CCFH · ● Active · Expert · CrowdStrike
Exam facts
| Field | Value |
|---|---|
| Cost | $350 USD |
| Duration | 90 minutes |
| Questions | 60 (all scored) |
| Passing | ~75% (approximately 45 of 60 questions) |
| Format | Multiple choice |
| Delivery | Pearson VUE (proctored online or test center) |
| Languages | English |
| Valid | 3 years |
| Renewal | Retake exam, or pursue CCFA/CCFR to maintain currency |
| Prerequisites | 6 months hands-on experience with Falcon platform recommended; CCFA + CCFR recommended as prior certifications |
| Released | 2023 |
| Retiring | N/A |
Vendor source — CrowdStrike University CCFH ↗ Official exam guide — CCFH Certification Exam Guide PDF ↗ Exam scheduling — Pearson VUE CrowdStrike Exams ↗
About
The CrowdStrike Certified Falcon Hunter (CCFH) is an expert-level certification that validates advanced threat hunting capabilities using the CrowdStrike Falcon platform. Released in 2023, the CCFH targets threat hunters, detection engineers, and senior SOC analysts who operate proactively to identify adversary presence, establish threat patterns, and author custom detection rules. Holders demonstrate mastery of threat hunting methodology (hypothesis-driven investigations, forensic timeline reconstruction, kill-chain mapping), Falcon platform tools (Insight, Investigate, LogScale), MITRE ATT&CK operationalization, custom IOA rule authoring, and threat intelligence integration.
The CCFH is positioned as the capstone credential in the CrowdStrike Falcon certification trilogy (CCFA → CCFR → CCFH) and assumes prior knowledge of Falcon platform fundamentals and incident response workflows. It is most valuable for organizations operating at tier 3+ threat hunting maturity, where hunts are hypothesis-driven, multi-tool investigations often spanning days or weeks. The exam emphasizes adversary behavior modeling, advanced query language proficiency (CQL and LogScale), and the ability to translate intelligence into operational hunts at scale.
Domain context — Security / Threat Hunting
Advanced, vendor-specific threat hunting credential for CrowdStrike Falcon-based SOC and threat hunting teams operating at expert level. Sits at the intersection of detection engineering, proactive threat intelligence, and adversary behavior modeling. The CCFH targets organizations with mature threat hunting programs and expects hunters to independently design complex investigations, author custom detection rules, and translate threat intelligence into operational hunts.
Read full deep dive — CrowdStrike Ecosystem →
Topics covered
Based on the official CCFH exam blueprint:
- Threat Hunting Methodology — threat hunting lifecycle, hypothesis development and validation, hunt initiation strategies, advanced search techniques, forensic timeline reconstruction, findings documentation and escalation
- MITRE ATT&CK Framework Operationalization — ATT&CK tactic and technique mapping, cyber kill chain (7 stages: reconnaissance, scanning, enumeration, access, privilege escalation, persistence, covering tracks), threat actor behavior modeling and pattern recognition, ATT&CK navigator use cases
- Falcon Event Investigation & Detection Analysis — Falcon event classification and enrichment, root cause analysis, detection accuracy validation, machine timeline reconstruction for complex multi-step attacks
- Search and Investigation Tools — Falcon Insight query syntax, CrowdStrike Query Language (CQL) fundamentals and advanced operators, LogScale (Humio) federated search, cross-tool investigation (Sandbox + Insight integration)
- Custom IOA Rule Design — Indicator of Attack (IOA) rule architecture, behavioral anomaly rules, rule testing and validation, operational deployment strategies, tuning for false-positive reduction
- Falcon Platform Modules (Expert Focus) — Insight and Investigate console mastery, Discover module for behavioral insights, Falcon LogScale for hunting-scale data analysis, response action integration
- Adversary Tradecraft & Insider Threat Hunting — Lateral movement techniques, persistence mechanisms, data exfiltration patterns, insider threat hunting hypothesis development
- Charlotte AI for Hunting — AI-driven context and enrichment, automated investigation assistance, relationship mapping for complex incidents
- Reporting and Metrics — hunt findings documentation, threat intelligence reporting standards, hunt effectiveness metrics, executive-level threat briefing preparation
Source: CrowdStrike CCFH Certification Guide ↗
Common skills at Security / Threat Hunting · Expert
Shared content for the Security / Threat Hunting domain at Expert level — not specific to this cert.
