CrowdStrike Falcon Advanced Threat Hunting Queries
-
Updated
Aug 19, 2026 - CQL
CrowdStrike Falcon Advanced Threat Hunting Queries
A VS Code extension for for LogScale Query Language (formerly Humio) syntax highlighting.
Complete set up guide for Humio now as Falcon Logscale on single node self hosted server.
Obsidian plugin — CQL syntax highlighting for CrowdStrike LogScale
RMM Tools list files for hunting in CrowdStrike / Logscale
CrowdStrike CQL threat-hunting packs — one self-contained playbook per threat (MITRE ATT&CK, IOCs, triage, hardening)
Will check humio and other contemporary servers status depended to it
matplotlib benchmarks and useful use cases
Falcon LogScale Alert action for Pushover (https://pushover.net)
A Falcon LogScale package for monitoring and visualising data about a Nextcloud server
Shell script to pull data from shelly devices (https://www.shelly.cloud) and send to Falcon LogScale HEC endpoint
Fixture-validated Sigma detections compiled for Elastic and CrowdStrike LogScale with evidence manifests, CI, and documented validation boundaries.
Create a powershell DSC configuration file for use in a group policy to distribute and enroll the Falcon LogScale Collector.
Step-by-step guide to building a highly available Falcon LogScale Collector setup with keepalived + VIP failover.
To associate your repository with the logscale topic, visit your repo's landing page and select "manage topics."