Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CROWDSTRIKE

CrowdStrike Certified Falcon Hunter (CCFH)

CrowdStrike Certified Falcon Hunter

The CrowdStrike Certified Falcon Hunter (CCFH) certification validates the skills of investigative analysts who perform deep detection analysis, machine timelining, event-related search queries, insider-threat investigations, and proactive threat hunting on the CrowdStrike Falcon platform. It is designed for security professionals who go beyond front-line response to uncover hidden threats and strengthen their organization's cyber defense. Earning the CCFH demonstrates your ability to turn Falcon platform telemetry into actionable intelligence and proactive hunting outcomes.

DeliveryPearson VUE
Free questions629

Content last reviewed 4 August 2026 · Up to date

The certification

What CrowdStrike Certified Falcon Hunter (CCFH) proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

7domains
34objectives
159concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The CrowdStrike Certified Falcon Hunter (CCFH) certification is a role-based credential for investigative analysts who perform deeper detection analysis and response, machine timelining, event-related search queries, insider-threat-related investigations, and proactive investigations (threat hunting) using the CrowdStrike Falcon platform. It validates your ability to leverage Falcon's investigative capabilities to identify, analyze, and respond to sophisticated threats that evade front-line defenses.

Earning the CCFH demonstrates that you can effectively use Falcon platform tools to conduct thorough investigations, build timelines of attacker activity, query event data, and proactively hunt for threats across your environment. This certification is part of the CrowdStrike Falcon Certification Program, which validates proficiency across Falcon user disciplines and supports effective cyber defense. It is ideal for security professionals who want to formalize their expertise in advanced threat hunting and incident investigation.

Who it’s for

The CCFH certification is directed at the investigative analyst who performs deeper detection analysis and response, machine timelining and event-related search queries, insider-threat-related investigations, and proactive investigations (threat hunting). It is ideal for security professionals who are responsible for going beyond initial alerts to understand the full scope of an attack and proactively identify threats. This certification is well-suited for threat hunters, incident responders, and security analysts who have hands-on experience with the CrowdStrike Falcon platform and are looking to validate their advanced investigative skills. It is also valuable for those who want to formalize their expertise in proactive threat hunting and contribute to a more robust security posture.

Recommended experience

CrowdStrike strongly recommends that candidates complete the training courses offered in CrowdStrike University that align to the CCFH certification and have at least 6 months' experience working in the Falcon platform, as the exam questions measure knowledge and skills gained through hands-on experience. At least 6 months of hands-on experience working with the CrowdStrike Falcon platform; Completion of recommended training courses in CrowdStrike University aligned to the CCFH certification; Experience with deeper detection analysis and response, machine timelining, event-related search queries, insider-threat investigations, and proactive threat hunting

The syllabus

What you’ll learn

Every domain and objective CrowdStrike measures, with the weight they carry on the exam.

