CrowdStrike Certified Falcon Hunter

CrowdStrike · CCFH · Expert

CrowdStrike · CrowdStrike Ecosystem

CrowdStrike Certified Falcon Hunter

CCFHactiveExpert
Official CrowdStrike source · crowdstrike.com

CCFH · ● Active · Expert · CrowdStrike


Exam facts

FieldValue
Cost$350 USD
Duration90 minutes
Questions60 (all scored)
Passing~75% (approximately 45 of 60 questions)
FormatMultiple choice
DeliveryPearson VUE (proctored online or test center)
LanguagesEnglish
Valid3 years
RenewalRetake exam, or pursue CCFA/CCFR to maintain currency
Prerequisites6 months hands-on experience with Falcon platform recommended; CCFA + CCFR recommended as prior certifications
Released2023
RetiringN/A

Vendor source — CrowdStrike University CCFH ↗ Official exam guide — CCFH Certification Exam Guide PDF ↗ Exam scheduling — Pearson VUE CrowdStrike Exams ↗


About

The CrowdStrike Certified Falcon Hunter (CCFH) is an expert-level certification that validates advanced threat hunting capabilities using the CrowdStrike Falcon platform. Released in 2023, the CCFH targets threat hunters, detection engineers, and senior SOC analysts who operate proactively to identify adversary presence, establish threat patterns, and author custom detection rules. Holders demonstrate mastery of threat hunting methodology (hypothesis-driven investigations, forensic timeline reconstruction, kill-chain mapping), Falcon platform tools (Insight, Investigate, LogScale), MITRE ATT&CK operationalization, custom IOA rule authoring, and threat intelligence integration.

The CCFH is positioned as the capstone credential in the CrowdStrike Falcon certification trilogy (CCFA → CCFR → CCFH) and assumes prior knowledge of Falcon platform fundamentals and incident response workflows. It is most valuable for organizations operating at tier 3+ threat hunting maturity, where hunts are hypothesis-driven, multi-tool investigations often spanning days or weeks. The exam emphasizes adversary behavior modeling, advanced query language proficiency (CQL and LogScale), and the ability to translate intelligence into operational hunts at scale.


Domain context — Security / Threat Hunting

Advanced, vendor-specific threat hunting credential for CrowdStrike Falcon-based SOC and threat hunting teams operating at expert level. Sits at the intersection of detection engineering, proactive threat intelligence, and adversary behavior modeling. The CCFH targets organizations with mature threat hunting programs and expects hunters to independently design complex investigations, author custom detection rules, and translate threat intelligence into operational hunts.

Read full deep dive — CrowdStrike Ecosystem →


Topics covered

Based on the official CCFH exam blueprint:

  • Threat Hunting Methodology — threat hunting lifecycle, hypothesis development and validation, hunt initiation strategies, advanced search techniques, forensic timeline reconstruction, findings documentation and escalation
  • MITRE ATT&CK Framework Operationalization — ATT&CK tactic and technique mapping, cyber kill chain (7 stages: reconnaissance, scanning, enumeration, access, privilege escalation, persistence, covering tracks), threat actor behavior modeling and pattern recognition, ATT&CK navigator use cases
  • Falcon Event Investigation & Detection Analysis — Falcon event classification and enrichment, root cause analysis, detection accuracy validation, machine timeline reconstruction for complex multi-step attacks
  • Search and Investigation Tools — Falcon Insight query syntax, CrowdStrike Query Language (CQL) fundamentals and advanced operators, LogScale (Humio) federated search, cross-tool investigation (Sandbox + Insight integration)
  • Custom IOA Rule Design — Indicator of Attack (IOA) rule architecture, behavioral anomaly rules, rule testing and validation, operational deployment strategies, tuning for false-positive reduction
  • Falcon Platform Modules (Expert Focus) — Insight and Investigate console mastery, Discover module for behavioral insights, Falcon LogScale for hunting-scale data analysis, response action integration
  • Adversary Tradecraft & Insider Threat Hunting — Lateral movement techniques, persistence mechanisms, data exfiltration patterns, insider threat hunting hypothesis development
  • Charlotte AI for Hunting — AI-driven context and enrichment, automated investigation assistance, relationship mapping for complex incidents
  • Reporting and Metrics — hunt findings documentation, threat intelligence reporting standards, hunt effectiveness metrics, executive-level threat briefing preparation

Source: CrowdStrike CCFH Certification Guide ↗


Common skills at Security / Threat Hunting · Expert

Shared content for the Security / Threat Hunting domain at Expert level — not specific to this cert.

