Getting Started with CrowdStrike CQL

A very quick way to get started using CrowdStrike CQL. If you like the material, please check out our available courses: https://www.blueteamwins.com/udemycou... Base Search: | time := formatTime("%Y-%m-%d %H:%M:%S", field=@timestamp, locale=en_US, timezone=Z) |select([time,CommandLine,UserName,FileName,ImageFileName,SHA256HashData,TargetProcessId])