crowdstrike/fdr Dashboards

00 - FDR Package Announcement - Please Read
WidgetDescriptionType
FDR Package Migration # Important Changes **This package is being reduced to only include the parser. Please use the crowdstrike/fltr-core package instead.** Instructions for configuring the crowdstrike/fltr-core package can be found here: https://github.com/CrowdStrike/logscale-community-content/wiki/FLTR-Setup-and-Configuration # Migrating Content If you've made modifications to the crowdstrike/fdr package contents and wish to keep them, they can be exported by going to Settings -> Create a Package -> Export Package in this repo. Note
Detections by Instance
WidgetDescriptionType
Detections by Tactic

Hide Query

Show Query

Pie Chart
Detection Rate

Hide Query

Show Query

Time Chart
Map: Severity -> Technique

Hide Query

Show Query

Sankey
Detections by Severity

Hide Query

Show Query

Pie Chart
Detections by Technique

Hide Query

Show Query

Bar Chart
Detection by Attack

Hide Query

Show Query

Table
Detection: Grandparent File -> Parent File

Hide Query

Show Query

Sankey
Detection: Parent File -> File

Hide Query

Show Query

Sankey
Map: Technique -> Tactic

Hide Query

Show Query

Sankey
Detection Table Displays a summary of detected events based on Agent and Customer ID by username, file path, file name, severity, tactic, technique, etc then arranges them in table format.

Hide Query

Show Query

Table
Detections by Host

Hide Query

Show Query

Table
Detections by User

Hide Query

Show Query

Table
Detections by Type
WidgetDescriptionType
Detections by Tactic

Hide Query

Show Query

Pie Chart
Detection Rate

Hide Query

Show Query

Time Chart
Map: Severity -> Technique

Hide Query

Show Query

Sankey
Detections by Severity

Hide Query

Show Query

Pie Chart
Detections by Technique

Hide Query

Show Query

Bar Chart
Detection by Attack

Hide Query

Show Query

Table
Detection: Grandparent File -> Parent File

Hide Query

Show Query

Sankey
Detection: Parent File -> File

Hide Query

Show Query

Sankey
Map: Technique -> Tactic

Hide Query

Show Query

Sankey
Detection Table Displays a summary of detected events based on Agent and Customer ID by username, file path, file name, severity, tactic, technique, etc then arranges them in table format.

Hide Query

Show Query

Table
Detections by Host

Hide Query

Show Query

Table
Detections by User

Hide Query

Show Query

Table
Dev - Software Inventory
WidgetDescriptionType
Product Versions

Hide Query

Show Query

Pie Chart
Product Names

Hide Query

Show Query

Bar Chart
Software Inventory

Hide Query

Show Query

Table
Software Companies Displays a list of software companies and application information.

Hide Query

Show Query

Bar Chart
Software Inventory Note # FDR Requirements This dashboard runs on the secondary FDR data. FDR secondary data is not enabled by default, you may need to submit a ticket to CrowdStrike Support to enable the secondary data feed. You can check to see if your data includes secondary data by searching this data for: @path = fdrv2* To narrow down the data set use the CompanyName and then the ProductName drop-down parameters above. Note
Domain Search
WidgetDescriptionType
Domain Lookup Summary

Hide Query

Show Query

Table
Process and Domain Details

Hide Query

Show Query

Table
Number of Hosts hitting the domain

Hide Query

Show Query

Single Value
Domain Lookups by Host

Hide Query

Show Query

Bar Chart
Domain Lookups by Host (Table)

Hide Query

Show Query

Table
Lookup Details Shows all lookups for a given domain name/pattern

Hide Query

Show Query

Table
Workflow Note # Process and Domain Details Provide Domain Name and ComputerName (or aid) to display the data. Note
Workflow Note # Domain Lookup and Process Details Provide Domain Name to display the data. You can filter results by aid or Computer Name. Note
Workflow Note # Domain Lookup Summary Displays top domains, enter Domain Name to narrow the search. Note
Workflow Note # Domain Lookups by Host Displays top Hosts hitting the Domain(s). Enter Domain Name to narrow the search. Note
File Vantage
WidgetDescriptionType
File Integrity Alerts by User

Hide Query

Show Query

Bar Chart
File Vantage Alerts

Hide Query

Show Query

Table
File Vantage Alerts by Criticality

Hide Query

Show Query

Pie Chart
File Integrity Alerts

Hide Query

Show Query

Time Chart
File Integrity Alerts by Operation

Hide Query

Show Query

Bar Chart
File Vantage Alerts by Platform Displays a list of file vantage alerts by platform.

