The Hash Search is an Investigate tool that allows you to search for a file hash and view its process execution history across all hosts in your environment. It shows information such as process name, command line, parent process name, parent command line, etc. for each execution of the file hash. Wildcard searches are permitted with the Hash Search, as long as they are at least four characters long. The Hash Search is available on Linux, as well as Windows and Mac OS X. Module Load History is presented in aHash Search, along with other information such as File Write History and Detection History.
[Reference: https://www.crowdstrike.com/blog/tech-center/hash-search-in-crowdstrike-falcon/, , , ]
Submit