Queries in CrowdStrike
The crowdstrike plugin includes 33 queries:
Name | Description | Queries |
---|---|---|
Alerts are events identified by Falcon sensors on the hosts in your environment. This table uses the new Alerts API (replacing the deprecated Detects API). | ||
[Deprecated] Detections are events identified by Falcon sensors on the hosts in your environment. | ||
Hosts are endpoints that run the Falcon sensor. | ||
A threat actor, also known as a malicious actor, is any person or organization that intentionally causes harm in the digital sphere. | ||
Known CVE identified vulnerabilities in the environment. | ||
Users in the Falcon system. | ||
Zero Trust Assessments. | ||
Zero Trust Compliance. |