CrowdStrike

CrowdStrike

EDR(Falcon Insight)

CrowdStrike's Falcon Insight is a product in the EDR (Endpoint Detection and Response) area that enables threat detection (*), investigation, and response functions for terminals with agents installed.
*Falcon Prevent (NGAV) not only detects but also blocks threats, but Falcon Insight enables further investigation and countermeasures.

Since the logs that record the behavior of the terminals are sent to the CrowdStrike cloud side, the logs of all terminals can be viewed on the management console, and the information necessary for investigation can be grasped in real time. increase.
In addition, regardless of the platform of the terminal (WindowsOS, MacOS, LinuxOS), by enabling network isolation and remote control of the terminal from the management console, it will be possible to quickly respond and recover after detection is confirmed.

(1) Easy-to-understand GUI and search screen

Behavior logs collected from terminals can be viewed from the management console, and all collected logs can be viewed regardless of detection. In addition to arbitrarily searching from search sentences, dashboards focusing on specific searches such as hosts, hashes, IP addresses, etc. are also provided as presets, enabling easy investigation.

Easy-to-understand GUI and search screen

(2) When a problem is detected, quickly and safely isolate it remotely

It is possible to remotely isolate terminals and operate with the Real-Time-Response function.

Terminals can be isolated from the network and commands can be executed remotely from the management console regardless of platform (Windows, Mac, Linux).

Even when the device is isolated, it is possible to communicate with the CrowdStrike cloud, so operations such as sample acquisition/deletion can be performed remotely in a safe manner. In addition, simultaneous isolation of terminals related to the same incident and automatic isolation based on conditions can be realized.

Quickly remotely and securely isolate when a problem is detected

(3) Quickly block infringement by lateral movement

One of the features of Falcon Insight is that even if lateral movement occurs and an incident occurs across multiple terminals, it can be visualized on a single screen, making it easier to investigate the extent of impact. increase.

Quickly blocks breaches caused by lateral movement
In addition, CrowdStrike provides LongTermRepository and LogScale for long-term storage of logs required for investigations. Even if the retention period has passed, it is possible to store logs safely by using these functions.
  • LongTermRepository:
    Logs that record the behavior of terminals with CrowdStrike agents can be stored for a longer span than can be viewed in Insight. While the logs that can be viewed with Insight can be contracted for up to 90 days, LongTermRepository allows log storage for one year.
  • Log Scale:
    Allows you to keep logs of third-party products. With the increase in log volume due to the management of many security products,
    Since a large amount of logs can be stored at a low cost, it is possible to store logs for the purpose of a data lake.
    *Purchase of LongTermRepository is required to store CrowdStrike logs.
LogScale / LongTermRepository

Inquiry/Document request

In charge of Macnica CrowdStrike Co., Ltd.

Mon-Fri 8:45-17:30