Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
CrowdStrike’s 2024 Threat Hunting Report is a standalone report released on August 20, 2024. It analyzes proactive threat-hunting observations made by CrowdStrike OverWatch between July 1, 2023, and June 30, 2024. Its central finding is that attackers are increasingly using legitimate identities, administration tools and remote-management software to conduct hands-on-keyboard intrusions that can look like normal IT activity.
The figures describe CrowdStrike’s observed interactive-intrusion dataset—not every cyberattack worldwide—and should be read as a historical assessment of that reporting period, not as the current threat rate in 2026.
What the 2024 Threat Hunting Report covers
The report is based on observations from CrowdStrike OverWatch, the company’s proactive threat-hunting operation. CrowdStrike published it on August 20, 2024, with an executive-summary PDF and report landing page.
Free tools Windows power users keep installed
One-click scans. No signup required.
Its scope is narrower than a global incident census. The report focuses on interactive intrusions: incidents in which an adversary establishes an active presence and performs hands-on-keyboard actions inside a victim environment. A human operator can inspect systems, adapt to defenses, escalate privileges and move laterally instead of relying solely on an automated exploit or a fixed malware payload.
#1 Best Overall
- AI Motion Detection 2.0 – Driving AI to the next level, human&vehicle detection and flexible detection area are more accurate than before. For quicker locating in crucial moments, human&vehicle smart searching in recordings offers you great help.
- Tried-and-True Safe Guard – This one-stop security solution can work with TVI, AHD, CVI, CVBS & IP cameras, the kit includes 1080P cams. The 8CH 3K lite DVR can hook up with 1080P@30fps or 3K/5MP@20fps cams. Therefore, you can also DIY it with other cameras in your home.
- Reliable 24/7 Continuous Recording – With a pre-installed 1TB HDD(Support up to 10TB HDD), providing 24/7 surveillance recording for you. Upgraded H.265+ saves more storage space and uses less bandwidth, recording videos longer and smoother viewing.
- Smart Dual-Light Effectively Guard Your Home – This newly upgraded security system offers you a crisp full color night vision, IR mode and color night vision switch flexibly. Once detect intruders, immediate pushes pop up on your phone, securing your peace of mind day&night.
- Color Night Vision & IP67 Weatherproof – Built-in IR lights and white lights, these cameras can see up to 100ft in B&W night vision, full-color night vision up to 66ft. Rated IP67, these wired cameras can brave all weather, and stand from cold to hot.
The report is not the same as CrowdStrike’s 2024 Global Threat Report
The similarly named publications cover different periods and questions:
| Publication | Release date | Primary focus |
|---|---|---|
| 2024 Global Threat Report | February 21, 2024 | A broad review of the 2023 threat landscape, including eCrime, nation-state activity, cloud intrusions and breakout time. |
| 2024 Threat Hunting Report | August 20, 2024 | OverWatch observations from July 1, 2023, through June 30, 2024, emphasizing interactive intrusions and hands-on-keyboard behavior. |
For example, the Global Threat Report—not the Threat Hunting Report—reported an average eCrime breakout time of 62 minutes in 2023, down from 84 minutes, and a fastest observed breakout time of 2 minutes 7 seconds. Those statistics should not be attributed to the Threat Hunting Report. See CrowdStrike’s Global Threat Report analysis for that material.
Key findings from the report
For the report’s observation period, CrowdStrike reported the following changes in its observed interactive-intrusion dataset:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems| Finding | What it means |
|---|---|
| Interactive intrusions increased 55% | More observed incidents involved active operator participation rather than only automated activity. |
| 86% were attributed to eCrime | CrowdStrike attributed this share of observed interactive intrusions to financially motivated cybercrime activity. |
| Healthcare eCrime-related intrusions increased 75% | Healthcare saw a substantial year-over-year increase in this specific category of observed activity. |
| Technology-sector intrusions increased 60% | Technology remained the most frequently targeted industry for the seventh consecutive year in CrowdStrike’s comparison. |
| RMM use increased 70% | Attackers increasingly used remote monitoring and management software during observed intrusions. |
| 27% used RMM tools | More than one-quarter of the interactive intrusions in the dataset involved remote-management software. |
| ScreenConnect surpassed AnyDesk | ConnectWise ScreenConnect became the most observed RMM tool in CrowdStrike’s dataset. |
CrowdStrike’s report materials also say the operation tracked more than 245 adversaries. That figure comes from the report landing-page summary and should not be confused with the 230-plus figure associated with the earlier Global Threat Report.
