product
- What you can do with CrowdStrike
- CrowdStrike Modules Falcon
- NGAV(Prevent/USB/FW)
- EDR(Falcon Insight)
- Threat Hunting (OverWatch)
- IT Asset Management (Discover)
- Vulnerability Management (Spotlight)
- Threat Intelligence (Intelligence/Sandbox)
- Identity Protection (ITD/ITP)
- Cloud Security (CNAPP)
- EASM(Surface)
service
Application for evaluation machine
- FAQ

CrowdStrike
CrowdStrike
EDR(Falcon Insight)
CrowdStrike's Falcon Insight is a product in the EDR (Endpoint Detection and Response) area that enables threat detection (*), investigation, and response functions for terminals with agents installed.
*Falcon Prevent (NGAV) not only detects but also blocks threats, but Falcon Insight enables further investigation and countermeasures.
Since the logs that record the behavior of the terminals are sent to the CrowdStrike cloud side, the logs of all terminals can be viewed on the management console, and the information necessary for investigation can be grasped in real time. increase.
In addition, regardless of the platform of the terminal (WindowsOS, MacOS, LinuxOS), by enabling network isolation and remote control of the terminal from the management console, it will be possible to quickly respond and recover after detection is confirmed.
(1) Easy-to-understand GUI and search screen
Behavior logs collected from terminals can be viewed from the management console, and all collected logs can be viewed regardless of detection. In addition to arbitrarily searching from search sentences, dashboards focusing on specific searches such as hosts, hashes, IP addresses, etc. are also provided as presets, enabling easy investigation.

(2) When a problem is detected, quickly and safely isolate it remotely
It is possible to remotely isolate terminals and operate with the Real-Time-Response function.
Terminals can be isolated from the network and commands can be executed remotely from the management console regardless of platform (Windows, Mac, Linux).
Even when the device is isolated, it is possible to communicate with the CrowdStrike cloud, so operations such as sample acquisition/deletion can be performed remotely in a safe manner. In addition, simultaneous isolation of terminals related to the same incident and automatic isolation based on conditions can be realized.

(3) Quickly block infringement by lateral movement
One of the features of Falcon Insight is that even if lateral movement occurs and an incident occurs across multiple terminals, it can be visualized on a single screen, making it easier to investigate the extent of impact. increase.

- LongTermRepository:
Logs that record the behavior of terminals with CrowdStrike agents can be stored for a longer span than can be viewed in Insight. While the logs that can be viewed with Insight can be contracted for up to 90 days, LongTermRepository allows log storage for one year. - Log Scale:
Allows you to keep logs of third-party products. With the increase in log volume due to the management of many security products,
Since a large amount of logs can be stored at a low cost, it is possible to store logs for the purpose of a data lake.
*Purchase of LongTermRepository is required to store CrowdStrike logs.

Inquiry/Document request
In charge of Macnica CrowdStrike Co., Ltd.
- TEL:045-476-2010
- E-mail:crowdstrike_info@macnica.co.jp
Weekdays: 9:00-17:00