CrowdStrike Falcon Endpoint Detection and Response Administration Training Course
| Course code | SD-CS-043 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security teams cannot respond consistently when endpoint telemetry is incomplete, prevention policies are poorly tuned, and analysts must work through large volumes of untriaged detections. CrowdStrike Falcon administrators need more than console familiarity: they must understand how sensors, host groups, policies, detections, investigations, containment actions, and integrations work together. This five-day course prepares participants to operate Falcon as an endpoint detection and response platform that supports measurable incident-response procedures rather than a collection of isolated security features.
Participants learn to administer the Falcon console, plan and validate sensor deployment, organise assets with host groups and tags, and configure prevention and detection policies for different endpoint populations. The course covers Falcon Insight XDR event data, detection triage, process-tree analysis, indicator searching, real-time response, network containment, and remediation workflows. Participants also work with Falcon Discover asset visibility, Falcon Fusion SOAR workflows, role-based access control, reporting, and API-led integration concepts. They gain practical methods for reducing false-positive noise while retaining evidence needed for investigations and audit review.
Instructor-led demonstrations are followed by guided exercises in a Falcon training environment. Participants investigate realistic endpoint incidents, tune a policy without weakening protection, contain a simulated compromised host, collect response evidence, and route actions through an automated workflow. Each participant leaves with a documented Falcon EDR administration runbook and a 30-day implementation plan covering sensor rollout, policy structure, triage procedures, escalation points, and reporting measures. This course is suited to teams establishing Falcon operations, standardising an existing deployment, or moving analysts into an EDR administration role.
Course objectives
By the end of this course, participants will be able to:
- Configure Falcon sensor deployment packages, update policies, and installation verification procedures for Windows, macOS, and Linux endpoints
- Design host group, tag, and policy assignments that apply appropriate controls to servers, workstations, and high-risk assets
- Tune prevention and detection policies using documented exceptions, severity criteria, and change-control evidence
- Triage Falcon detections by analysing event timelines, process trees, command lines, and associated endpoint activity
- Investigate suspicious behaviour with Falcon Insight XDR search filters and indicator-based queries
- Execute Real Time Response and network containment actions while preserving incident evidence and authorisation records
- Build Falcon Fusion SOAR workflows for notification, enrichment, escalation, and repeatable response actions
- Produce a Falcon administration runbook and 30-day improvement plan for endpoint coverage, alert handling, and reporting
Benefits of attending
For you
- Build credible hands-on experience administering CrowdStrike Falcon policies, sensors, host groups, and response actions
- Develop a repeatable method for moving from a Falcon detection to an evidence-backed triage decision
- Gain practical confidence using Real Time Response and network containment during endpoint incidents
- Create a portfolio-ready Falcon administration runbook that demonstrates operational ownership of an EDR platform
- Prepare for endpoint security, SOC engineering, and incident-response responsibilities involving CrowdStrike deployments
For your organisation
- Increase endpoint coverage accuracy through structured sensor deployment, health validation, and host-group design
- Reduce analyst time spent on low-value alerts through documented detection triage and policy-tuning practices
- Improve containment speed by defining authorised Real Time Response and network isolation workflows
- Strengthen auditability with role-based access, exception records, incident evidence, and administration runbooks
- Standardise Falcon operations across security and infrastructure teams through a shared 30-day improvement plan
Target competencies
Who should attend
- Endpoint Security Administrators — who configure Falcon sensors, policies, endpoint groups, and access controls
- SOC Analysts — who must investigate Falcon detections and escalate endpoint incidents with defensible evidence
- Incident Responders — who require rapid host containment, evidence collection, and remote response procedures
- Cyber Security Engineers — who integrate Falcon telemetry and workflows into the wider security architecture
- IT Infrastructure Administrators — who support sensor rollout across Windows, macOS, Linux, and server estates
- Security Operations Managers — who need consistent EDR operating procedures, coverage measures, and reporting
Requirements and prerequisites
Participants should understand basic endpoint administration, including Windows services, macOS or Linux endpoint concepts, software deployment, and user or group permissions. Familiarity with TCP/IP, DNS, common malware behaviours, security alerts, and incident-response terminology is expected. Experience reviewing logs or working in a SIEM is helpful but not essential. Participants should be comfortable navigating a web console and interpreting process names, command lines, and IP addresses. Prior CrowdStrike Falcon experience, scripting ability, threat-hunting expertise, or formal security certification is not required; complete beginners should expect a technically practical introduction rather than a general cyber-security awareness course.