Why interactive intrusions are difficult to detect
Traditional defenses often look for a malicious file, a known command-and-control address or a recognizable malware family. Interactive attackers can avoid those signals by using tools that are already installed or commonly accepted by administrators.
A compromised administrator might use valid credentials, PowerShell, remote services, cloud consoles, scripting tools or an approved remote-access product. Each individual action may look ordinary. The suspicious pattern often emerges only when defenders correlate:
Rank #2
- No Subscription Required with aosuBase: All recordings will be encrypted and stored in aosuBase without subscription or hidden cost. 32GB of local storage provides up to 4 months of video loop recording. Even if the cameras are damaged or lost, the data remains safe.aosuBase also provides instant notifications and stable live streaming.
- New Experience From AOSU: 1. Cross-Camera Tracking* Automatically relate videos of same period events for easy reviews. 2. Watch live streams in 4 areas at the same time on one screen to implement a wireless security camera system. 3. Control the working status of multiple outdoor security cameras with one click, not just turning them on or off.
- Solar Powered, Once Install and Works Forever: Built-in solar panel keeps the battery charged, 3 hours of sunlight daily keeps it running, even on rainy and cloud days. Install in any location just drill 3 holes, 5 minutes.
- 360° Coverage & Auto Motion Tracking: Pan & Tilt outdoor camera wireless provides all-around security. No blind spots. Activities within the target area will be automatically tracked and recorded by the camera.
- 2K Resolution, Day and Night Clarity: Capture every event that occurs around your home in 3MP resolution. More than just daytime, 4 LED lights increase the light source by 100% compared to 2 LED lights, allowing more to be seen for excellent color night vision.
- Who authenticated and whether the account normally performs that action
- Where the session originated and whether the device is familiar
- Which privileges were used and whether they were escalated
- What processes, services, scheduled tasks or remote sessions followed the login
- Whether the activity moved between endpoint, identity and cloud environments
This is why the report’s emphasis is behavioral. The question is not simply whether a tool is legitimate; it is whether the identity, location, timing, target and sequence of actions make sense together.
Recommended Free Tools
Why legitimate credentials matter
Valid credentials can help an attacker bypass controls designed primarily to stop unauthorized software. CrowdStrike highlights the use of legitimate identities as a way for adversaries to appear like authorized insiders.
Multifactor authentication remains essential, but it does not eliminate every identity risk. Organizations also need to monitor unusual login context, unfamiliar devices, impossible-travel patterns, abnormal privilege use, session theft, token abuse and suspicious access to sensitive systems.
Practical identity controls include:
- Use phishing-resistant MFA for privileged and remote-access accounts where feasible.
- Remove dormant accounts and review access during employee and contractor offboarding.
- Govern service accounts and other non-human identities, including their owners and privileges.
- Correlate identity events with endpoint and cloud activity.
- Revoke sessions and tokens promptly after suspected compromise.
- Monitor password spraying, social-engineering indicators and unusual administrative behavior.
Why attackers abuse RMM software
Remote monitoring and management tools are legitimate products used by internal IT teams, managed service providers and contractors. They are not malware simply because attackers sometimes abuse them.
An RMM product can provide remote access, command execution, persistence and lateral movement while blending into normal support activity. Using an existing administration tool may also be less conspicuous than deploying a custom remote-access implant.
The report’s 70% increase in RMM use and 27% share of observed interactive intrusions show why organizations should treat RMM governance as a security control, not only an IT inventory task.
Rank #3
- Outdoor 4 is our most affordable wireless smart security camera yet, offering up to two-year battery life for around-the-clock peace of mind. Local storage not included with Sync Module Core.
- See and speak from the Blink app — Experience 1080p HD live view, infrared night vision, and crisp two-way audio.
- Two-year battery life — Set up in minutes and get up to two years of power with the included AA Energizer lithium batteries and a Blink Sync Module Core.
- Enhanced motion detection — Be alerted to motion faster from your smartphone with dual-zone, enhanced motion detection.
