CrowdStrike Falcon Intelligence is a threat intelligence solution that integrates with endpoint protection to provide information on adversaries and external threats. It tracks adversary groups to deliver profiles on their tradecraft, tools, and tactics, which can be mapped to standardized frameworks. The system monitors the open, deep, and dark web to detect risks such as brand impersonation, fraud, exposed credentials, and data leaks, including the ability to filter for supplier breaches. It delivers context-aware intelligence, including real-time indicators of compromise (IOCs) and data on actively exploited vulnerabilities, to enable analysis of endpoint threats and anticipation of adversary activity.
The solution includes automated malware analysis using sandbox environments and specialized agents that automate the reversing and classification of malware. To support security operations, it provides pre-tested YARA and Snort rules for detection engineering, an agent for continuous threat hunting, unified investigation workspaces, and AI-powered workflows. The platform facilitates automated countermeasures, such as domain takedowns, and integration with existing security tools through API access and browser extensions. This allows for the embedding of intelligence into operational workflows.