the question is asking "system time of xxx". the "*FileWritten event" is the event, the focus is the system time, so the answer is A
Document : Falcon Documentation > Event Investigation > Events > Events Full Reference (Events Data Dictionary)
ContextTimeStamp_decimal
The time at which an event occurred on the system, as seen by the sensor (in decimal, non-hex format). Not to be confused with timestamp which is the time the event was received by the cloud.
(A) ContextTimeStamp_decimal: This field specifically refers to the time the event was captured by the security system, which is what you're interested in for a FileWritten event.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
examtopics3000
Highly Voted 1 year, 3 months agoalanalanalan
Most Recent 4 months, 4 weeks agosilva222222
6 months, 3 weeks agogr23
10 months, 2 weeks agoJoe_Kwok
1 year, 3 months ago