  • Advanced threat modeling and adversary behavior analysis
  • Log analysis and time-series event correlation at scale
  • Indicator of Compromise (IOC) and Indicator of Attack (IOA) research, validation, and operationalization
  • Query language mastery (SQL-like, proprietary SIEM dialects, federated search across multiple data sources)
  • Forensic timeline reconstruction and anomaly detection across complex multi-step attack scenarios
  • Threat intelligence integration and operationalization for proactive hunting
  • Hypothesis-driven hunt planning, execution, and documentation
  • Detection engineering and rule authoring for behavioral analytics
  • Adversary profiling and tradecraft analysis

Recommended courses at Security / Threat Hunting · Expert

ProviderTitleCostURL
CrowdStrike UniversityCSU LP-H: Threat Hunter Learning Path (Advanced)Free (for Falcon customers)
CrowdStrike UniversityCCFH Certification Exam Prep (Expert-level modules)Free (for Falcon customers)
CrowdStrike UniversityLogScale (Humio) Advanced Query TechniquesFree (for Falcon customers)
UdemyCrowdStrike Certified Falcon Hunter (CCFH) 2026 — Advanced Threat Hunting$14–$99
WhizlabsCrowdStrike CCFH Practice Exams (Expert-level)$49

Course-selection rule: Courses must be specifically for CCFH at expert level. CSU LP-H is the officially recommended preparation, offered free to CrowdStrike Falcon platform customers. Prerequisite knowledge of CCFA and CCFR concepts is assumed.


Prerequisites and preparation timeline

Prerequisites (recommended, not strict):

  • Minimum 12 months hands-on experience with CrowdStrike Falcon platform (best practice)
  • Completion of CCFA (Falcon Administrator) — validates Falcon architecture, policy, and investigation console
  • Completion of CCFR (Falcon Responder) — validates incident response workflows and investigation techniques
  • Prior threat hunting or SOC analyst experience (2-3 years in detection/analysis role)
  • Solid understanding of MITRE ATT&CK framework (tactics, techniques, kill chain)
  • Proficiency with query languages (SQL or similar); CQL/LogScale are taught but SQL fundamentals assumed

Preparation timeline:

  • Dedicated study: 4-8 weeks (40-60 hours) if coming from CCFA + CCFR background
  • Hands-on labs: 20-40 hours in a Falcon environment, authoring IOA rules and running hunts
  • Total commitment: 60-100 hours for exam-ready proficiency (compared to 40-60 hours for CCFA/CCFR)

Why CCFH is harder than prior Falcon certs:

  • Requires independent problem-solving (hypothesis-driven hunting) rather than procedural execution
  • Query language syntax is more forgiving than pure SQL but demands deeper understanding of event correlation
  • IOA rule authoring has fewer "right answers" — rules must be tested, tuned, and validated operationally
  • Exam scenarios often don't have perfect forensic clarity — requires inference and probabilistic reasoning

Practice exams

ProviderTitleCostURL
CrowdStrike UniversityOfficial CCFH Practice Exams (Expert-level)Free (for Falcon customers)
ExamTopicsCCFH Free Practice Questions (community-contributed)Free (partial)
WhizlabsCrowdStrike CCFH Advanced Practice Exam$49
VMExamCrowdStrike Falcon Hunter Certification Exam$99

Books

TitleAuthorPublisherYearISBNURL
Threat Hunting with Splunk: Practical Techniques and APT DetectionOmar BorgIndependently published20239798860926134
The Threat Hunter's Handbook: Techniques and Strategies for Cyber DefenseLarry EthanIndependently published20239798340082787
The Threat Hunter's Cookbook: Techniques and Queries for Security TeamsRyan Fetterman, Sydney MarroneSplunk2022N/A
Cyber Threat Hunters Handbook: Applying Advanced Analytics, Automation, and Collaborative Intelligence for Digital DefenseDavid F. Pereira QuicenoIndependently published20239789365898965

Book rule: These titles focus on threat hunting methodology, query construction, and APT detection — transferable skills for any SIEM platform, including CrowdStrike Falcon. No CCFH-specific study guide has been published by CrowdStrike; official prep relies on CSU courses.


Hunt scenarios covered by the exam

The CCFH exam emphasizes real-world threat hunting scenarios that require hypothesis development, tool mastery, and intelligence integration:

  1. Advanced Persistence Hunts — identifying attacker footholds via non-obvious persistence mechanisms (scheduled tasks, WMI consumers, kernel drivers, COM object hijacking). Requires timeline reconstruction, behavioral rule creation, and kill-chain validation.

