CrowdStrike's Falcon Forensics optimizes the collection of point data and forensic screening histories for robust analysis of cybersecurity incidents. Respondents can quickly identify relevant data with predefined dashboards to speed up the investigation.
CrowdStrike's Falcon Forensics optimizes the collection of point data and forensic screening histories for robust analysis of cybersecurity incidents. Respondents can quickly identify dashboard data with dashboards defined to speed up the investigation.
BENEFITS OF FALCON FORENSICS
THE ONLY SOLUTION TO COLLECT AND ANALYZE DETAILED FORENSIC DATA
SIMPLIFY FORENSIC DATA COLLECTION AND ANALYSIS
Falcon Forensics offers data collection while performing screening analyses during an investigation. Forensic security often involves time-consuming searches with multiple tools. Simplify your collection and analysis in one solution to speed up screening.
SPEED UP RESPONSE TIME AND IMPROVE ATTACKER ACTIVITY.
Falcon Forensics automates data collection and provides information about an incident. Responders can access the entire threat context without lengthy queries or full collections of disk images.
FEATURES OF FALCON FORENSICS
HOW FALCON FORENSICS WORKS
Extended visibility with predefined dashboards
Provides incident responders with a single solution to analyze large amounts of historical and real-time data to uncover vital information for triaging an incident.
Identify attacker activity quickly with multiple predefined dashboards to provide specific information about an incident.
See trends over the past 24 hours with the deployment status dashboard.
Examine a high-level view of telemetry in a single system with the host information panel.
Use the Quick Wins Dashboard to quickly identify possible misconfigurations and hacker activity with predefined dashboard groupings.
Gather and analyze multiple artifacts for a single system and time period in the Host Timeline Dashboard. Use this panel to get a visual representation of the artifacts for a specific timeline of events.
Increase the experience with full remediation context
Automate data collection and eliminate time-consuming queries with a convenient console to view relevant artifacts pertaining to your search.
Track attacker activity by analyzing the Master File Table (MFT), shim cache, shellbags, and other artifacts in your organization.
Use query capabilities in predefined panes to focus on the attacker's specific activity.
Discover an attacker's activity that may have occurred prior to Falcon EDR monitoring.
Eliminate complex processes
Manage large-scale deployments with ease. Deploy Falcon Forensics at any scale, from dozens to hundreds of multiple endpoints.
Take advantage of one for CrowdStrike Cloud processing.
Use CrowdStrike Real Time Response for rapid deployment.
Robust artifact collection types
Falcon Forensics collects a set of artifact type categories to support the investigations of incident response teams. Data Types include: Directory and File Metadata, File Hashes, Network Data, Detailed Process Lists, Services and Driver Enumeration, Environment Variables, Scheduled Tasks, User and Group Reports.
Event log information
Registration information
Process execution artifacts
Common persistence mechanisms
System Requirements:
CPU: 1.8 GHz dual core processor
RAM: 2 GB
HDD/SSD: 50 GB of free space on main drive
Operating system: Microsoft Windows 10, Microsoft Windows 8 32-bit, Microsoft Windows 7 32-bit, and Microsoft Windows Vista 32-bit
Resolution: 1024 × 768
Supported Operating Systems
Mac OS X 10.5x (Leopard), Mac OS X 10.6 (Snow Leopard), Mac OS X 10.7 (Lion), Mac OS X 10.7 (Mountain Lion), OS X 10.9 (Mavericks), and Mac OS X 10.10 (Yosemite)
Hardware requirements
Memory - 1 GB RAM and more
Free disk space - 50 MB
System type - 32-bit and 64-bit OS
You don't know what software you need or you haven't found what you were looking for? We have a team ready to help you choose the right software for your company.