CrowdStrike Falcon Intelligence
Falcon Intelligence: world-class threat intelligence. Tracking 200+ adversary groups, IOC feeds, malware analysis, strategic intelligence for business decisions.

Key Features
- Adversary tracking - profile 200+ criminal and state groups
- IOC feeds - Indicators of Compromise for SIEM/SOAR
- Malware analysis - automated and manual sample analysis
- Strategic intelligence - reports for executives and CISO
- Intelligence APIs - integration with security stack
Table of Contents
What is Falcon Intelligence?
Falcon Intelligence is a threat intelligence platform from CrowdStrike - the company that first introduced the concept of adversary tracking. Instead of focusing only on malware and IOC, CrowdStrike tracks people behind attacks.
Why adversary-focused:
- Malware changes, but TTPs (Tactics, Techniques, Procedures) are stable
- Knowing the adversary, you can predict their next move
- Attribution allows better threat prioritization
Adversary Tracking
Naming Convention
CrowdStrike uses animal names for actor categories:
| Suffix | Category | Examples |
|---|---|---|
| BEAR | Russia | COZY BEAR, FANCY BEAR |
| PANDA | China | WICKED PANDA, MUSTANG PANDA |
| KITTEN | Iran | CHARMING KITTEN |
| CHOLLIMA | North Korea | LABYRINTH CHOLLIMA |
| SPIDER | eCrime | WIZARD SPIDER, CARBON SPIDER |
| JACKAL | Hacktivism | FRONTLINE JACKAL |
Adversary Profiles
For each actor, CrowdStrike provides:
- Motivation - financial, espionage, sabotage
- Targets - industries, regions, organization types
- TTPs - techniques used in attacks
- Malware - tools and infrastructure
- Recent activity - latest campaigns
Example: WIZARD SPIDER
Type: eCrime
Origin: Eastern Europe
Motivation: Financial (Ransomware)
Active since: 2016
Notable malware: TrickBot, Ryuk, Conti
Targets: Healthcare, Manufacturing, Government
Recent: Linked to Conti ransomware operations
Falcon Intelligence Levels
Falcon Intelligence (Standard)
- Adversary profiles (public info)
- IOC feeds
- Malware search
- Basic reports
Falcon Intelligence Premium
- Deep adversary intelligence - detailed profiles
- Strategic reports - for CISO and executives
- Custom intelligence - dedicated reports for your industry
- Analyst access - ability to ask questions
Falcon Intelligence Recon
- Digital risk monitoring - dark web monitoring
- Threat actor targeting - are you in their sights
- Credential monitoring - leaked employee passwords
- Brand monitoring - phishing sites, fake domains
IOC Feeds
Falcon Intelligence provides IOC (Indicators of Compromise):
IOC Types
- File hashes - MD5, SHA1, SHA256
- Domains - malicious domains
- IPs - C2 infrastructure
- URLs - phishing, malware delivery
- Email addresses - phishing actors
Integrations
IOC can be automatically sent to:
- SIEM (Splunk, QRadar, Sentinel)
- Firewall (Fortinet)
- SOAR (Phantom, Demisto)
- EDR (via Falcon Agent)
Confidence Scoring
Each IOC has confidence score:
- High - confirmed malicious
- Medium - probably malicious
- Low - suspicious, requires verification
Malware Analysis
Automated Analysis
Upload file to Falcon Sandbox:
- Static analysis - strings, imports, metadata
- Dynamic analysis - behavioral execution
- Network analysis - C2 communication
- Attribution - mapping to threat actors
Manual Analysis
For Premium: access to CrowdStrike analysts:
- Reverse engineering
- Custom malware analysis
- Attribution research
Strategic Intelligence
Reports for CISO and executives:
Threat Landscape Reports
- Quarterly threat assessments
- Industry-specific threats
- Regional threat analysis
- Emerging threats
Executive Briefings
- Non-technical summaries
- Risk prioritization
- Board-ready materials
Targeted Intelligence
- “Who is targeting our industry?”
- “What groups are active in our region?”
- “Are we being targeted by specific actors?”
Intelligence APIs
Integration with your security stack:
# Example: Query for IOCs
response = falcon_intel.get_indicators(
types=['domain', 'ip'],
malicious_confidence='high',
last_updated_gte='2024-01-01'
)
for ioc in response:
firewall.block(ioc.value)
Available APIs
- Indicator API - IOC feeds
- Actor API - adversary profiles
- Report API - intelligence reports
- Sandbox API - malware submission
Workflow with Falcon Intelligence
Proactive Intelligence
[New Campaign Detected] --> [CrowdStrike Alert]
|
"WIZARD SPIDER targeting healthcare"
|
[Your SOC]
|
[Proactive hunting for TTPs]
Reactive Investigation
[Alert in Falcon Insight] --> [Investigation]
|
[Query Intelligence for context]
|
"This malware is FANCY BEAR tool"
"Used in campaign against NATO governments"
Why CrowdStrike Intelligence?
Track Record
- First to identify FANCY BEAR (Russian GRU)
- Key in DNC hack 2016 investigation
- Tracking SolarWinds/SUNBURST
Scale
- 200+ tracked adversaries
- 20+ years historical data
- Global analyst team
Integration
- Native with Falcon platform
- APIs for custom integrations
- Feeds for third-party tools
Inquire about CrowdStrike Falcon Intelligence
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
OSINT (Open Source Intelligence)
Cybersecurity
See your company through attacker's eyes. Leaks, employee data, vulnerabilities - all from Google.
Managed Detection & Response (MDR)
Cybersecurity
24/7 protection by experts, without building your own SOC.
Managed Endpoint Protection (EDR/XDR)
Cybersecurity
Every endpoint protected. Every alert analyzed. Ransomware blocked in 15 minutes.
Threat Intelligence
Cybersecurity
Know your enemy before they strike. Proactive defense powered by data.
From Our Knowledge Base
Articles related to this solution
CVE-2026-53805: NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution...
Security Alert - CVE-2026-53805. CVSS: 9.8 (critical).
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist