Skip to main content
Get RTR extracted file contents for the specified session and sha256. The following role is required to run this action:
  • Real Time Responder - Active Responder.
CrowdStrike returns the file in 7z format. In order to get the file’s true content, configure in the step config to save the output into a file - For more information, see Configuring your Step Settings. If not, the action will keep running/will return nothing and will not download the wanted file.

Parameters

Example Output

Workflow Library Example

Get Rtr Extracted File Contents with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop