search page, what are Event Actions?
In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc.Which command would be the appropriate choice?