Training methodology
The course combines focused instructor-led sessions with guided configuration and investigation labs in a CrowdStrike Falcon training environment. Participants deploy and validate sensors, create host groups, apply policies, examine Falcon Insight XDR detections, and use Real Time Response under defined incident-authorisation rules. Scenario-based case work uses suspicious PowerShell activity, persistence indicators, and lateral-movement evidence to connect console actions with operational decisions. Small-group reviews compare tuning choices and escalation paths. The final workshop converts lab learning into an organisation-specific administration runbook and 30-day rollout plan.
Course outline
Day 1: Falcon platform foundations and sensor operations
- CrowdStrike Falcon platform architecture and module relationships
- Falcon console navigation, tenant structure, and operational roles
- Falcon sensor architecture for Windows, macOS, and Linux
- Sensor installation packages, deployment methods, and provisioning tokens
- Sensor version management, update policies, and staged rollout planning
- Sensor health checks, connectivity status, and coverage validation
- Host inventory fundamentals, device attributes, tags, and host groups
Workshop: Participants build a sensor rollout worksheet and validate a simulated endpoint population for installation status, version compliance, and missing coverage.
Day 2: Prevention policies, access control, and asset visibility
- Prevention policy hierarchy and host-group policy assignment
- Malware prevention, exploit mitigation, and behavioural detection settings
- Policy exceptions, allowlisting decisions, and compensating-control records
- Detect-only versus prevent modes and safe policy-testing methods
- Role-based access control, user roles, and least-privilege administration
- Falcon Discover asset inventory, application visibility, and unmanaged asset identification
- Configuration change control, policy baselines, and administrative audit trails
Workshop: Participants design host groups and prevention policies for a mixed workstation and server estate, then document one justified exception through change control.
Day 3: Detection triage and endpoint investigation
- Falcon Insight XDR detection lifecycle, severity, status, and ownership
- Detection triage criteria, prioritisation queues, and escalation thresholds
- Event timeline analysis and process-tree reconstruction
- Command-line, hash, user, network, and parent-child process interpretation
- Indicator searching with Falcon Insight XDR filters and event fields
- MITRE ATT&CK technique mapping for endpoint behaviours
- Investigation notes, evidence capture, and incident handover standards
Workshop: Participants investigate a simulated suspicious PowerShell detection, reconstruct the execution chain, identify ATT&CK techniques, and produce an escalation note.
Day 4: Response actions, containment, and automation
- Incident-response decision points and authority for endpoint actions
- Network containment scope, limitations, and restoration procedures
- Real Time Response session controls and remote command execution
- Evidence collection using Real Time Response scripts and file retrieval
- Host remediation, sensor uninstall protection, and recovery validation
- Falcon Fusion SOAR workflow components, triggers, and approval steps
- Automated notification, enrichment, ticket creation, and response orchestration
Workshop: Participants contain a simulated compromised endpoint, collect specified evidence through Real Time Response, and configure a Falcon Fusion SOAR escalation workflow.
Day 5: Operational governance, reporting, and administration planning
- Falcon dashboards for endpoint coverage, detection volume, and response performance
- Scheduled reports and metrics for security operations leadership
- Falcon API concepts, API clients, scopes, and integration governance
- SIEM and service-management integration patterns for Falcon events
- Detection-tuning review cycles and false-positive reduction methods
- EDR operating procedures for shift handover, incident ownership, and quality assurance
- Thirty-day Falcon administration roadmap and continuous-improvement priorities
Workshop: Participants complete a Falcon EDR administration runbook and 30-day action plan defining coverage targets, policy changes, triage workflows, owners, and reporting measures.
Tools & standards covered
CrowdStrike Falcon console, Falcon Insight XDR, Falcon Fusion SOAR, Falcon Discover
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Operational Technology Cyber Security for Energy Utilities Training Course
Energy utilities operate control environments where a cyber incident can interrupt generation, transmission, distribution, water processing,…
Burp Suite Web Application Security Testing Training Course
Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …
Cyber Security Governance for Government and Public Sector Teams Training Course
Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…
Cyber Security for IT Auditors and Assurance Teams Training Course
IT auditors and assurance teams are expected to provide defensible conclusions on cyber risk, yet many audits still rely on high-level polic…