Active Alert Triage Flow
3 simple steps to locate, deobfuscate, remediate, and verify an endpoint alert with edge security.
Locate Alert in CrowdStrike Falcon
Grab the flagged command line from your Falcon Activity V2 console in 3 quick steps.
Open the Alert
In Falcon, navigate to Activity (V2) ➔ Detections and click the new alert to open the incident graph.
Click Flagged Process
In the execution tree, click the flagged process node (usually powershell.exe or cmd.exe).
Copy Command Line
In the drawer that slides out, copy the full Command Line. Then paste it into Step 2 below.
Falcon terminated the execution in <3s. 0 payload written to disk. Usually safe with routine RTR verification.
The script ran to completion. Network containment and immediate forensic review required.
Parent process hint: Parent is explorer.exe = user ran via Win+R fake captcha lure (ClickFix). Parent is WINWORD.EXE = phishing macro document.
Paste Alert & Run Edge AI Triage
Paste raw PowerShell, command line, or Falcon JSON. Edge AI executes on Cloudflare with zero data retention.
Next Recommended Steps & Remediation
Immediate action directives, safe RTR commands, and post-RTR verification.
No Alert Triaged Yet
Paste an alert command line or script in Step 2 above and click "Analyze Alert with Edge AI" to receive immediate containment directives, safe RTR commands, and resolution notes.
Analyzing Alert on Cloudflare Workers AI Edge...
Deobfuscating script syntax, evaluating blast radius, and preparing safe RTR commands...
Run Safe Real-Time Response (RTR) Command
Connect to host via RTR in Falcon and execute the non-hanging query below:
reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Run
🔁 Verify RTR Terminal Output Interactive Follow-Up
Paste the output from your Falcon RTR terminal to receive an instant clean-bill verdict and containment sign-off.
Decoded Script & Attack Breakdown
Mimecast URL Protect (TTP) & Gateway Action Plan
Standardized resolution note ready to paste directly into Falcon console:
Friendly, reassuring message to send to the affected user:
Execute in Falcon Advanced Event Search to hunt for identical staging IPs or commands across all 545 endpoints:
CrowdStrike Enablement & Reference Hub
4 foundational CrowdStrike University courses, real-world operational drills, and frontline runbooks.
📚 CrowdStrike University Learning Track (~2h 20m total)
FALCON 101: Platform Essentials
Console navigation, agent telemetry over outbound TCP 443, and auditing hosts in Reduced Functionality Mode (RFM).
FALCON 185: Falcon for IT Fundamentals
Asset visibility, rogue device discovery, host groups (HG-Prod-Win-Workstations), and update policies (SU-Win-Prod).
SU-Win-Prod to check version pinning across workstations and servers.
FALCON 109: Detection Methods & MITRE
Distinguishing between static file signatures (IOCs) and behavioral adversary patterns (IOAs) mapped across MITRE ATT&CK.
CCFR: Responder Practice Exam
Practice questions testing parent process trees, command lines, and containment decisions.
🎯 Frontline Incident Decision Drills
Drill 1: Encoded PowerShell from Office
Phish #812WINWORD.EXE -> powershell.exe -enc SQBFA...
What is the immediate priority action?
Drill 2: Host Returns After 35 Days
Lifecycle #545A returning laptop is absent from active Host Management due to the 30-day auto-purge. What is the procedure?
Drill 3: ClickFix & Fake Captcha Lure
Live Incidentexplorer.exe -> powershell.exe "@(0)...# Gateway Verification"
Falcon killed it in 2.3s. Network shows 0 bytes received; 0 files written. What next?
📖 Frontline Quick Reference Cheatsheets
Process Tree Archetypes
Real-Time Response (RTR) Rules
- RTR runs as NT AUTHORITY\SYSTEM: HKCU does not exist. Always query
HKLM\Software\Microsoft\Windows\CurrentVersion\Run. - Never run recursive Temp listings:
ls C:\Users\*\AppData\Local\Tempwill freeze RTR memory buffers. Cancel with Ctrl+C. - memdump / xmemdump: Disabled on all 545 hosts per policy to prevent production workstation freezing.
- Native instant commands:
ipconfig,ps, andnetstatreturn immediately without queuing.