Skip to content
Cybersecurity CrowdStrike

CrowdStrike Falcon Identity Threat Protection

Falcon Identity: identity and Active Directory protection. Credential theft detection, lateral movement, privilege escalation. Identity-based Zero Trust.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Key Features

  • AD monitoring - real-time Active Directory visibility
  • Credential theft detection - password theft detection
  • Lateral movement prevention - blocking horizontal movement
  • Privilege escalation detection - escalation detection
  • Identity-based Zero Trust - every access verified
Available now
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Send inquiry
Table of Contents

What is Falcon Identity?

Falcon Identity Threat Protection is a Falcon platform module dedicated to identity protection - primarily Active Directory, but also Azure AD and other identity providers.

Why identity protection is critical:

  • 80% of attacks use stolen credentials
  • Lateral movement almost always goes through AD
  • Ransomware first takes over Domain Admin
  • Dwell time - attackers are in AD for weeks before attack

The Active Directory Problem

AD is the main attack target

[Initial Access] --> [Credential Theft] --> [Lateral Movement] --> [Domain Admin]
                                                                        |
                                                                 [Game Over]

Typical attack chain:

  1. Phishing → first endpoint compromised
  2. Mimikatz → credential dump from LSASS
  3. Pass-the-Hash → lateral movement to other servers
  4. Kerberoasting → service account credentials obtained
  5. DCSync → dump all passwords from DC
  6. Golden Ticket → persistence as Domain Admin

Traditional solutions are not enough

  • SIEM - sees logs, doesn’t understand context
  • EDR - protects endpoints, doesn’t understand AD
  • PAM - controls access, doesn’t detect attacks
  • AD auditing - generates too much noise

How does Falcon Identity work?

1. Real-time AD Visibility

Falcon monitors Active Directory without installation on Domain Controllers:

[Domain Controllers] <-- Monitor --> [Falcon Identity]
         |                                   |
   [Replication traffic]              [Analysis & Detection]
         |                                   |
   [Auth events]                      [Alerts & Response]

Monitored events:

  • Authentication (NTLM, Kerberos)
  • Group membership changes
  • Privilege assignments
  • Service account activity
  • Replication traffic

2. Credential Theft Detection

Detecting various credential theft techniques:

LSASS Access:

  • Mimikatz
  • ProcDump
  • Custom credential dumpers

Kerberos Attacks:

  • Kerberoasting
  • AS-REP Roasting
  • Golden/Silver Ticket

Pass-the-X:

  • Pass-the-Hash
  • Pass-the-Ticket
  • Overpass-the-Hash

3. Lateral Movement Detection

Detecting horizontal movement:

[Workstation A] --> [Workstation B] --> [Server C] --> [Domain Controller]
      |                   |                  |               |
   ALERT            ALERT              ALERT          CRITICAL
   "Unusual         "Admin             "First          "DCSync
   RDP source"      credentials        access          detected"
                    from                to DC"
                    workstation"

Detected techniques:

  • RDP/SMB/WinRM from unusual sources
  • Service account used interactively
  • Admin credentials on workstations
  • Unusual authentication patterns

4. Honey Tokens

Decoys to detect attackers:

Honey Users: False AD accounts that shouldn’t be used:

cn=svc_backup_admin, ...
(Looks like service account, but is a decoy)

Any use attempt = alert.

Honey Credentials: False credentials in LSASS memory:

  • Attacker dumps credentials
  • Tries to use honey credential
  • Immediate alert

5. Zero Trust Enforcement

Identity-based access decisions:

Risk-based Authentication:

  • User risk score (behavioral analysis)
  • Device risk score (Falcon Agent)
  • Location/time anomalies
  • Authentication pattern changes

Conditional Access:

IF user_risk = high OR device_risk = high
THEN require MFA + limit access

Integrations

Microsoft

  • Active Directory (on-prem)
  • Azure AD / Entra ID
  • Microsoft 365

Identity Providers

  • Okta
  • Ping Identity
  • OneLogin

PAM Solutions

  • CyberArk
  • Delinea
  • BeyondTrust

Falcon Identity vs Competition

FeatureFalcon IdentityMicrosoft Defender for IdentityTenable.ad
DeploymentAgentlessSensors on DCsAgents
DetectionReal-timeNear real-timePeriodic
XDR IntegrationNativeMicrosoft ecosystemLimited
Honey tokensYesNoNo
Zero TrustFullLimitedNo

Use Cases

Ransomware Prevention

Detecting lateral movement before encryption:

  • Credential theft detection
  • Lateral movement alerts
  • DCSync prevention
  • Automatic response

Insider Threat

Detecting malicious employee actions:

  • Unusual access patterns
  • Privilege abuse
  • Data exfiltration indicators

Compliance

Meeting audit requirements:

  • Privileged access monitoring
  • Authentication logging
  • Change tracking

Implementation

Requirements

  • Windows Server 2012+ (Domain Controllers)
  • Network access to DC replication traffic
  • Falcon Insight on endpoints (optional, but recommended)

Deployment

  1. Configuration in Falcon console
  2. Network setup (monitoring replication)
  3. Honey token deployment
  4. Policy configuration
  5. Integration with response playbooks

Implementation time: 1-2 weeks AD impact: Zero (no agents on DCs)

Inquire about CrowdStrike Falcon Identity Threat Protection

Contact your product specialist and get a custom quote.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist