After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?
When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence. Which answer best defines Local Prevalence?
The Bulk Domain Search tool contains Domain information along with which of the following?
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?