CrowdStrike Falcon in practice: Mac and Linux sensors, USB threats and investigation tools
A deeper CrowdStrike Falcon course built from CrowdStrike's public tech hub and blog: installing and checking the Falcon sensor on macOS and Linux (and the approvals a Mac needs), handling USB risk with Falcon Device Control and cleaning an infected drive with Real Time Response, and investigating with incidents, global search, context enrichment and role dashboards.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- CrowdStrike Falcon
Skills you'll practise
- Install the Falcon sensor on a Linux host with falconctl and a Mac with its system approvals, and confirm each sensor is running
- Explain the three kinds of USB drop attack CrowdStrike describes and what Falcon Device Control records about files written to USB
- Plan a Real Time Response clean-up of a USB drive infected by a spreader that hides user data in an obfuscated folder
- Use incidents, global search and context enrichment cards to investigate an indicator such as a hash or domain
- Choose dashboard widgets that show sensor coverage gaps, such as sensors inactive for more than 14 days
Course outline
- 1.CrowdStrike Falcon in practice: Mac and Linux sensors, USB threats and investigationVideo · 2 min
- 2.Mac and Linux sensors: installing, approving and checkingLesson · 17 min
- 3.USB devices: the risk, Device Control and cleaning an infected driveLesson · 17 min
- 4.Investigating: incidents, global search, context enrichment and dashboardsLesson · 16 min
- 5.CrowdStrike Falcon in practice: Mac and Linux sensors, USB threats and investigation tools: knowledge checkKnowledge check · 16 questions
- 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- CrowdStrike Tech Hub: Installing Falcon Sensor for Linux (falconctl CID, ps check, kernel and user mode)
- CrowdStrike Tech Hub: Install Falcon Sensor for Mac (CID with checksum, network filter, system extension, Full Disk Access)
- CrowdStrike Tech Hub: Customized Dashboards (sensor health, SOC and vulnerability widgets)
- CrowdStrike Tech Hub: Context Enrichment (CrowdStrike Store apps, global search, incident cards)
- CrowdStrike Tech Hub: Falcon Insight XDR walkthrough (third-party telemetry, containment, response actions)
- CrowdStrike blog: Visibility and Granular Control, Securing USB Devices in the Workplace (USB drop attacks, Falcon Device Control)
- CrowdStrike blog: Mitigating USB Data Exfiltration with Falcon Device Control (file write visibility, source code identification, ZIP introspection)
- CrowdStrike blog: Remediating 'Hidden' Malware with Real Time Response (USB spreader, non-breaking space folder)
- CrowdStrike blog: Understanding Indicators of Attack, event stream processing on the sensor and in the cloud
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.