CrowdStrike Falcon Endpoint Detection and Response Administration Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-043
Duration5 days
LevelFoundation to Intermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Security teams cannot respond consistently when endpoint telemetry is incomplete, prevention policies are poorly tuned, and analysts must work through large volumes of untriaged detections. CrowdStrike Falcon administrators need more than console familiarity: they must understand how sensors, host groups, policies, detections, investigations, containment actions, and integrations work together. This five-day course prepares participants to operate Falcon as an endpoint detection and response platform that supports measurable incident-response procedures rather than a collection of isolated security features.

Participants learn to administer the Falcon console, plan and validate sensor deployment, organise assets with host groups and tags, and configure prevention and detection policies for different endpoint populations. The course covers Falcon Insight XDR event data, detection triage, process-tree analysis, indicator searching, real-time response, network containment, and remediation workflows. Participants also work with Falcon Discover asset visibility, Falcon Fusion SOAR workflows, role-based access control, reporting, and API-led integration concepts. They gain practical methods for reducing false-positive noise while retaining evidence needed for investigations and audit review.

Instructor-led demonstrations are followed by guided exercises in a Falcon training environment. Participants investigate realistic endpoint incidents, tune a policy without weakening protection, contain a simulated compromised host, collect response evidence, and route actions through an automated workflow. Each participant leaves with a documented Falcon EDR administration runbook and a 30-day implementation plan covering sensor rollout, policy structure, triage procedures, escalation points, and reporting measures. This course is suited to teams establishing Falcon operations, standardising an existing deployment, or moving analysts into an EDR administration role.

Course objectives

By the end of this course, participants will be able to:

  • Configure Falcon sensor deployment packages, update policies, and installation verification procedures for Windows, macOS, and Linux endpoints
  • Design host group, tag, and policy assignments that apply appropriate controls to servers, workstations, and high-risk assets
  • Tune prevention and detection policies using documented exceptions, severity criteria, and change-control evidence
  • Triage Falcon detections by analysing event timelines, process trees, command lines, and associated endpoint activity
  • Investigate suspicious behaviour with Falcon Insight XDR search filters and indicator-based queries
  • Execute Real Time Response and network containment actions while preserving incident evidence and authorisation records
  • Build Falcon Fusion SOAR workflows for notification, enrichment, escalation, and repeatable response actions
  • Produce a Falcon administration runbook and 30-day improvement plan for endpoint coverage, alert handling, and reporting

Benefits of attending

For you

  • Build credible hands-on experience administering CrowdStrike Falcon policies, sensors, host groups, and response actions
  • Develop a repeatable method for moving from a Falcon detection to an evidence-backed triage decision
  • Gain practical confidence using Real Time Response and network containment during endpoint incidents
  • Create a portfolio-ready Falcon administration runbook that demonstrates operational ownership of an EDR platform
  • Prepare for endpoint security, SOC engineering, and incident-response responsibilities involving CrowdStrike deployments

For your organisation

  • Increase endpoint coverage accuracy through structured sensor deployment, health validation, and host-group design
  • Reduce analyst time spent on low-value alerts through documented detection triage and policy-tuning practices
  • Improve containment speed by defining authorised Real Time Response and network isolation workflows
  • Strengthen auditability with role-based access, exception records, incident evidence, and administration runbooks
  • Standardise Falcon operations across security and infrastructure teams through a shared 30-day improvement plan

Target competencies

Falcon policy administrationEndpoint sensor deploymentDetection triageProcess-tree investigationHost containmentSOAR workflow design

Who should attend

  • Endpoint Security Administrators — who configure Falcon sensors, policies, endpoint groups, and access controls
  • SOC Analysts — who must investigate Falcon detections and escalate endpoint incidents with defensible evidence
  • Incident Responders — who require rapid host containment, evidence collection, and remote response procedures
  • Cyber Security Engineers — who integrate Falcon telemetry and workflows into the wider security architecture
  • IT Infrastructure Administrators — who support sensor rollout across Windows, macOS, Linux, and server estates
  • Security Operations Managers — who need consistent EDR operating procedures, coverage measures, and reporting

Requirements and prerequisites

Participants should understand basic endpoint administration, including Windows services, macOS or Linux endpoint concepts, software deployment, and user or group permissions. Familiarity with TCP/IP, DNS, common malware behaviours, security alerts, and incident-response terminology is expected. Experience reviewing logs or working in a SIEM is helpful but not essential. Participants should be comfortable navigating a web console and interpreting process names, command lines, and IP addresses. Prior CrowdStrike Falcon experience, scripting ability, threat-hunting expertise, or formal security certification is not required; complete beginners should expect a technically practical introduction rather than a general cyber-security awareness course.

Training methodology

The course combines focused instructor-led sessions with guided configuration and investigation labs in a CrowdStrike Falcon training environment. Participants deploy and validate sensors, create host groups, apply policies, examine Falcon Insight XDR detections, and use Real Time Response under defined incident-authorisation rules. Scenario-based case work uses suspicious PowerShell activity, persistence indicators, and lateral-movement evidence to connect console actions with operational decisions. Small-group reviews compare tuning choices and escalation paths. The final workshop converts lab learning into an organisation-specific administration runbook and 30-day rollout plan.

