Active Alert Triage Flow < 90s SLA
Instant deobfuscation, containment guidance, and safe RTR remediation.
Open the Alert
Go to Activity (V2) โ Detections and click the new alert to open the incident graph.
Click Flagged Process
In the execution tree, click the flagged node (e.g. powershell.exe or cmd.exe).
Copy Command Line
In the slide-out drawer, copy the full Command Line, then paste it below.
Falcon terminated execution in <3s. 0 payload written to disk. Usually safe with routine RTR verification.
The script executed fully. Network containment and forensic triage required.
Parent hint: explorer.exe = Win+R lure (ClickFix). WINWORD.EXE = phishing macro.
Paste Alert Telemetry
Accepts raw command line, obfuscated PowerShell scripts, or Falcon event JSON.
Recommended Actions & Safe Remediation
Action directives, deobfuscated payload, and safe RTR commands.
Paste an alert command line or script in the input box above and click "Analyze Alert with Edge AI" to view containment directives, safe RTR scripts, and resolution notes.
Analyzing Alert on Cloudflare Workers AI Edge...
Deobfuscating script syntax, evaluating blast radius, and preparing safe RTR commands...
Run Safe Real-Time Response (RTR) Command
Connect to host via RTR in Falcon and execute the non-hanging query below:
reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Run
๐ Verify RTR Terminal Output Interactive Follow-Up
Paste the output from your Falcon RTR terminal to receive an instant clean-bill verdict and containment sign-off.
Decoded Script & Attack Breakdown
Mimecast URL Protect (TTP) & Gateway Action Plan
Standardized resolution note ready to paste directly into Falcon console:
Friendly, reassuring message to send to the affected user:
Execute in Falcon Advanced Event Search to hunt for identical staging IPs or commands across all 545 endpoints:
CrowdStrike Enablement & Reference Hub
4 foundational CrowdStrike University courses, real-world operational drills, and frontline runbooks.
๐ CrowdStrike University Learning Track (~2h 20m total)
FALCON 101: Platform Essentials
Console navigation, agent telemetry over outbound TCP 443, and auditing hosts in Reduced Functionality Mode (RFM).
FALCON 185: Falcon for IT Fundamentals
Asset visibility, rogue device discovery, host groups (HG-Prod-Win-Workstations), and update policies (SU-Win-Prod).
SU-Win-Prod to check version pinning across workstations and servers.
FALCON 109: Detection Methods & MITRE
Distinguishing between static file signatures (IOCs) and behavioral adversary patterns (IOAs) mapped across MITRE ATT&CK.
CCFR: Responder Practice Exam
Practice questions testing parent process trees, command lines, and containment decisions.
๐ฏ Frontline Incident Decision Drills
Drill 1: Encoded PowerShell from Office
Phish #812WINWORD.EXE -> powershell.exe -enc SQBFA...
What is the immediate priority action?
Drill 2: Host Returns After 35 Days
Lifecycle #545A returning laptop is absent from active Host Management due to the 30-day auto-purge. What is the procedure?
Drill 3: ClickFix & Fake Captcha Lure
Live Incidentexplorer.exe -> powershell.exe "@(0)...# Gateway Verification"
Falcon killed it in 2.3s. Network shows 0 bytes received; 0 files written. What next?
๐ Frontline Quick Reference Cheatsheets
Process Tree Archetypes
Real-Time Response (RTR) Rules
- RTR runs as NT AUTHORITY\SYSTEM: HKCU does not exist. Always query
HKLM\Software\Microsoft\Windows\CurrentVersion\Run. - Never run recursive Temp listings:
ls C:\Users\*\AppData\Local\Tempwill freeze RTR memory buffers. Cancel with Ctrl+C. - memdump / xmemdump: Disabled on all 545 hosts per policy to prevent production workstation freezing.
- Native instant commands:
ipconfig,ps, andnetstatreturn immediately without queuing.