- Person detection — Get alerts when a person is detected with embedded computer vision (CV) as part of an optional Blink Subscription Plan (sold separately).
Controls for RMM abuse
- Maintain an authoritative inventory of approved RMM products and installations.
- Alert when an unapproved RMM tool appears or an approved tool is installed unexpectedly.
- Log who initiated each session, from which device or network, and against which endpoint.
- Monitor new services, process ancestry, command execution and unusual installation activity.
- Separate vendor access from employee access and require MFA for both.
- Use time-limited, least-privilege access for contractors and third-party providers.
- Review whether unused remote-access features can be disabled.
Blocking every RMM product can disrupt legitimate support operations. A controlled allowlist, strong authentication and detailed session monitoring are usually more practical than treating all remote-management software as inherently malicious.
Healthcare and technology are notable sectors
CrowdStrike reported a 75% increase in eCrime-related interactive intrusions against healthcare organizations. That does not mean every healthcare organization experienced the same level of risk, but it highlights the importance of protecting clinical systems, identities, remote access and third-party support channels.
Interactive intrusions affecting the technology sector increased 60%, and technology remained the most frequently targeted industry for the seventh consecutive year in the report’s comparison. Technology companies can be attractive targets because they hold valuable intellectual property, operate highly connected environments and may provide access to customers or partners.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →FAMOUS CHOLLIMA and the insider-style access problem
CrowdStrike also highlighted FAMOUS CHOLLIMA, a North Korea-linked activity set that the company says infiltrated more than 100 primarily U.S. technology companies by posing as legitimate remote IT workers.
This example is useful because it illustrates a broader identity problem: an attacker does not always need to break in through malware if they can obtain employment, contractor or administrative access that appears legitimate. The claim is CrowdStrike’s attribution and campaign assessment, not an independently established universal count.
Defenses should therefore cover the full access lifecycle: hiring and contractor verification, device enrollment, least privilege, session monitoring, rapid offboarding and immediate revocation of credentials when access is no longer justified.
Rank #4
- 【AI Motion Detection 2.0】Driving AI to the next level, human&vehicle detection and flexible detection area are more accurate than before. For quicker locating in crucial moments, human&vehicle smart searching in recordings offers you great help.
- 【Tried-and-True Safe Guard】This one-stop security solution can work with TVI, AHD, CVI, CVBS & IP cameras, the kit includes 1080P cams. The 8CH 3K lite DVR can hook up with 1080P@30fps or 3K/5MP@20fps cams. Therefore, you can also DIY it with other cameras in your home.
- 【Reliable 24/7 Continuous Recording】With a pre-installed 1TB HDD(Support up to 10TB HDD), providing 24/7 surveillance recording for you. Upgraded H.265+ saves more storage space and uses less bandwidth, recording videos longer and smoother viewing.
- 【Smart Dual-Light Effectively Guard Your Home】This newly upgraded security system offers you a crisp full color night vision, IR mode and color night vision switch flexibly. Once detect intruders, immediate pushes pop up on your phone, securing your peace of mind day&night.
- 【Color Night Vision & IP67 Weatherproof】Built-in IR lights and white lights, these cameras can see up to 100ft in B&W night vision, full-color night vision up to 66ft. Rated IP67, these wired cameras can brave all weather, and stand from cold to hot.
What defenders should do with the findings
1. Strengthen identity monitoring
Prioritize privileged accounts, remote-access accounts, service accounts and identities with access to cloud control planes. Review unusual authentication context and privilege changes, not just failed logins.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
2. Expand endpoint telemetry
Collect process, command-line, logon, persistence and lateral-movement data from laptops, servers and high-value systems. Hunt for suspicious use of built-in tools, remote execution, new services, scheduled tasks and credential-dumping behavior.
3. Connect endpoint and cloud signals
Monitor unusual cloud administrative actions, new credentials, role changes and access from unfamiliar infrastructure. A cloud compromise may not produce obvious endpoint malware, so cloud audit logs need their own coverage.
4. Establish an RMM governance model
Define approved products, approved users, allowed sources and expected support hours. Investigate new installations and remote sessions that do not match those rules.
5. Prepare rapid containment playbooks
Interactive operators can move quickly. Playbooks should specify how to isolate a host, disable or restrict a compromised identity, revoke sessions and tokens, terminate malicious processes, remove persistence and preserve evidence.