Course outline

Day 1: Falcon platform foundations and sensor operations

  • CrowdStrike Falcon platform architecture and module relationships
  • Falcon console navigation, tenant structure, and operational roles
  • Falcon sensor architecture for Windows, macOS, and Linux
  • Sensor installation packages, deployment methods, and provisioning tokens
  • Sensor version management, update policies, and staged rollout planning
  • Sensor health checks, connectivity status, and coverage validation
  • Host inventory fundamentals, device attributes, tags, and host groups

Workshop: Participants build a sensor rollout worksheet and validate a simulated endpoint population for installation status, version compliance, and missing coverage.

Day 2: Prevention policies, access control, and asset visibility

  • Prevention policy hierarchy and host-group policy assignment
  • Malware prevention, exploit mitigation, and behavioural detection settings
  • Policy exceptions, allowlisting decisions, and compensating-control records
  • Detect-only versus prevent modes and safe policy-testing methods
  • Role-based access control, user roles, and least-privilege administration
  • Falcon Discover asset inventory, application visibility, and unmanaged asset identification
  • Configuration change control, policy baselines, and administrative audit trails

Workshop: Participants design host groups and prevention policies for a mixed workstation and server estate, then document one justified exception through change control.

Day 3: Detection triage and endpoint investigation

  • Falcon Insight XDR detection lifecycle, severity, status, and ownership
  • Detection triage criteria, prioritisation queues, and escalation thresholds
  • Event timeline analysis and process-tree reconstruction
  • Command-line, hash, user, network, and parent-child process interpretation
  • Indicator searching with Falcon Insight XDR filters and event fields
  • MITRE ATT&CK technique mapping for endpoint behaviours
  • Investigation notes, evidence capture, and incident handover standards

Workshop: Participants investigate a simulated suspicious PowerShell detection, reconstruct the execution chain, identify ATT&CK techniques, and produce an escalation note.

Day 4: Response actions, containment, and automation

  • Incident-response decision points and authority for endpoint actions
  • Network containment scope, limitations, and restoration procedures
  • Real Time Response session controls and remote command execution
  • Evidence collection using Real Time Response scripts and file retrieval
  • Host remediation, sensor uninstall protection, and recovery validation
  • Falcon Fusion SOAR workflow components, triggers, and approval steps
  • Automated notification, enrichment, ticket creation, and response orchestration

Workshop: Participants contain a simulated compromised endpoint, collect specified evidence through Real Time Response, and configure a Falcon Fusion SOAR escalation workflow.

Day 5: Operational governance, reporting, and administration planning

  • Falcon dashboards for endpoint coverage, detection volume, and response performance
  • Scheduled reports and metrics for security operations leadership
  • Falcon API concepts, API clients, scopes, and integration governance
  • SIEM and service-management integration patterns for Falcon events
  • Detection-tuning review cycles and false-positive reduction methods
  • EDR operating procedures for shift handover, incident ownership, and quality assurance
  • Thirty-day Falcon administration roadmap and continuous-improvement priorities

Workshop: Participants complete a Falcon EDR administration runbook and 30-day action plan defining coverage targets, policy changes, triage workflows, owners, and reporting measures.

Tools & standards covered

CrowdStrike Falcon console, Falcon Insight XDR, Falcon Fusion SOAR, Falcon Discover

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior Falcon experience is required. You should, however, be comfortable with endpoint administration, basic networking, security alerts, and interpreting items such as process names, IP addresses, and command lines.

No. Guided exercises use a Falcon training environment with prepared endpoints, detections, and scenarios. Participants may bring non-sensitive examples of their own policy or rollout challenges for discussion, but no production credentials are needed.

Bring a modern laptop with a current web browser, reliable internet access, and permission to use the course collaboration and lab access tools. A local Falcon sensor installation is not required, and participants should not install anything on corporate endpoints without their organisation's approval.

It is designed for endpoint security administrators, SOC analysts, incident responders, cyber security engineers, and infrastructure administrators supporting a Falcon deployment. It is particularly useful for teams that need to formalise operating procedures around an existing or planned Falcon environment.

This course focuses on administering and operating CrowdStrike Falcon: sensors, policies, detection triage, containment, response workflows, access control, and reporting. It uses investigation techniques needed by administrators, but it does not concentrate on advanced adversary emulation, reverse engineering, or specialist malware analysis.

You will leave with a Falcon administration runbook and a 30-day implementation plan that can be adapted to your environment. These deliverables cover sensor coverage, policy structure, detection handling, containment authority, workflow automation, escalation, and operational metrics.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Operational Technology Cyber Security for Energy Utilities Training Course

Energy utilities operate control environments where a cyber incident can interrupt generation, transmission, distribution, water processing,…

5 Days Certificate

Burp Suite Web Application Security Testing Training Course

Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …

5 Days Certificate

Cyber Security Governance for Government and Public Sector Teams Training Course

Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…

5 Days Certificate

Cyber Security for IT Auditors and Assurance Teams Training Course

IT auditors and assurance teams are expected to provide defensible conclusions on cyber risk, yet many audits still rely on high-level polic…