- Advanced threat modeling and adversary behavior analysis
- Log analysis and time-series event correlation at scale
- Indicator of Compromise (IOC) and Indicator of Attack (IOA) research, validation, and operationalization
- Query language mastery (SQL-like, proprietary SIEM dialects, federated search across multiple data sources)
- Forensic timeline reconstruction and anomaly detection across complex multi-step attack scenarios
- Threat intelligence integration and operationalization for proactive hunting
- Hypothesis-driven hunt planning, execution, and documentation
- Detection engineering and rule authoring for behavioral analytics
- Adversary profiling and tradecraft analysis
Recommended courses at Security / Threat Hunting · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| CrowdStrike University | CSU LP-H: Threat Hunter Learning Path (Advanced) | Free (for Falcon customers) | ↗ |
| CrowdStrike University | CCFH Certification Exam Prep (Expert-level modules) | Free (for Falcon customers) | ↗ |
| CrowdStrike University | LogScale (Humio) Advanced Query Techniques | Free (for Falcon customers) | ↗ |
| Udemy | CrowdStrike Certified Falcon Hunter (CCFH) 2026 — Advanced Threat Hunting | $14–$99 | ↗ |
| Whizlabs | CrowdStrike CCFH Practice Exams (Expert-level) | $49 | ↗ |
Course-selection rule: Courses must be specifically for CCFH at expert level. CSU LP-H is the officially recommended preparation, offered free to CrowdStrike Falcon platform customers. Prerequisite knowledge of CCFA and CCFR concepts is assumed.
Prerequisites and preparation timeline
Prerequisites (recommended, not strict):
- Minimum 12 months hands-on experience with CrowdStrike Falcon platform (best practice)
- Completion of CCFA (Falcon Administrator) — validates Falcon architecture, policy, and investigation console
- Completion of CCFR (Falcon Responder) — validates incident response workflows and investigation techniques
- Prior threat hunting or SOC analyst experience (2-3 years in detection/analysis role)
- Solid understanding of MITRE ATT&CK framework (tactics, techniques, kill chain)
- Proficiency with query languages (SQL or similar); CQL/LogScale are taught but SQL fundamentals assumed
Preparation timeline:
- Dedicated study: 4-8 weeks (40-60 hours) if coming from CCFA + CCFR background
- Hands-on labs: 20-40 hours in a Falcon environment, authoring IOA rules and running hunts
- Total commitment: 60-100 hours for exam-ready proficiency (compared to 40-60 hours for CCFA/CCFR)
Why CCFH is harder than prior Falcon certs:
- Requires independent problem-solving (hypothesis-driven hunting) rather than procedural execution
- Query language syntax is more forgiving than pure SQL but demands deeper understanding of event correlation
- IOA rule authoring has fewer "right answers" — rules must be tested, tuned, and validated operationally
- Exam scenarios often don't have perfect forensic clarity — requires inference and probabilistic reasoning
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| CrowdStrike University | Official CCFH Practice Exams (Expert-level) | Free (for Falcon customers) | ↗ |
| ExamTopics | CCFH Free Practice Questions (community-contributed) | Free (partial) | ↗ |
| Whizlabs | CrowdStrike CCFH Advanced Practice Exam | $49 | ↗ |
| VMExam | CrowdStrike Falcon Hunter Certification Exam | $99 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Threat Hunting with Splunk: Practical Techniques and APT Detection | Omar Borg | Independently published | 2023 | 9798860926134 | ↗ |
| The Threat Hunter's Handbook: Techniques and Strategies for Cyber Defense | Larry Ethan | Independently published | 2023 | 9798340082787 | ↗ |
| The Threat Hunter's Cookbook: Techniques and Queries for Security Teams | Ryan Fetterman, Sydney Marrone | Splunk | 2022 | N/A | ↗ |
| Cyber Threat Hunters Handbook: Applying Advanced Analytics, Automation, and Collaborative Intelligence for Digital Defense | David F. Pereira Quiceno | Independently published | 2023 | 9789365898965 | ↗ |
Book rule: These titles focus on threat hunting methodology, query construction, and APT detection — transferable skills for any SIEM platform, including CrowdStrike Falcon. No CCFH-specific study guide has been published by CrowdStrike; official prep relies on CSU courses.
