Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CROWDSTRIKE

CrowdStrike Certified Falcon Hunter (CCFH)

CCFHCrowdStrike Certified Falcon Hunter

The CrowdStrike Certified Falcon Hunter (CCFH) certification validates the skills of investigative analysts who perform deep detection analysis, machine timelining, event-related search queries, insider-threat investigations, and proactive threat hunting on the CrowdStrike Falcon platform. It is designed for security professionals who go beyond front-line response to uncover hidden threats and strengthen their organization's cyber defense. Earning the CCFH demonstrates your ability to turn Falcon platform telemetry into actionable intelligence and proactive hunting outcomes.

629 practice questions · Updated 2026-08-04

7Domains
34Objectives
159Concepts
629Questions

CCFH Curriculum

Every domain, objective, and concept the CCFH exam measures.

  1. Cyber Kill Chain Overview
  2. Reconnaissance
  3. Scanning and Enumeration
  4. Gaining Access
  5. Escalation of Privileges
  6. Maintaining Access
  7. Covering Tracks
  8. Intelligence Gap Recognition
  1. ATT&CK Framework Overview
  2. Mapping Threat Actor Behaviors
  3. Navigating ATT&CK Matrices
  4. Using ATT&CK for Detection and Response
  1. MITRE ATT&CK Framework Overview
  2. Threat Model Research
  3. TTP Identification and Mapping
  4. Threat Actor Profiling
  5. Pivoting in Threat Research
  6. Communicating to Non-Technical Audiences

  1. Host Timeline navigation
  2. Event types and icons
  3. Event timestamps and ordering
  4. Host state indicators
  5. Event filtering and search
  6. Event details and context
  7. Correlating events with host activity
  1. Process Timeline layout
  2. Event sequence interpretation
  3. Process relationships
  4. Detection markers
  5. Timeline navigation
  6. Flow of events analysis
  1. Identify pivot options
  2. Navigate to tools
  3. Use pivot data

  1. File metadata fields
  2. Process metadata fields
  3. Correlating file and process metadata
  4. Using metadata for threat hunting
  1. Investigate Module Overview
  2. Search Functionality
  3. Filtering and Faceting
  4. Detection Details
  5. Event Timeline
  6. Entity Exploration
  7. Graph View
  8. Saved Searches and Reports
  9. Export and Collaboration
  1. Users search use cases
  2. Hosts search use cases
  3. Hash search use cases
  4. IP address search use cases
  5. Bulk domains search use cases
  6. Selecting the appropriate search option

  1. CQL Syntax Fundamentals
  2. Query Structure
  3. Field and Value Syntax
  4. Comparison Operators
  5. Logical Operators
  6. Wildcards and Special Characters
  7. Time Range Syntax
  8. Parentheses and Precedence
  1. CQL Syntax Fundamentals
  2. Query Building Blocks
  3. Search Execution
  1. Format event data for readability
  2. Export event data
  3. Chart event data
  1. Filter event data
  2. Analyze results
  1. Target/Parent/Context Relationship
  2. Process Hierarchy in Event Data
  3. Using Context for Investigation

4.6 Define key data event types

3 concepts · 18 questions
  1. Identify key data event types
  2. Understand event source and purpose
  3. Differentiate event types
  1. Unix time format
  2. UTC time format
  3. Conversion methods
  4. Timezone considerations
  5. Practical application in Falcon
  1. Dashboard creation
  2. Adding Advanced Event Search results
  3. Dashboard configuration
  4. Saving and sharing dashboards

  1. Accessing Hunt reports
  2. Understanding Hunt report structure
  3. Refining event details
  1. Locate Visibility reports
  2. Identify report types
  3. Apply filters to reports
  4. Refine event details
  5. Export report data
  1. Locate the Events Reference
  2. Understand the purpose of the Events Reference
  3. Search for specific events
  4. Interpret event fields
  5. Apply event information

  1. Recognize overt malicious behaviors
  2. Analyze suspicious behaviors
  3. Correlate behaviors with attack patterns
  4. Prioritize alerts based on severity
  1. Asset Inventory Fundamentals
  2. Asset Value and Criticality
  3. Threat Actor Profiling
  4. Target Selection Criteria
  5. Asset-Target Mapping
  1. Reliability Assessment
  2. Validity Assessment
  3. Relevance Assessment
  4. Process of Elimination Application
  1. Alternative analytical interpretations
  2. False positive reduction strategies
  3. Contextual analysis in hunting
  1. PowerShell command-line basics
  2. CMD command-line basics
  3. Decoding obfuscated PowerShell
  4. Decoding obfuscated CMD activity
  5. Understanding PowerShell execution policies and contexts
  6. Understanding CMD batch and inline execution
  7. Interpreting command-line arguments and flags
  8. Correlating decoded activity with hunting hypotheses
  1. Enterprise-wide file infection pattern recognition
  2. Root cause analysis for file infections
  3. Source identification techniques
  1. Baseline of normal activity
  2. Indicators of testing activity
  3. Indicators of DevOps activity
  4. Indicators of adversary behavior
  5. Contextual analysis
  6. Tools and techniques for differentiation
  1. Initial Attack Vector Identification
  2. Vulnerability Exploitation Analysis
  3. Mapping Attack Vector to Vulnerability

  1. Routine Active Hunt Planning
  2. Hunt Execution Process
  3. Environment-Specific Hunt Tuning
  4. Breach Determination Criteria
  1. Outlier Analysis Fundamentals
  2. Falcon Search and Filtering
  3. Baseline Establishment
  4. Statistical and Heuristic Methods
  5. Visualizing Outliers
  6. Investigating Outlier Events
  7. Documenting and Reporting Outliers
  1. Hypothesis Generation
  2. Hunting Lead Sources
  3. Formulating Testable Hypotheses
  4. Mapping Hypotheses to Falcon Queries
  5. Iterative Hypothesis Refinement
  6. Proving Hypotheses with Evidence
  1. EAM query syntax
  2. Simple EAM queries
  3. Complex EAM queries
  4. EAM query optimization

7.5 Investigate a process tree

4 concepts · 24 questions
  1. Process tree structure
  2. Process tree investigation workflow
  3. Suspicious process identification
  4. Process tree correlation with events
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCFH, so none is invented.