Describe capabilities of RTR Read Only Analyst role?
-RTR Read Only Analyst - Can run a core set of read-only response commands to perform reconnaissance
How to create a new user
Falcon Menu> Host setup and Management> Falcon Users > User Management > Input domain email/ First name/ Last Name/ Role
**To add users, you must have an administrative role for your Falcon subscription (Falcon Administrator or Falcon Intel Admin).
How to delete a user
Click on Falcon > Falcon Users > User Management > Additional Actions > Delete user
**Must have an administrative role for your Falcon subscription (Falcon Administrator or Falcon Intel Admin).
How to edit a user
Falcon Menu> Host setup and Management> Falcon Users > User Management
What does RTR do?
Real Time Response: Runs commands on Windows, Mac, Linux host directly from Falcon Console and can remotely connect to host from any location.
What capabilities does RTR provide Windows hosts?
What are some of the remediation tasks that RTR can perform?
RTR can perform many common response and remediation tasks:
- List running processes and kill processes
- Show network connections
- Navigate the file system, get or delete files, and perform many
file system operations
- Upload files
- Remotely restart or shut down a host
- Manage and run your own custom scripts or executables
Describe the capabilities of RTR Active Responder role?
RTR Active Responder - Can run all of the commands RTR Read Only Analyst can and more, including the ability to: extract files using the get command, run commands that modify the state of the remote host, and run certain custom scripts
Describe the capabilities of RTR Administrator role?
RTR Administrator - Can do everything RTR Active Responder can do, plus create custom scripts, upload files to hosts using the put command, and directly run executables using the run command
What determines a user’s permissions in the falcon console?
users role
How to manage user roles?
falcon menu> Host setup and management> Falcon users> User management>locate the user you want to manage>select 3 dots>view user details>assign roles>select roles as necessary> assign
To get falcon setup, what must be created?
Falcon admins