product
- What you can do with CrowdStrike
- CrowdStrike Modules Falcon
- NGAV(Prevent/USB/FW)
- EDR(Falcon Insight)
- Threat Hunting (OverWatch)
- IT Asset Management (Discover)
- Vulnerability Management (Spotlight)
- Threat Intelligence (Intelligence/Sandbox)
- Identity Protection (ITD/ITP)
- Cloud Security (CNAPP)
- EASM(Surface)
- SSPM(Shield)
service
Application for evaluation machine
- FAQ

CrowdStrike
CrowdStrike
FalconTech 2025 Event Report
hello everyone!
This year's user event"FalconTech 2025" was held!
In 2025, there will be two locations: Osaka (August 7th) and Shinagawa, Tokyo (September 5th).
The event was held for the first time in Osaka, and due to the effects of a typhoon, the Tokyo event was held as a hybrid event at short notice, but many people participated online.!
In this article, we will provide a digest of the actual CTF and panel discussion, as well as the real voices of the participants.


Falcon CTF
Using CrowdStrike FalconFor incident response and investigationThis is a CTF (Capture the Flag) competition where participants solve problems related to the game and compete against each other to show off their skills.
This year's event was also very well received, with participants being exposed to functions that they would not normally be able to use, with comments such as "It helped me improve my skills!" and "It gave me ideas for training new employees."
This CTF consisted of the following three categories:
- Operational Phase
- Incident Response
- Additional Modules
"Operation Phase"
This is a low difficulty category.
The questions use the Prevent/Insight function, so we have created questions that can be used by all customers.
Approximately half of the participants appeared to be able to answer the questions.
"Incident Response"
This is the most difficult category.
Advanced investigation using event search/process tree, etc. is required.
By including the situation in the question text, we created questions that would allow participants to learn the response process in an emergency.
There were two questions that only one person was able to answer, so the correct answer rate appeared to be low.
Additional modules
This category consists of additional modules (Spotlight/Discover/ITP/Cloud security/NG-SIEM/SSPM).
By including situations in the questions, we created questions that would help participants understand the benefits of introducing each module.
The correct answer rate for Spotlight/Discover was relatively high, while the correct answer rate for other modules appeared to be low.
\Winners will receive luxurious prizes!/


[Osaka] Falcon roundtable discussion
At the Osaka event, participants exchanged opinions candidly on topics such as what they learned from the CTF and daily operational challenges.
A wide range of topics were discussed frankly, from company-wide operational issues to support systems.
-
Operation
-
Incident Response
-
New features for PIO
-
Other modules
Roundtable Digest: Concerns, Ideas, and Awareness from the Operational Site
operation
- Log retention issues
There were complaints that CrowdStrike 's log storage period was short, at just one week, and several requests for operational improvements were made for long-term audits and investigations.
*Macnica 's note: The storage period for raw logs can be extended by contract. There is also a module that outputs raw logs externally. - Server deployment and support for affiliated companies
Concerns were shared, such as the implementation status of server terminals, management based on different modes, and the extent to which operations should be properly handled across the entire group and affiliated companies.
* Macnica Note: By using the paid Health Check MTG service, our staff can also provide advice on management and operations. - App conflicts and resource shortages
- Operational challenges include dealing with on-site issues such as conflicts with applications, installation errors, and performance degradation.
- Discussions were held on contact points, procedures for isolating issues, and how manufacturers and distributors should support manufacturers in the event of an incident. - Actual state of policy operation/tuning
There are examples of gradual implementation, such as "testing the latest policy in a select group and then applying it to production if there are no problems," and there are also voices saying that "active tuning is being done." - Techniques for catching up on functions and maintaining skills
- Information on the utilization of study groups hosted by manufacturers, Macnica health checks, various seminars, etc. was shared.
- We also heard the opinion that "Falcon University training, which requires a fee, is too expensive to use in the field."
Incident response
- Available 24 hours a day, 365 days a year
The participants shared information about the differences in each company's systems and initial response rules, such as how they have established a constant response system, reporting flows at night and in emergencies, and initial incident triggers (CS alerts /SOC notifications, etc.). - Alert analysis and investigation
・Response styles vary. Differences were seen among companies, such as "stopping once blocked, and whitelisting if overdetection has an impact," "digging deeper into only a few devices such as USB-connected devices," and "only a few detections per month, and analyzing them in detail."
* Macnica note: Although blocked detections are given a lower priority, from an incident response perspective, we believe that the detected content needs to be investigated.
- Other topics discussed included "I feel like there are more alerts being triggered by things other than EDR recently," "I'm not familiar with alert investigation, so depending on the alert, it's difficult to dig deep into the reason for detection, which is frustrating," and "I'd like a collection of standard queries and know-how for alert investigation." - Alert management and investigation scope
The balance between security and operational costs was once again a hot topic, including methods for managing and recording alerts and how deep to dig and investigate.
Interest in module utilization and new functions
- Additional Modules
Some participants expressed their views on the future, saying things like, "I'd like to know if there are any effective ways to utilize Discover," and "We're very interested in the ITDR, DLP, and cloud areas going forward." - Charlotte AI
There was a lot of excitement and questions about the implementation of AI technology in the field, such as "Is there a fee?" and "Can it be used for CTF problems (automated answering)?" - Expectations for the know-how and query collection
Following the trend of recommending NG-SIEM as the manufacturer's standard, there was a strong demand for Macnica to provide its own collection of standard investigation queries and operational know-how.
Common issues in deployment and operation systems
- Company-wide/group deployment rate barrier
On-site difficulties were shared, such as "We still have legacy operating systems, such as old Linux, so we can't apply CrowdStrike 100 % across the company," and "Even if we want to use it, it's difficult in special environments." - Requests for support system
Some comments included, "It's reassuring how quickly manufacturers respond to inquiries via management console chat. I hope Macnica will also offer chat support in Japanese," and "I wasn't aware that manufacturers' chat services existed." - Education and skill development issues
Common needs were also seen in the use of seminars and events, and in support measures for obtaining qualifications (CrowdStrike certification).






