CrowdStrike Falcon IT Readiness Hub

Internal Training Curriculum & Real-Time Alert Triage Playbook

Progress 0%
0/4
Self-Paced IT Curriculum

CrowdStrike University IT Fundamentals to Triage Track

These four complimentary modules provide the knowledge required for frontline IT support to verify endpoint sensor health, assess Falcon detection alerts, review process trees, and respond to security events.

Total Time: ~2 hours 20 mins No Training Credits Required (Free Tier) Practical Checkpoints Included
Phase 1 • Platform Foundations
50 mins

FALCON 101: Falcon Platform Essentials

Master the layout of the Falcon console, understand agent communication back to the cloud, and locate hosts using host management.

Key Learning Points:
  • Sensor communication architecture over outbound TCP port 443
  • How to identify hosts in Reduced Functionality Mode (RFM)
  • Navigating the Activity App vs Host Management App
Tenant Checkpoint:

Log into your live Falcon tenant, navigate to Host Setup > Host Management, and filter by "RFM: Yes" to audit unprotectable machines.

Status: Pending Launch Course
Phase 2 • IT Operations & Hygiene
25 mins

FALCON 185: Falcon for IT Fundamentals

Understand how IT operations teams use Falcon for asset visibility, managing sensor update channels, and day-to-day endpoint troubleshooting.

Key Learning Points:
  • Inventory discovery and identifying rogue unmanaged devices
  • Managing static vs dynamic host sensor groups
  • Staging sensor update policies across pilot and production tiers
Tenant Checkpoint:

Review your organisation's current Sensor Update Policy to check whether devices are pinned to an older version or tracking the latest builds.

Status: Pending Launch Course
Phase 3 • Detection Logic & ATT&CK
25 mins

FALCON 109: MITRE ATT&CK & Detection Methods

Understand why Falcon triggers alerts. Learn to distinguish between static file indicators (IOCs) and adversary behaviours (IOAs).

Key Learning Points:
  • IOCs (Signatures/Hashes) vs IOAs (Indicators of Attack/Behaviours)
  • How to interpret MITRE tactics: Initial Access, Execution, Persistence, Lateral Movement
  • Distinguishing between Machine Learning pre-execution blocks and runtime IOA blocks
Tenant Checkpoint:

Open any alert in Activity > Endpoint Detections and click the "MITRE ATT&CK" badge to see the mapped adversary technique.

Status: Pending Launch Course
Phase 4 • Incident Triage & Scenarios
38 mins

CCFR: Falcon Responder Practice Exam

Test alert triage capabilities with real-world scenarios. Covers process tree analysis, command-line arguments, and containment actions.

Key Learning Points:
  • Reading parent-child process execution trees (e.g. Outlook spawning PowerShell)
  • De-obfuscating Base64 encoded CLI parameters and download cradles
  • Decision threshold: When to apply Network Containment vs when to mark as False Positive
Practical Drill:

Complete all scenario questions, record the rationale behind missed answers, and discuss them during team catch-ups.

Status: Pending Launch Exam