Critical Severity Detection

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Creates an incident when a CrowdStrike Falcon sensor detection is triggered with a Critical Severity

Attribute Value
Type Analytic Rule
Solution CrowdStrike Falcon Endpoint Protection
ID f7d298b2-726c-42a5-bbac-0d7f9950f527
Severity High
Status Available
Kind Scheduled
Required Connectors CefAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CommonSecurityLog DeviceProduct == "FalconHost"
DeviceVendor == "CrowdStrike"
?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to CrowdStrike Falcon Endpoint Protection