Solved

Immediate Threats - Crowdstrike Doesn't show file execution logs

  • 27 March 2023
  • 1 reply
  • 44 views

Userlevel 1
Badge

Hi All, I was analyzing few immediate threat reports and saw some binaries were executed by Cymulate and not prevented by Crowdstrike. But a hash search in CS doesn’t show any signs of the file execution? Why does this happen? Is this something to do with the file exclusion?

icon

Best answer by Shiraz 27 March 2023, 14:34

View original

1 reply

Userlevel 2
Badge +1

Hi @nithun_chand 

  1. Have you experienced any issues with your CS in other assessments, either within this module or in other modules?
  2. We have a document detailing CS exclusions. Please review it and check if there are any configurations you may have missed.

 

 

Shiraz

Product Manager

Cymulate

 

Reply