  2. Lateral Movement Investigations — tracing attacker movement across networks after initial compromise. Tests CQL query construction, event correlation, and MITRE ATT&CK technique mapping.

  3. Insider Threat Scenarios — hunting for data exfiltration, privilege abuse, and anomalous user behavior. Tests behavioral anomaly detection, statistical analysis, and risk scoring.

  4. Multi-stage Attack Chain Reconstruction — linking reconnaissance, scanning, initial access, and post-exploitation activities across hours or days. Tests machine timeline reconstruction and IOA rule design.

  5. Threat Actor Profiling — extracting adversary tradecraft patterns, operational security practices, and capability assessment from behavioral artifacts. Tests MITRE ATT&CK operationalization and intelligence reporting.

  6. Custom IOA Rule Development — authoring behavioral rules that detect novel malware or attack patterns not covered by signature-based IOCs. Tests rule logic, testing methodology, and operational deployment.


Typical job titles at Security / Threat Hunting · Expert

Primary roles:

  • Threat Hunter (senior / lead)
  • Senior Threat Analyst
  • Cyber Threat Intelligence Analyst (hunt-focused)
  • Detection Engineer (threat hunting focus)
  • Incident Response Analyst (proactive / threat hunting)
  • SOC Manager / Team Lead (threat hunting operations)
  • Threat Hunt Lead / Threat Hunting Program Manager

Related titles (overlapping expertise):

  • Threat Intelligence Analyst (advanced)
  • Security Analyst (expert level)
  • Forensic Analyst (with proactive hunting focus)
  • Malware Analyst (with behavioral IOA focus)

(Job titles drawn from current job-board postings that list CCFH, threat hunting, or CrowdStrike Falcon expertise as required or preferred.)


Salary

RegionRangeSource
USD$112,100 – $235,500Glassdoor ↗ · Salary.com ↗ · ZipRecruiter ↗
ZARNo region-specific data available — use CrowdStrike Falcon SOC Engineer general role estimate
GBP£85,000 – £165,000 (estimated from USD conversion)No direct survey available; USD figure converted at 1.27 GBP/USD
EUR€105,000 – €220,000 (estimated, DE/FR/NL)No region-specific data available
AUDA$195,000 – A$410,000 (estimated from USD conversion)No direct survey available; USD figure converted at 1.55 AUD/USD

Salary rule: USD range reflects Threat Hunter (entry $112K) and Senior Threat Hunter ($235K) from Glassdoor. Regional data extrapolated from USD using April 2026 exchange rates; no certified threat hunting salary surveys exist for ZAR, GBP, EUR, or AUD.


Skills validated

Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.

Platform expertise:

  • CrowdStrike Falcon Insight and Investigate console mastery — advanced filtering, pivoting, and relationship mapping
  • Falcon LogScale (Humio) query language for hunting-scale analytics, federated search across multiple data sources
  • CrowdStrike Query Language (CQL) — complex event filtering, aggregation, enrichment, and correlation

Threat hunting methodology:

  • Threat hunting hypothesis development and validation (top-down and bottom-up approaches)
  • Kill-chain hypothesis mapping and adversary behavior pattern recognition
  • Machine timeline reconstruction for complex multi-step attack chains
  • Behavioral anomaly detection and statistical outlier identification
  • Hunt findings documentation, executive-level threat briefing preparation

Detection and rule authoring:

  • IOA (Indicator of Attack) rule design, testing, and deployment
  • Behavioral rule logic for advanced threat detection
  • False-positive tuning and rule optimization for operational environments
  • Integration of threat intelligence into custom detection rules

Adversary tradecraft analysis:

  • Lateral movement technique identification and hunting
  • Persistence mechanism discovery and validation
  • Privilege escalation tactic operationalization (MITRE ATT&CK)
  • Data exfiltration pattern recognition
  • Insider threat hunting scenarios and detection strategies

Tools and integrations:

  • Charlotte AI for investigation assistance and automated context enrichment
  • Falcon Discover for behavioral insights and asset intelligence
  • Sandbox integration for malware analysis and IOC validation
  • Threat intelligence platform integration and operationalization
  • Log aggregation and long-term hunt data retention strategies

Related certifications

CrowdStrike Falcon certification pathway:

Cross-vendor threat hunting equivalents:

Vendor overview:


Sources


Last verified: 2026-05-01 Parent ecosystem: CrowdStrike Ecosystem Parent domain: Security / Threat Hunting Vendor overview: CrowdStrike Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000