Hunt scenarios covered by the exam
The CCFH exam emphasizes real-world threat hunting scenarios that require hypothesis development, tool mastery, and intelligence integration:
-
Advanced Persistence Hunts — identifying attacker footholds via non-obvious persistence mechanisms (scheduled tasks, WMI consumers, kernel drivers, COM object hijacking). Requires timeline reconstruction, behavioral rule creation, and kill-chain validation.
-
Lateral Movement Investigations — tracing attacker movement across networks after initial compromise. Tests CQL query construction, event correlation, and MITRE ATT&CK technique mapping.
-
Insider Threat Scenarios — hunting for data exfiltration, privilege abuse, and anomalous user behavior. Tests behavioral anomaly detection, statistical analysis, and risk scoring.
-
Multi-stage Attack Chain Reconstruction — linking reconnaissance, scanning, initial access, and post-exploitation activities across hours or days. Tests machine timeline reconstruction and IOA rule design.
-
Threat Actor Profiling — extracting adversary tradecraft patterns, operational security practices, and capability assessment from behavioral artifacts. Tests MITRE ATT&CK operationalization and intelligence reporting.
-
Custom IOA Rule Development — authoring behavioral rules that detect novel malware or attack patterns not covered by signature-based IOCs. Tests rule logic, testing methodology, and operational deployment.
Typical job titles at Security / Threat Hunting · Expert
Primary roles:
- Threat Hunter (senior / lead)
- Senior Threat Analyst
- Cyber Threat Intelligence Analyst (hunt-focused)
- Detection Engineer (threat hunting focus)
- Incident Response Analyst (proactive / threat hunting)
- SOC Manager / Team Lead (threat hunting operations)
- Threat Hunt Lead / Threat Hunting Program Manager
Related titles (overlapping expertise):
- Threat Intelligence Analyst (advanced)
- Security Analyst (expert level)
- Forensic Analyst (with proactive hunting focus)
- Malware Analyst (with behavioral IOA focus)
(Job titles drawn from current job-board postings that list CCFH, threat hunting, or CrowdStrike Falcon expertise as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $112,100 – $235,500 | Glassdoor ↗ · Salary.com ↗ · ZipRecruiter ↗ |
| ZAR | No region-specific data available — use CrowdStrike Falcon SOC Engineer general role estimate | |
| GBP | £85,000 – £165,000 (estimated from USD conversion) | No direct survey available; USD figure converted at 1.27 GBP/USD |
| EUR | €105,000 – €220,000 (estimated, DE/FR/NL) | No region-specific data available |
| AUD | A$195,000 – A$410,000 (estimated from USD conversion) | No direct survey available; USD figure converted at 1.55 AUD/USD |
Salary rule: USD range reflects Threat Hunter (entry $112K) and Senior Threat Hunter ($235K) from Glassdoor. Regional data extrapolated from USD using April 2026 exchange rates; no certified threat hunting salary surveys exist for ZAR, GBP, EUR, or AUD.
Skills validated
Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.
