The opening move
On September 2, 2026, a security researcher publicly released FalconFlank, a local privilege-escalation exploit targeting the CrowdStrike Falcon sensor. Here’s the twist that makes it worth reading even if you don’t run Falcon: the exploit doesn’t beat the EDR — it gets the EDR to do the work. It plants a booby-trapped macro document, then redirects privileged clean-up so Falcon itself writes a rogue bcrypt.dll into the PowerShell directory, where it’s sideloaded as SYSTEM. It’s the same class of attack as ShieldBreak, a security product’s own SYSTEM privileges turned against it.
| Threat | Response team | Outcome |
|---|---|---|
| CrowdStrike Falcon local privilege-escalation zero-day. No CVE, no vendor fix; the planted DLL self-deletes. | HuntIQ Threat Research + Tanium Atlas — human hunters backed by AI-assisted tooling. | Reproduced from source, behavioral patterns used directly within a Tanium Atlas driven hunt. |
“When your EDR is the thing being turned against you, you can’t ask that same agent whether you’re clean. With Tanium Atlas we ask the endpoint itself — the behavior it actually recorded — and get a real answer across the whole fleet in seconds, not a scan result from the tool that’s been compromised.”
— Aaron Smith, Head of Threat Hunting
How the fast response worked
HuntIQ Threat Research didn’t wait for a writeup. Working straight from the code the researcher published, the team reviewed the entire tradecraft — how it plants a booby-trapped file, tricks Falcon into moving it into a trusted system folder, rides that trust to full control of the machine, and then deletes the evidence behind it.
From that, the team built numerous methodologies and detections to catch it. None of them depend on finding the file, because the file is gone by the time you’d look. Instead, they watch for the behavior the attack leaves behind: the payload loading, the odd sequence of programs carrying it out, the temporary folders it stages in, and the exploit running in the first place.
Then they packed the whole hunt into one prompt. A hunter runs it, and Tanium Atlas checks every one of those seven signals across the entire fleet — right now and back through history — flags anything worth a second look, and hands back a clear, ranked report. Nothing leaves the network to do it. On our own test fleet, the full sweep came back clean in about sixty seconds, with an honest note on which machines had the visibility needed to trust that answer. That’s the difference between a clean hunt and a guess.
This is what Tanium Security Operations delivers: detection and confirmation of exposure before the threat has even been named.