[Tokyo] Module Experience Event
At the Tokyo event, participants were able to experience the effective use of new functions and the benefits of their implementation through a trial session of additional modules.
Many participants commented that they were able to experience the value and benefits of the product, with comments such as "I was able to get a sense of how it could be implemented" and "I was able to learn about specific examples of its use in the field."
The four modules you have selected are:
- Falcon Identity Threat Protection
- Falcon Cloud Security
- Falcon Next-Gen SIEM
- Falcon Discover/Spotlight
And finally, we'll introduce the SSPM, which is attracting attention from everyone!
- Falcon Shield
Summary
Through this event...
-
"The sense of security of knowing the worries and efforts of my colleagues"
-
"Exchanging know-how that is truly useful in the field"
-
"Expectations for new functions and operations are rising even more."
This once again highlighted the "community value unique to Falcon users."
Macnica will continue to support connections and knowledge sharing between users, and will accompany you in solving on-site issues!
Please look forward to the next event!




What is Falcomi? & Preview of upcoming events!
What is Falcomi?
Falcomi is a community exclusively for companies that have introduced CrowdStrike Falcon. Macnica was created as a place where users can use Falcon more efficiently and effectively through the exchange of information and sharing of operational know-how that is unique to users.
<Characteristics of Falcomi>
- You can feel free to ask any questions you have.
For example, users can solve everyday questions such as "How do other companies do this setting?" or "What should I do when this kind of alert appears?" - Plenty of community-only events
We regularly plan study sessions and seminars for community members, such as the Meetup held this time, and "FalconTech," where participants learn how to use Falcon in a CTF format. - There is also a wealth of content for beginners, such as how to set up the system immediately after installation.
After installing Falcon, we have prepared videos and documents to resolve any initial configuration questions you may have, allowing you to get off to a hassle-free start.
<Next event announcement!>
December 5, 2025, “Falcomi Meetup Vol.2" is scheduled to be held!
We will let you know as soon as the application site opens, so please block off your schedule and wait!
What Vol.1 was like This article Please see.
The biggest appeal of Falcomi is that it allows user companies to exchange real-world operational knowledge and tips with each other. You can find colleagues who you can immediately consult with about any questions you have, and you can also gain opportunities for in-depth learning at events.
If you would like to make more use of Falcon or would like to learn about other companies' case studies, why not join Falcomi?
*Limited to CrowdStrike user companies and companies purchasing through Macnica.
*If you are not sure whether you purchased from Macnica, please apply first (^^)/
Inquiry/Document request
In charge of Macnica CrowdStrike Co., Ltd.
- TEL:045-476-2010
- E-mail:crowdstrike_info@macnica.co.jp
Weekdays: 9:00-17:00