Automate incident investigation, faster alert triage & response
CrowdStrike Falcon Intelligence is a cutting-edge solution that integrates threat intelligence into endpoint protection, automating investigations, accelerating response times, and enabling security teams to transition from a reactive to a predictive, proactive state. This innovative platform combines automated analysis with human intelligence, empowering security teams of all sizes and skill levels to effectively stay ahead of cyber threats.
Top Features
Extended endpoint integration
- Built into the CrowdStrike Falcon® platform, there is no integration, administration or deployment required.
- Protected endpoints automatically forward all quarantined files to Falcon Intelligence for immediate investigation.
- Streamline your workflow and pivot seamlessly into adversary insights from other CrowdStrike modules.
Indicators of Compromise (IOCs)
- Visualize relationships between IOCs and adversaries found on your endpoints protected by the CrowdStrike Falcon® platform.
- Hunt for threats with IOCs enriched with context.
- Strengthen defences with CrowdStrike's real-time global IOC feed.
- Pre-built integrations and APIs enable you to orchestrate defences with existing security solutions.
Actor profiles
- Access 165+ profiles of the nation-state, eCrime and hacktivist adversaries.
- Identify adversaries focused on attacking your business, region, or industry.
- Learn about your adversaries’ intent and capabilities and predict their next move.
Automated investigations
- Bring endpoint protection to the next level by combining malware sandbox analysis, malware search and threat intelligence in a single solution.
- Reduce the time and skills required to perform manual incident investigations.
- Identify and investigate related threats and block similar attacks in the future.
Recommended products
Automated investigations
- Bring endpoint protection to the next level by combining malware sandbox analysis, malware search and threat intelligence in a single solution.
- Reduce the time and skills required to perform manual incident investigations.
- Identify and investigate related threats and block similar attacks in the future.

Indicators of Compromise (IOCs)
- Visualize relationships between IOCs and adversaries found on your endpoints protected by the CrowdStrike Falcon® platform.
- Hunt for threats with IOCs enriched with context.
- Strengthen defenses with CrowdStrike's real-time global IOC feed.
- Pre-built integrations and APIs enable you to orchestrate defenses with existing security solutions.

Actor profiles
- Access 165+ profiles of the nation-state, eCrime and hacktivist adversaries.
- Identify adversaries focused on attacking your business, region, or industry.
- Learn about your adversaries’ intent and capabilities and predict their next move.

Extended endpoint integration
- Built into the CrowdStrike Falcon® platform, there is no integration, administration or deployment required.
- Protected endpoints automatically forward all quarantined files to Falcon Intelligence for immediate investigation.
- Streamline your workflow and pivot seamlessly into adversary insights from other CrowdStrike modules.

Additional Information
Terms & Conditions
Terms of Service
https://www.crowdstrike.com/website-terms-of-use/Privacy Policy
https://www.crowdstrike.com/privacy-notice/Resources
CrowdStrike Falcon Intelligence - How to Defend Against Threats with Falcon Intelligence
In this video, we will demonstrate the power of the automated threat intelligence available with Falcon Intelligence.
CrowdStrike Falcon Intelligence - Recon
CrowdStrike Falcon Intelligence Recon enables organizations to better protect their brand, employees, and sensitive data by allowing security teams to easily conduct investigations of underground activity.