An analyst is triaging a detection that has been categorized under the ‘Follow Through’ Objective Layer. Based on the Falcon technical documentation, which of the following adversary tactics is most likely to be observed within this specific layer?
In the ' Graph View ' of a detection, processes are connected by arrows. Which of the following does a yellow arrow connecting two processes indicate?
The primary purpose for running a Hash Search is to:
To speed up investigations, Falcon uses ' event workflows ' . Which of the following sentences best describes what event workflows are?