Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Falcon Intelligence Recon+ was CrowdStrike’s managed digital risk protection service announced on July 28, 2021. It combined Falcon Intelligence Recon technology with CrowdStrike Intelligence analysts who monitored criminal and restricted online sources, assessed threats to a customer’s brands, employees and data, recommended responses, and helped facilitate certain takedowns. The announcement described a broad external-threat service—not a dark-web-only scanner—and did not establish present-day pricing, availability, takedown success rates or independent performance.

What Falcon Intelligence Recon+ was designed to do

CrowdStrike positioned Recon+ as a way to outsource much of the work involved in finding and responding to threats outside an organization’s network. The company said its analysts would hunt for exposure, investigate potential threats, warn customers about relevant findings and recommend mitigation.

The service was intended to protect three outward-facing targets:

  • Brands: impersonation, fraudulent accounts, phishing sites, malicious domains and harmful posts that could damage reputation or business.
  • Employees: exposed credentials, targeted attacks and activity that could put staff or corporate access at risk.
  • Sensitive data: leaks and criminal trading activity involving an organization’s information.

These capabilities are statements from CrowdStrike’s July 2021 announcement. They describe the announced scope, not independently measured outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
CrowdStrike Falcon Go | Premier Antivirus Protection for Small Businesses | Industry Leading Cybersecurity | Easy to Install | Business Software | Windows/Mac | 12 Month Subscription | 3 Licenses
  • ANTIVIRUS PROTECTION FOR YOUR BUSINESS — CrowdStrike Falcon Prevent next-gen antivirus proactively anticipates known and unknown cyber threats and evolves ahead of cyber criminals. Purchase 3 licenses.
  • EASILY MANAGE YOUR USB DEVICES — See and control any USB device in your environment. Enable safe and accountable usage of anything connected to your devices like cameras, printers, and wireless devices.
  • EASY TO USE — Falcon Go is easy to set up and manage for both technical and non-technical users. Install the Falcon sensor to your devices in just minutes to get protected.
  • HIGH QUALITY PROTECTION YOU CAN TRUST — CrowdStrike Falcon uses machine learning and 24/7 monitoring to keep your business devices protected from all types of threats from malware and ransomware to sophisticated attacks.
  • SECURE LOGIN — Login requires a password and a secondary code from a multi-factor authentication app that supports one-time passwords (TOTP). Options include Google Authenticator, Microsoft Authenticator, Duo Mobile, 1Password, Okta Verify and more.

Where CrowdStrike said analysts looked

Recon+ was described as monitoring more than conventional dark-web websites. CrowdStrike listed thousands of restricted forums, marketplaces, messaging platforms, social-media posts and data-leak sites, along with Internet Relay Chat (IRC), botnet and distributed-denial-of-service (DDoS) configurations, and messaging applications.

That source mix matters because criminal activity often moves between public services, invitation-only communities, leak sites and encrypted or semi-private channels. Coverage of a source does not mean every post is visible, attributable or actionable; the announcement did not publish a complete source list, collection method or detection-rate measurement.

How the managed service was supposed to work

  1. Collection: CrowdStrike technology and intelligence personnel monitored the external sources described in the announcement.
  2. Validation and assessment: Analysts investigated identified activity and assessed whether it represented exposure or a credible enterprise threat.
  3. Customer warning: The service issued alerts about relevant findings and explained the apparent risk.
  4. Mitigation advice: Analysts recommended response actions appropriate to the finding.
  5. Optional enforcement support: CrowdStrike said it could facilitate takedowns for certain fraudulent accounts, phishing websites, domains and malicious posts.
  6. Ongoing reporting: The announced service included monthly activity reports and invitations to quarterly threat briefings.

“Facilitate” does not mean guaranteed removal. A takedown can depend on the hosting provider, registrar, social platform, evidence requirements and applicable law. The announcement did not state a guaranteed response time or successful-removal percentage.

Recon+ in CrowdStrike’s intelligence portfolio

In 2021, CrowdStrike placed Recon+ alongside Falcon Intelligence, which it described as enriching detected events and incidents, and Falcon Intelligence Premium, which it described as providing intelligence reporting, technical and malware analysis, and threat hunting. Recon+ was the managed external-risk option in that portfolio description: analysts performed the monitoring and investigation work on the customer’s behalf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What later CrowdStrike releases do—and do not—establish

A December 2022 CrowdStrike release described Falcon Intelligence Recon as monitoring open, deep and dark web activity. It also described integration with Falcon Surface to correlate criminal activity and tradecraft with external attack-surface data, and said Falcon Surface and the Recon integration were generally available at that time.

In August 2025, CrowdStrike described a later Falcon Adversary Intelligence release with personalized threat intelligence, dark-web activity tracking, threat profiles and analyst workflows. That release does not identify Falcon Adversary Intelligence as a rename or replacement for Recon+. Product names, packaging and availability should therefore be confirmed directly with CrowdStrike before procurement.

What the published figures mean

Figure What it refers to How to interpret it
Approximately 6 trillion endpoint-related events per week A 2021 CrowdStrike statement about Falcon Threat Graph A vendor-wide platform scale claim, not the number of Recon+ findings or a measure of its protection results.
More than 265 nation-state, eCrime and hacktivist groups tracked A figure CrowdStrike stated in 2025 for its adversary-intelligence coverage Intelligence coverage context, not a Recon+ efficacy statistic.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a managed digital risk protection service can remove from your workload

An internal team normally has to decide which sources to monitor, distinguish credible exposure from noise, preserve evidence, identify the responsible provider and coordinate legal, security, communications and fraud teams. A managed service can centralize those tasks and provide an analyst-led escalation path. It does not eliminate the customer’s responsibilities.

  • Confirming which brands, domains, executives, subsidiaries and employee populations are in scope.
  • Providing authoritative evidence that an account, domain or asset belongs to the organization.
  • Resetting credentials, revoking tokens and fixing the underlying security weakness.
  • Approving legal or communications actions.
  • Responding to alerts and measuring whether remediation worked.

Questions to ask before evaluating Recon+ or a similar service

Source coverage

Ask which open, deep, dark-web, messaging and leak sources are monitored, how often they are checked, and whether coverage is continuous or periodic.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Analyst validation

Clarify how analysts verify a suspected leak or impersonation, what evidence accompanies an alert, and how false positives are handled.

Escalation and response

Request the severity model, notification targets, escalation contacts and the customer actions expected after an alert.

Takedown boundaries

Confirm which fraudulent accounts, phishing sites, domains and posts are eligible, who contacts the provider, what legal authority is required, and how unsuccessful requests are reported.

Reporting and integrations

Check whether reports are monthly, whether briefings are quarterly, and which ticketing, security-information or attack-surface workflows can receive findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Commercial status

Because the available descriptions are dated, obtain current confirmation of the product name, package contents, regional availability, service levels and price from CrowdStrike. The published material does not provide a current price or independent comparison.

Bottom line for security buyers

Falcon Intelligence Recon+ was announced as a human-supported service for finding and mitigating external threats across criminal forums, marketplaces, messaging channels, social platforms, leak sites and related infrastructure. Its distinctive promise was analyst triage and response assistance, including certain takedown efforts, rather than simply delivering a feed of dark-web mentions. The evidence available here is historical vendor documentation, so buyers should treat Recon+ as a product to verify—not assume its 2021 scope, name or availability remains unchanged.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.