Step inside the CrowdStrike Falcon® platform and sharpen your skills with hands-on workshops led by CrowdStrike experts. Explore what's coming, then check back in August when the full agenda goes live.
The endpoint is the control plane for AI, where prompts begin and agents operate, but shadow AI expands risk across endpoint, SaaS, and cloud. See how adversaries use prompt injection to hijack AI agents and learn how to secure them across environments.
What you’ll do:
Understand how shadow AI expands your attack surface
See how prompt injection is used to compromise AI agents
Learn how to detect and secure AI agents across environments
Gain practical techniques you can apply immediately
Workshops are open to all Fal.Con Europe attendees.
AI is accelerating attacks at the endpoint, from ransomware to malware-free intrusions. See how agentic endpoint security uses AI to detect subtle threats, automate investigation, and take real-time action. Learn how to stop AI-driven attacks while safely enabling AI across your environment.
What you’ll do:
Understand how adversaries use AI to accelerate modern attacks
See how AI detects behaviors and automates investigation in real time
Learn how to contain threats faster with agentic workflows
Gain practical experience securing and enabling AI across endpoints
Workshops are open to all Fal.Con Europe attendees.
Today’s SOCs are slowed by fragmented data and manual workflows. Explore an Agentic SOC model to unify telemetry, automate detection and investigation, and orchestrate response. Follow a real attack lifecycle and learn how to move from reactive analysis to faster, outcome-driven security operations.
What you’ll do:
Understand the Agentic SOC model (Onboard, Operationalize, Orchestrate)
Learn how to unify data and reduce alert fatigue
See how AI accelerates detection, investigation, and response
Gain practical insight into orchestrating response across the attack lifecycle
Workshops are open to all Fal.Con Europe attendees.
27 seconds is all it takes for an adversary to break in. Learn how to build, deploy, and orchestrate AI agents using Charlotte AI. Create agents with natural language, apply guardrails, and design workflows that automate investigation and response—combining machine speed with human oversight.
What you’ll do:
Learn how to build AI agents using natural language in AgentWorks
Understand how to apply guardrails and ground agents in real data
See how agents coordinate tools, models, and workflows
Design orchestrated response with human-in-the-loop approvals
Workshops are open to all Fal.Con Europe attendees.
With valid credentials attackers don’t break in, they log in. Learn how to detect and stop identity-based threats across human, non-human, and AI identities. Explore how attackers exploit credentials and gain practical techniques to secure access and limit movement across cloud, SaaS, and on-prem environments.
What you’ll do:
Understand how attackers exploit credentials and identity-based access
Learn to detect threats across human, non-human, and AI identities
See how adaptive access and AI-driven response reduce risk
Gain practical techniques to limit lateral movement across environments
Workshops are open to all Fal.Con Europe attendees.
Sensitive data is constantly in motion across endpoints, cloud, and GenAI tools, creating new risks. In this hands-on workshop, detect and stop real-world data exfiltration across hybrid environments. Learn how to gain visibility, enforce policy, and prevent leaks before sensitive data leaves your organization.
What you’ll do:
Understand how data moves across endpoints, cloud, and GenAI tools
Learn to detect and stop real-world exfiltration scenarios
See how policy enforcement enables consistent protection
Gain visibility and control to prevent data loss across environments
Workshops are open to all Fal.Con Europe attendees.
Cloud risk evolves in real time. Learn how to connect misconfigurations to active threats across cloud environments. Use asset context and guided scenarios to identify, prioritize, and remediate risk before it escalates into an attack.
What you’ll do:
Understand how misconfigurations lead to active cloud threats
Learn to identify and prioritize risk across cloud environments
Explore how asset context improves investigation and response
Gain practical techniques to remediate risk before escalation
Workshops are open to all Fal.Con Europe attendees.
See how autonomous exposure management helps you find vulnerabilities across managed, unmanaged, and unsupported assets. Then prioritize exposures with threat intelligence and move faster with targeted remediation and patching.
What you’ll do:
Learn to identify exposures across managed, unmanaged, and network assets
Understand how threat intelligence prioritizes real risk
See how AI agents accelerate exposure analysis and decision-making
Gain practical techniques to remediate vulnerabilities and close gaps
Workshops are open to all Fal.Con Europe attendees.
See how Falcon Secure Access delivers runtime browser security on any browser, any device, without added friction. Learn how to stop credential theft, data exfiltration, and web-based attacks as they happen across a distributed workforce.
What you’ll do:
Understand browser-based threats and modern attack techniques
Learn how to stop credential theft and data exfiltration in real time
See how to extend Zero Trust to the browser
Gain practical strategies to secure access across users and devices
Workshops are open to all Fal.Con Europe attendees.
Put your incident response skills to the test. Step into a live red team vs. blue team simulation and respond to a multi-stage attack in real time. Investigate activity, pivot across telemetry, and execute precise actions to detect and stop adversaries across endpoint, identity, and cloud.
What you’ll do:
Experience a live red team vs. blue team attack simulation
Learn to investigate and pivot across endpoint, identity, and cloud telemetry
Practice executing precise response actions in real time
Improve incident response speed, accuracy, and overall effectiveness
Workshops are open to all Fal.Con Europe attendees.
Explore how adversaries manipulate AI agents through prompt injection, tool abuse, and other attack paths. Experiment with agents, tools, and inputs to see how attacks unfold — and how guardrails and security controls can help contain them.
What you’ll do:
Manipulate agent behavior through indirect prompt injection
Explore tool abuse and agent-centric attack paths
Test guardrails and controls against runtime attacks
Workshops are open to all Fal.Con Europe attendees.
Step into a high-stakes scavenger hunt to uncover insider threats tied to DPRK adversary FAMOUS CHOLLIMA. Analyze real tradecraft, follow timed clues, and investigate suspicious activity in the Falcon console by racing against peers to detect and stop insider threats before they escalate.
What you’ll do:
Understand insider threat tactics used by FAMOUS CHOLLIMA
Investigate suspicious activity using real-world tradecraft scenarios
Practice detecting insider threats in an interactive environment
Compete through timed challenges and a live leaderboard
Adversary Tradecraft workshops are open to all Fal.Con Europe attendees.
Step into an interactive investigation to respond to a simulated cloud breach. Analyze real adversary tradecraft from groups like SCATTERED SPIDER, uncover tactics across compromised environments, and put your detection and response skills to the test in fast-moving, cloud-native scenarios.
What you’ll do:
Understand cloud-focused adversary tactics and techniques
Investigate a simulated breach across cloud environments
Practice detecting and responding to real-world attack scenarios
Strengthen cloud detection and response skills under pressure
Adversary Tradecraft workshops are open to all Fal.Con Europe attendees.
Face autonomous adversary agents across the attack lifecycle, from reconnaissance to exfiltration. Use Charlotte AI and AgentWorks agents to investigate, contain, and respond to evolving threats with speed and precision.
What you’ll do:
Hunt threats driven by autonomous adversary agents
Correlate cross-domain telemetry and agent behavior
Use Charlotte AI to investigate, contain, and respond
Adversary Tradecraft workshops are open to all Fal.Con Europe attendees.
Investigate an adversary using stolen identity data to bypass traditional defenses. Use the Falcon platform to uncover identity-driven activity, contain the threat, and stop attacks even when the adversary has valid credentials.
What you’ll do:
Investigate attacks using stolen credentials and session tokens
Trace identity-driven activity across the environment
Contain and stop an adversary operating with valid credentials
Adversary Tradecraft workshops are open to all Fal.Con Europe attendees.