Hide Query

Show Query

Pie Chart
File Vantage Alerts by File Name

Hide Query

Show Query

Pie Chart
File Integrity Alerts by Object

Hide Query

Show Query

Bar Chart
Hash Search
WidgetDescriptionType
File Execution Details (Specify FileName or SHA256)

Hide Query

Show Query

Table
File Execution by Host

Hide Query

Show Query

Pie Chart
File Written by Hosts

Hide Query

Show Query

Pie Chart
File Written Details (Specify ComputerName) This widget only shows result if a ComputerName is specified)

Hide Query

Show Query

Table
Written on Distinct Hosts

Hide Query

Show Query

Single Value
Execution Activity

Hide Query

Show Query

Time Chart
Execution History (Specify FileName or SHA256)

Hide Query

Show Query

Table
Number of Hosts Executing File

Hide Query

Show Query

Single Value
Unique Host Executions

Hide Query

Show Query

Time Chart
Workflow Note # Workflow Start by entering a file name or a SHA256 to see results for 'Execution History', File Execution Details', and 'File Written Details'. Note
Host Search
WidgetDescriptionType
Services Started

Hide Query

Show Query

Table
Network Connection Destinations

Hide Query

Show Query

World Map
Parent to Child Process

Hide Query

Show Query

Sankey
Listening Ports

Hide Query

Show Query

Table
Top DNS Requests

Hide Query

Show Query

Table
Detections: Map Tactic Technique

Hide Query

Show Query

Sankey
User Logons

Hide Query

Show Query

Table
Schedule Tasks

Hide Query

Show Query

Table
Network Connections Count

Hide Query

Show Query

Table
Detections

Hide Query

Show Query

Table
Packed Executable Written

Hide Query

Show Query

Single Value
Unique Executables Written

Hide Query

Show Query

Single Value
Processes

Hide Query

Show Query

Table
Host Information

Hide Query

Show Query

Table
Workflow Note #Workflow Add a non-wildcard value to the aid parameter for the widgets to display results. Note
IP Search
WidgetDescriptionType
IP Summary

Hide Query

Show Query

Table
IP Connections by Host

Hide Query

Show Query

Table
IP Connections by Host

Hide Query

Show Query

Bar Chart
Process and IP

Hide Query

Show Query

Table
IP Lookup Details (Specify IP to show data) Displays a table of IP address details including computer ID, the first and last lookup, etc. then limits the results to the first 199 entries.

Hide Query

Show Query

Table
Monitor Deployment
WidgetDescriptionType
Active Sensors

Hide Query

Show Query

World Map
Number of Hosts

Hide Query

Show Query

Time Chart
Hosts by Platform

Hide Query

Show Query

Pie Chart
Hosts by Platform

Hide Query

Show Query

Table
Process Context Events
WidgetDescriptionType
Process - Network Events

Hide Query

Show Query

Table
Context Events by Type

Hide Query

Show Query

Pie Chart
Files Written Displays a list of files that have been written.

Hide Query

Show Query

Table
Original Processes Displays a record of an original process from the command line, with an accompanying file name.

Hide Query

Show Query

Table
Files Deleted

Hide Query

Show Query

Table
Destination IPs

Hide Query

Show Query

Pie Chart
DNS Requests

Hide Query

Show Query

Table
All Context Events

Hide Query

Show Query

Event List
Image Hash Events

Hide Query

Show Query

Table
Workflow Note # Workflow Start by entering a filename. The aid is optional, but will constrain (and speed up) the search if you have it. If you find an interesting process copy the ProcessId and paste it in the parameter above to show the context events below. Note
Threat Hunting
WidgetDescriptionType
Check random ASEPs

Hide Query

Show Query

Table
Top Country Destinations

Hide Query

Show Query

Table
Suspicious Leads

Hide Query

Show Query

Table
High Entropy Domains Displays a list of high entropy domains using Akamai and limits the results to the first 20 entries.

Hide Query

Show Query

Table
Open Ports

Hide Query

Show Query

Table
Top IP Destinations

Hide Query

Show Query

Table
Potential Script Obfuscation Script content rated by Shanon entropy to look for randomness as a proxy for obfuscation attempts.

Hide Query

Show Query

Table
Unoriginal Filename

Hide Query

Show Query

Event List
Required Please specify the aid parameter in order to see results for the 'Open Ports' widget. Note