What web browsers were running at a given time?

ID: Q1019

CrowdStrike is a detection platform, not a logging platform, so not all ProcessRollup events might be logged.



  • Mac, Linux and Windows systems with the Falcon Agent
  • Chrome, Firefox, Safari, and Edge web browsers

Not Covered

  • Other browsers (including Chromium)
  • One of those four browsers, but have had their process name changed

The following data source(s) are needed for this approach to the question.

  • CrowdStrike: ProcessRollup

More information on Splunk.

  1. Query filtering the known browsers in execution event logs.
  2. Type: splunk-query
  3. Value: ComputerName="{hostname}" event_simpleName=ProcessRollup* ImageFileName IN ("chrome", "firefox", "safari", "edge") | table _time, CommandLine, ImageFileName