logo

Scaling your threat hunting operations with CrowdStrike and PSFalcon

ID: 6a628bff-e68f-5282-9a04-49c1ae41bcd2

STIX ID: report--6a628bff-e68f-5282-9a04-49c1ae41bcd2

Feed Name: NVISO Labs

Date Published: 2023-12-13

Date Updated: 2026-04-28

Author: Dimitris Binichakis

...
...

This blog post explains how to leverage CrowdStrike Falcon Real Time Response via the PSFalcon PowerShell module to execute scripted threat-hunting checks across multiple hosts for persistence mechanisms—covering registry Run/RunOnce keys, scheduled tasks, startup folders, WMI subscriptions, and services—mapped to MITRE ATT&CK techniques (T1547.001, T1053.005, T1546.003, T1543.003). It details prerequisites (API client, permissions), converting group names to GroupId, Base64-encoding custom commands, and provides a reusable Persistence-Hunter.ps1 workflow that outputs CSVs to support rapid triage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.