Falcon Forensics

CrowdStrike's Falcon Forensics optimizes the collection of point data and forensic screening histories for robust analysis of cybersecurity incidents. Respondents can quickly identify relevant data with predefined dashboards to speed up the investigation.

Fabricantes: CrowdStrike
Category: Rede/Segurança
Learn more about Falcon Forensics

Request a Quote

What is Falcon Forensics?

CrowdStrike's Falcon Forensics optimizes the collection of point data and forensic screening histories for robust analysis of cybersecurity incidents. Respondents can quickly identify dashboard data with dashboards defined to speed up the investigation.

BENEFITS OF FALCON FORENSICS

THE ONLY SOLUTION TO COLLECT AND ANALYZE DETAILED FORENSIC DATA

SIMPLIFY FORENSIC DATA COLLECTION AND ANALYSIS

Falcon Forensics offers data collection while performing screening analyses during an investigation. Forensic security often involves time-consuming searches with multiple tools. Simplify your collection and analysis in one solution to speed up screening.

SPEED UP RESPONSE TIME AND IMPROVE ATTACKER ACTIVITY.

Falcon Forensics automates data collection and provides information about an incident. Responders can access the entire threat context without lengthy queries or full collections of disk images.

FEATURES OF FALCON FORENSICS

HOW FALCON FORENSICS WORKS

Extended visibility with predefined dashboards

Provides incident responders with a single solution to analyze large amounts of historical and real-time data to uncover vital information for triaging an incident.

Identify attacker activity quickly with multiple predefined dashboards to provide specific information about an incident.

See trends over the past 24 hours with the deployment status dashboard.

Examine a high-level view of telemetry in a single system with the host information panel.

Use the Quick Wins Dashboard to quickly identify possible misconfigurations and hacker activity with predefined dashboard groupings.

Gather and analyze multiple artifacts for a single system and time period in the Host Timeline Dashboard. Use this panel to get a visual representation of the artifacts for a specific timeline of events.

Increase the experience with full remediation context

Automate data collection and eliminate time-consuming queries with a convenient console to view relevant artifacts pertaining to your search.

Track attacker activity by analyzing the Master File Table (MFT), shim cache, shellbags, and other artifacts in your organization.

Use query capabilities in predefined panes to focus on the attacker's specific activity.

Discover an attacker's activity that may have occurred prior to Falcon EDR monitoring.

Eliminate complex processes

Manage large-scale deployments with ease. Deploy Falcon Forensics at any scale, from dozens to hundreds of multiple endpoints.

Take advantage of one for CrowdStrike Cloud processing.

Use CrowdStrike Real Time Response for rapid deployment.

Robust artifact collection types

Falcon Forensics collects a set of artifact type categories to support the investigations of incident response teams. Data Types include: Directory and File Metadata, File Hashes, Network Data, Detailed Process Lists, Services and Driver Enumeration, Environment Variables, Scheduled Tasks, User and Group Reports.

Event log information

Registration information

Process execution artifacts

Common persistence mechanisms

System Requirements:

CPU: 1.8 GHz dual core processor

RAM: 2 GB

HDD/SSD: 50 GB of free space on main drive

Operating system: Microsoft Windows 10, Microsoft Windows 8 32-bit, Microsoft Windows 7 32-bit, and Microsoft Windows Vista 32-bit

Resolution: 1024 × 768

Supported Operating Systems

Mac OS X 10.5x (Leopard), Mac OS X 10.6 (Snow Leopard), Mac OS X 10.7 (Lion), Mac OS X 10.7 (Mountain Lion), OS X 10.9 (Mavericks), and Mac OS X 10.10 (Yosemite)

Hardware requirements

Memory - 1 GB RAM and more

Free disk space - 50 MB

System type - 32-bit and 64-bit OS

You don't know what software you need or you haven't found what you were looking for?

You don't know what software you need or you haven't found what you were looking for? We have a team ready to help you choose the right software for your company.