Skip to content

Falcon Threat Hunter

Falcon Threat Hunter

1. Overview

Falcon Threat Hunter is a feature that enables threat hunting across one or more sensors based on Indicators of Compromise (IOC – Indicator of Compromise).

Objectives

  • Query IOCs in Threat Intelligence (TI)
  • Filter and select relevant attributes
  • Execute hunting across the system
  • Automatically generate write-up and playbook

2. Prerequisites

  • Have access to Alert Detail
  • Have permission to use Threat Intelligence Lookup
  • Have available IOCs (IP, MD5, SHA1, filename, domain, ...)

3. Workflow

3.1. Access Feature

  1. Open an Alert detail
  2. In the Threat Intelligence Lookup area
  3. Click Falcon Threat Hunter
  4. A 5-step popup will display


3.2. Step 1 – Input IOC

Actions:

  1. Enter IOC (IP / MD5 / SHA1 / filename / domain...)
  2. Click Step 2: TI Lookup

Results:

  • Display list of TI Events containing the IOC

3.3. Step 2 – Select Events & Attributes

Description:

Display TI Events related to the IOC

Actions:

  1. Check one or more Events
  2. Expand to view Attributes list
  3. Select attributes for hunting

Options:

  • Quick select by type (MD5, SHA1, IP, ...)
  • Select multiple attributes at once

  1. Click Hunt across system

3.4. Step 3 – Configure Hunting

3.4.1. Scope

Select hunting scope:

  • Current Office Sensors: Sensors belonging to current Office
  • All Offices Sensors: Entire system

3.4.2. Review

  • Verify the list of attributes to be used

3.4.3. Execute

  • Click Start Hunting

Results:

  • Display progress (%)
  • Automatically proceed to Step 4 when complete


3.5. Step 4 – Generate Write-up

Description:

  • System automatically generates write-up

Status:

  • While processing:
    • Copy Write-up: Disabled
    • Create Playbook: Disabled
  • After completion:
    • Buttons are enabled

Actions:

  1. Click Copy Write-up
  2. Click Create Playbook


3.6. Step 5 – Create Playbook & Ticket

Description:

  • System automatically creates Playbook

After completion:

  • Enable Create Ticket button

Actions:

  1. Copy Playbook (text)
  2. Click Create Ticket


4. End-to-End Flow

Input IOC
   ↓
TI Lookup
   ↓
Select Attributes
   ↓
Configure Hunting
   ↓
Execute Hunting
   ↓
Generate Write-up
   ↓
Create Playbook
   ↓
Create Ticket

5. Best Practices

  • Use multiple IOCs to increase coverage
  • Prioritize hashes (MD5/SHA1) for higher accuracy
  • Limit scope if needing to optimize processing time
  • Carefully review attributes before hunting

6. Notes

  • Hunting time depends on:
    • Scope (Office vs All)
    • Number of attributes
    • System data volume
  • Write-up and Playbook are auto-generated, need review before actual use