6. Hunt for behavior chains
Threat intelligence and known indicators are useful starting points, but they should be combined with local telemetry. A hunt might connect an unusual login to a new RMM service, remote command execution and access to sensitive cloud resources.
Best Value
- Video Doorbell is our second-generation smart security doorbell with up to two years of battery life, an expanded field of view, and improved security features for more peace of mind, no matter where you are.
- Last longer with two-year battery life — Experience up to two years of smart security coverage on both devices with included AA Energizer lithium batteries and a Blink Sync Module (included with Outdoor 4).
- See and speak from the Blink app — Experience head-to-toe HD viewing from Video Doorbell and 1080p HD live view from Outdoor 4 as well as infrared night vision and crisp two-way audio.
- See more at your door with Blink Video Doorbell — Greet guests and watch packages get delivered, day and night, with head-to-toe HD view and infrared night vision. Use two-way talk to hear and speak through the Blink app.
- Enhanced motion detection with Outdoor 4 — With our all-new Outdoor 4, enjoy a wider field of view and be alerted to motion faster with dual-zone, enhanced motion detection.
What the report does not prove
- It is not a census of all attacks worldwide.
- The percentages apply to interactive intrusions observed by CrowdStrike OverWatch during the stated period.
- The 86% eCrime figure should not be presented as the share of all cyberattacks that were eCrime.
- RMM software is dual-use administrative technology, not inherently malicious.
- The findings do not establish that RMM software caused the intrusions.
- Vendor attribution, including campaign and adversary assessments, should be presented as CrowdStrike’s analysis.
- The data covers July 2023 through June 2024 and should not be treated as a current 2026 measurement.
Vendor visibility can also shape observed results. Organizations using different security products, collecting different telemetry or operating in different regions may experience a different distribution of activity.
Does the report justify buying CrowdStrike?
The report is useful even for organizations that do not use CrowdStrike. Its findings describe defensive problems—identity abuse, legitimate-tool abuse, cloud visibility and hands-on-keyboard activity—that can be addressed through multiple technology and service models.
When comparing products, evaluate whether a platform can:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →- Correlate identity, endpoint, cloud and administrative events
- Detect behavioral abuse of legitimate tools
- Identify unauthorized RMM software and suspicious remote sessions
- Search historical telemetry and support threat hunting
- Isolate hosts, disable accounts, terminate processes and remove persistence
- Integrate with email, identity, firewall, SaaS, cloud and SIEM systems
- Support the organization’s available SOC staffing and response process
CrowdStrike Falcon
CrowdStrike is a natural candidate when an organization wants advanced endpoint telemetry, behavioral detection, threat intelligence and a broad Falcon platform. Its official pricing page lists self-service tiers, but enterprise modules, services, regional availability and contract terms can change. A platform this broad also requires appropriate staffing or a managed service for investigation and response.
Microsoft Defender
Microsoft Defender for Business can be attractive to organizations already using Microsoft 365, Entra ID, Intune or Sentinel. Microsoft emphasizes correlation across endpoint, identity, email and cloud workloads through the unified Defender portal. Licensing and existing entitlements matter, so compare the total Microsoft environment rather than only the endpoint price. See Microsoft’s security pricing overview.
Managed EDR and MDR
Organizations without a 24/7 SOC may be better served by a managed detection and response provider. Huntress, for example, markets managed endpoint detection, investigation, containment and remediation on its official pricing page. Managed services reduce the need to operate every workflow internally, but they also give the provider a larger role in monitoring and response.
These options are not direct apples-to-apples comparisons. Costs may be calculated per device, user, identity, data source or service tier, and enterprise contracts can include minimums, add-ons, servers, integrations and professional services.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBottom line
CrowdStrike’s 2024 Threat Hunting Report shows why modern defense cannot rely only on malware signatures. In the report’s observed dataset, interactive intrusions rose 55%, RMM use rose 70%, and attackers frequently used legitimate identities and administration tools.
The practical priority is to understand who is acting, from where, with which privileges, against which systems and through what legitimate tools. Organizations that combine identity protection, endpoint and cloud telemetry, RMM governance, behavioral detection and fast containment will be better positioned to detect the hands-on-keyboard activity the report describes—regardless of which security vendor provides the technology.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

