Process and File Remediation with Real Time Response
January 7, 2021Ted Pan Tech Center
CrowdStrike goes beyond traditional endpoint protection by providing extensive visibility and remediation capabilities across multiple platforms, such as Windows, MacOS, and Linux. CrowdStrike Real Time Response provides a robust remote access tool that can remediate almost all types of malicious activity performed by an adversary.
Real time response provides a list of commands that we can execute as well as the ability to run customized scripts. Accessed directly from the CrowdStrike Falcon® console, it is easy to connect to a host directly and repair any damage with a comprehensive list of commands.
We can easily view running processes and kill any malicious process. This allows the analyst to stop processes that may be currently spreading throughout the environment.
In conjunction with the ability to kill a process, we can also remove files and directories from the file system.
Here we took a look at just a sliver of what Real Time Response is capable of, but even so, we can see that it’s extremely powerful, flexible, and easy to use. It allows responders to rapidly investigate incidents and remediate any issues identified and is available for Windows, MacOS, and Linux.