Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CrowdStrike: For SOC Analysts
Bestseller
Highest Rated
Rating: 4.5 out of 5(2,513 ratings)
13,317 students

CrowdStrike: For SOC Analysts

Disclaimer: This course offered independently by Blue Team Consulting, LLC and is not affiliated with CrowdStrike, Inc.
Created byHailie Shaw
Last updated 11/2025
English
German [Auto],English [Auto],

What you'll learn

  • Create Custom Rules and Policies
  • Understand CrowdStrike Fundamentals
  • Analyze Endpoint Data
  • Detect and Investigate Threats
  • Console Navigation and Features
  • Real Time Response Actions and Scripts
  • Threat Hunt in CrowdStrike

Course content

1 section18 lectures3h 45m total length
  • Introduction1:38

    Explore CrowdStrike for SOC analysts with an overview of the console. Learn to triage detections from start to finish using the next-gen SIM, log scale, and the CrowdStrike query language.

  • Module 1a: Console Overview5:39

    Configure your console with UTC time, auto sign-in, and a preferred theme. Bookmark Investigate Advanced Event Search for quick access, and manage subscriptions and modules from the left menu.

  • Module 1b: Demo of the Console Overview13:59

    Learn to navigate the CrowdStrike console overview for SOC analysts, set UTC and preferences, review detections and crowd score, and leverage investigate, advanced event search, and the sandbox.

  • Module 2a: Where to Spend Your Time3:06

    Focus your time in the CrowdStrike console as a SOC analyst by reviewing monitor data and incidents, monitoring quarantine actions, and using investigate, configure, and intel tools.

  • Module 2b: Demo of the Important Menu Items13:41

    Navigate the CrowdStrike console to triage endpoint detections and incidents with filters and grouping, review quarantined files, and use investigate, hunt, sandbox, and Kql-powered raw logs for in-depth analysis.

  • Module 3a: Triaging a Detection16:08

    Triage detections in CrowdStrike using the detection dashboard, filters, and group by views to gauge severity quickly. Examine endpoint logs and KQL to confirm true positives and decide containment actions.

  • Module 3b: Demo of Detection Triage17:01

    Triages a detection on an endpoint, analyzing host details, the Sublime Text process, an eicar test file write, and incident workbench insights in CrowdStrike.

  • Module 4: OSINT Tools to Leverage9:21

    Explore open source intelligence tools for malware analysis, including VirusTotal, Any.run, Joe Sandbox, Hybrid Analysis, and Shodan, plus domain and whois lookups to support SOC root-cause investigations.

  • Module 5a: Advanced Event Search / CQL16:01

    Explore CrowdStrike's next gen sim and kcl for advanced endpoint log searches, build repeatable base queries, group and visualize results, format timestamps to utc, and export data for investigations.

  • Module 5b: Demo of Searching Endpoint Logs15:29

    Explore how CrowdStrike's advanced event search uses the CrowdStrike query language to query and visualize endpoint logs, filter by time and host, build dashboards, and export results.

  • Module 6a: Real Time Response Features10:46
  • Module 6b: Demo of Real Time Response25:28

    Demonstrates real-time response in CrowdStrike, triaging detections, evaluating true positives, and using live shell commands, file transfers, and script execution to analyze and contain threats like mimikatz.

  • Module 7a: Sandbox & Blocking Actions16:03

    Explore CrowdStrike's sandbox for malware analysis and submitting samples. Implement blocking actions via IOC management, host firewall rules, and regex-based blocks to enforce detections.

  • Module 7b: Demo of Sandbox Detonation and Performing Blocks18:58

    Detonate a sample executable in a CrowdStrike sandbox, analyze dynamic and static indicators, and implement blocking with IOC management, domain and hash controls, and custom EOA rule groups.

  • Module 8a: Whitelisting / Adding Exclusions8:55

    Learn to configure CrowdStrike exclusions by adding machine learning and IOA based whitelists, plus sensor visibility exclusions, to balance detections with reduced false positives while preserving visibility.

  • Module 8b: Demo of How to Add Exclusions11:08

    Compare IOA-based exclusions with machine learning based exclusions in CrowdStrike, and learn to create, test, and apply them using glob syntax.

  • Module 9: Putting it All Together!19:08

    Triaging a detection in module nine, this lecture uses an alert template and UTC reporting to identify mimikatz indicators on a Windows 11 workstation. It covers quarantining, blocking hashes, containment.

  • Module 10: Where to Go Next2:47

    Identify practical next steps after this course by pursuing CrowdStrike EDR certification or threat hunter and analyst certs, exploring Splunk Core certs and SIEM exposure, and hands-on incident response tools.

Requirements

  • A connection to the internet

Description

Module 1: Console Overview Get acquainted with the CrowdStrike console, your command center for proactive threat detection and incident response. Explore its interface, functionalities, and navigation to ensure a solid foundation for the rest of the course.

Module 2: Where to Spend Your Time Learn to prioritize effectively in a dynamic threat landscape. Understand the critical areas of focus within the CrowdStrike console to optimize your time and as it pertains to SOC work.

Module 3: Triaging a Detection Master the art of rapid detection triage. Develop skills to assess the severity of a detection, determine its scope, and decide on appropriate immediate actions.

Module 4: Useful Open Source Tools to Use Discover a curated toolkit of open-source resources that complement the CrowdStrike platform. Explore how to leverage these tools to enhance your threat intelligence and investigative capabilities.

Module 5: Event Search / CQL Delve into advanced event search techniques and learn how to craft powerful queries in CQL. Learn how to conduct host analysis and leveraging endpoint logs to your advantage.

Module 6: Real-Time Response Features Equip yourself with CrowdStrike's real-time response arsenal. Dive into containment strategies, remote actions, scripting, and other instant response capabilities.

Module 7: Sandbox & Blocking Actions Explore the CrowdStrike sandbox environment and understand its role in threat analysis. Learn to implement blocking actions effectively to halt threats in their tracks.

Module 8: Whitelisting / Exclusions Navigate the nuances of whitelisting and exclusions. Gain insights into striking the right balance between security and operational efficiency.

Module 9: Putting It All Together Immerse yourself in realistic scenarios where you'll apply your newfound knowledge. Walk through end-to-end incident response processes, from detection to resolution.

Module 10: Where to Go Next Chart your future course in the realm of cybersecurity. Discover avenues for continued learning, specialization, and skill refinement to stay ahead in the ever-evolving threat landscape.

Who this course is for:

  • Cybersecurity Practitioners
  • Incident Responders
  • Threat Hunters
  • IT Professionals Transitioning to Security
  • SOC Analysts
  • Threat Intelligence Analysts