The official CrowdStrike exam outline · checked 4 August 2026 · See the source

ATT&CK Frameworks
  • 1.1 Demonstrate knowledge of the cyber kill chain (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, covering tracks) and recognize intelligence gaps
  • 1.2 Utilize the MITRE ATT&CK Framework to model threat actor behaviors
  • 1.3 Operationalize the MITRE ATT&CK Framework to research threat models, TTPs and threat actors, and pivot as necessary and convey to non-technical audiences
3 objectives · 62 free questions · 13 pages
Detection Analysis
  • 2.1 Analyze information displayed in the Host Timeline to understand host states and events
  • 2.2 Analyze the information displayed in the Process Timeline to understand the flow of events and detections
  • 2.3 Pivot from the detection page to additional investigative tools
3 objectives · 60 free questions · 13 pages
Search and Investigation Tools
  • 3.1 Analyze and interpret metadata around files and processes recorded by Falcon
  • 3.2 Differentiate use of Investigate Module tools available in Falcon
  • 3.3 Understand use cases for various search options (e.g., Users, Hosts, Hash search, IP addresses, and Bulk domains)
  • 3.4 Interpret search result information displayed in dashboards to determine additional investigation or action
4 objectives · 73 free questions · 15 pages
Event Search
  • 4.1 Define key syntax of CrowdStrike Query Language (CQL)
  • 4.2 Build a query and perform a search using CQL
  • 4.3 Format event data for user readability, export or charting
  • 4.4 Filter event data and analyze results
  • 4.5 Describe the process relationship of (Target/Parent/Context)
  • 4.6 Define key data event types
  • 4.7 Convert and format Unix times to UTC readable time
  • 4.8 Create a custom dashboard to display Advanced Event Search results
8 objectives · 119 free questions · 27 pages
Reports and References
  • 5.1 Use the built-in Hunt reports to refine event details
  • 5.2 Use the built-in Visibility reports to refine event details
  • 5.3 Leverage the Events Reference (Events Data Dictionary) documentation to learn information about specific events
3 objectives · 51 free questions · 11 pages
Hunting Analytics
  • 6.1 Analyze and recognize suspicious overt malicious behaviors
  • 6.2 Understand target systems (asset inventory and who would target those assets)
  • 6.3 Evaluate information for reliability, validity and relevance for use in the process of elimination
  • 6.4 Identify alternative analytical interpretations to minimize and reduce false positives
  • 6.5 Decode and understand PowerShell/CMD activity
  • 6.6 Recognize patterns such as an enterprise-wide file infection process to determine the root cause or source of the infection
  • 6.7 Differentiate testing, DevOps or general user activity from adversary behavior
  • 6.8 Identify the vulnerability exploited from an initial attack vector
8 objectives · 160 free questions · 35 pages
Hunting Methodology
  • 7.1 Conduct routine active hunt operations within your environment in order to determine if your environment has been breached
  • 7.2 Perform outlier analysis with the Falcon tool
  • 7.3 Conduct hypothesis and hunting lead generation in order to prove them using Falcon tools
  • 7.4 Construct simple and complex EAM queries in Falcon
  • 7.5 Investigate a process tree
5 objectives · 104 free questions · 22 pages
On the day

The exam itself

Everything CrowdStrike publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationCrowdStrike Certified Falcon Hunter (CCFH)
DeliveryPearson VUE
LanguagesEnglish, Japanese
After you pass

Where this credential goes next

The path CrowdStrike lays out, how the credential is kept, and where to book.

Step-by-step path to CrowdStrike Certified Falcon Hunter (CCFH)

CrowdStrike Certified Falcon Hunter (CCFH) badgeCredential earnedCrowdStrike Certified Falcon Hunter (CCFH) Certification
Renewal and maintenance

CrowdStrike certifications are valid for 3 years. Renewal details are not published on the official exam page. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. CrowdStrike maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by CrowdStrike

Exam registration

Register for the exam through Pearson VUE, CrowdStrike’s authorized testing partner.

Schedule your exam

Visit the official CrowdStrike certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

Is the CCFH certification part of a larger certification program?

Yes, the CCFH is part of the CrowdStrike Falcon Certification Program, which offers role-based certifications for Falcon Practitioners, Administrators, Responders, Hunters, SIEM Analysts, SIEM Engineers, Identity Specialists, and Cloud Specialists.

Do I need to earn a lower-tier CrowdStrike certification before taking the CCFH exam?

No. CrowdStrike does not require a lower-tier certification as a prerequisite for the CCFH exam. However, it is strongly recommended that candidates complete the training courses offered in CrowdStrike University that align to the certification and have at least 6 months' experience working in the Falcon platform.

How do I schedule the CCFH exam?

You can schedule the CCFH exam by creating or logging in to your Pearson VUE account. You can choose to take the exam online via OnVUE or at a Pearson Testing Center (PVTC).

What are the identification requirements for the CCFH exam?

You must present a valid government-issued ID prior to taking the exam. The name on your Pearson account must match the name on your government-issued ID.

Can I pay for the CCFH exam with a voucher?

Yes, during the exam scheduling process, you have the option to pay for your exam by credit card or redeem an exam voucher. If you would like to purchase CrowdStrike University exam vouchers by purchase order, you can send an email with your request to a CrowdStrike training representative.

What job roles does the CCFH certification map to?

The CCFH certification is directed at the investigative analyst who performs deeper detection analysis and response, machine timelining and event-related search queries, insider-threat-related investigations, and proactive investigations (threat hunting). It is ideal for threat hunters and investigative analysts.

Are there any hands-on labs or performance-based components in the CCFH exam?

The official exam guide does not specify whether the CCFH exam includes hands-on labs or performance-based components. For detailed exam design and structure, refer to the CCFH Exam Guide.

How soon will I receive my CCFH exam results?

The official exam page does not specify the exact timing for score report availability. For information on what to expect during your exam, refer to the Pearson VUE 'What to expect' resources.

Information freshness · Content last reviewed on 2026-08-04 Up to date
Practice free questions 629 questions, free, no account needed.