Platform expertise:
- CrowdStrike Falcon Insight and Investigate console mastery — advanced filtering, pivoting, and relationship mapping
- Falcon LogScale (Humio) query language for hunting-scale analytics, federated search across multiple data sources
- CrowdStrike Query Language (CQL) — complex event filtering, aggregation, enrichment, and correlation
Threat hunting methodology:
- Threat hunting hypothesis development and validation (top-down and bottom-up approaches)
- Kill-chain hypothesis mapping and adversary behavior pattern recognition
- Machine timeline reconstruction for complex multi-step attack chains
- Behavioral anomaly detection and statistical outlier identification
- Hunt findings documentation, executive-level threat briefing preparation
Detection and rule authoring:
- IOA (Indicator of Attack) rule design, testing, and deployment
- Behavioral rule logic for advanced threat detection
- False-positive tuning and rule optimization for operational environments
- Integration of threat intelligence into custom detection rules
Adversary tradecraft analysis:
- Lateral movement technique identification and hunting
- Persistence mechanism discovery and validation
- Privilege escalation tactic operationalization (MITRE ATT&CK)
- Data exfiltration pattern recognition
- Insider threat hunting scenarios and detection strategies
Tools and integrations:
- Charlotte AI for investigation assistance and automated context enrichment
- Falcon Discover for behavioral insights and asset intelligence
- Sandbox integration for malware analysis and IOC validation
- Threat intelligence platform integration and operationalization
- Log aggregation and long-term hunt data retention strategies
Related certifications
CrowdStrike Falcon certification pathway:
- Foundation (recommended prerequisites): CrowdStrike Certified Falcon Administrator (CCFA) ↗ · CrowdStrike Certified Falcon Responder (CCFR) ↗
- Pathway note: CCFH is the expert-tier capstone. CCFA (platform administration) and CCFR (incident response) should precede CCFH for optimal preparation, though not strict prerequisites.
- Complementary: Both CCFA and CCFR stack naturally with CCFH — together they validate end-to-end Falcon platform expertise from admin → response → hunting.
Cross-vendor threat hunting equivalents:
- GIAC Certified Intrusion Analyst (GCIA) ↗ (vendor-neutral, SANS focus)
- Splunk Certified Threat Hunting Professional (Splunk ecosystem, comparable expert level)
- EC-Council Certified Threat Intelligence Professional (CTIP) ↗ (threat intelligence + hunting)
Vendor overview:
Sources
- CrowdStrike University: https://www.crowdstrike.com/en-us/crowdstrike-university/crowdstrike-falcon-certification-program/
- CrowdStrike CCFH Certification Guide PDF: https://www.crowdstrike.com/content/dam/crowdstrike/marketing/en-us/documents/pdfs/crowdstrike-university/cfcp-certification-guide.pdf
- Pearson VUE CrowdStrike Exams: https://www.pearsonvue.com/us/en/crowdstrike.html
- Glassdoor Cyber Threat Hunter Salaries: https://www.glassdoor.com/Salaries/cyber-threat-hunter-salary-SRCH_KO0,19.htm
- Salary.com Threat Hunter: https://www.salary.com/research/salary/hiring/threat-hunter-salary
- ZipRecruiter Threat Hunting Salary: https://www.ziprecruiter.com/Salaries/Threat-Hunting-Salary
- ExamTopics CCFH-202: https://www.examtopics.com/exams/crowdstrike/ccfh-202/
- VMExam CrowdStrike Falcon Hunter: https://www.vmexam.com/crowdstrike/ccfh-202b-crowdstrike-falcon-hunter
- Udemy CCFH-202b 2026 Course: https://www.udemy.com/course/ccfh-202-crowdstrike-certified-falcon-hunter-2025/
- Amazon: Threat Hunting with Splunk by Omar Borg: https://www.amazon.com/Threat-Hunting-Splunk-Practical-Techniques/dp/B0CHL92TSK
- Amazon: The Threat Hunter's Handbook by Larry Ethan: https://www.amazon.com/Threat-Hunters-Handbook-Techniques-Strategies/dp/B0DHSF5CS8
- Splunk Threat Hunter's Cookbook: https://www.splunk.com/en_us/campaigns/threat-hunters-cookbook.html
- CrowdStrike LogScale Documentation: https://library.humio.com/
- LogScale CrowdStrike Integrations: https://library.humio.com/integrations/integrations-crowdstrike.html
Last verified: 2026-05-01 Parent ecosystem: CrowdStrike Ecosystem Parent domain: Security / Threat Hunting Vendor overview: CrowdStrike Vendor Overview