CrowdStrike
Company Info
About
CrowdStrike Holdings, Inc. is an American cybersecurity technology company that provides cloud workload and endpoint security, threat intelligence, and cyberattack response services. The company's flagship offering is the Falcon platform, an AI-native, cloud-based platform designed to prevent breaches by consolidating cybersecurity measures. The Falcon platform utilizes a single, lightweight sensor to collect telemetry data, which is then analyzed by the CrowdStrike Security Cloud to deliver hyper-accurate detections, automated protection, and remediation. CrowdStrike has been involved in investigations of several high-profile cyberattacks and aims to address the limitations of traditional malware-based defenses with its advanced approach. The company emphasizes its AI-driven capabilities, partner-first go-to-market model, and international expansion.
21.0k+
9144Total headcount
1.1M+
20513Social media followers
+94
Rapid Expansion
+84
Surging
Merger & Acquisition
Acquisitions
CrowdStrike, a cybersecurity provider, is acquiring identity security startup SGNL for approximately $740 million. Announced January 8, 2026, with an expected close in Q1 2027, the acquisition aims to bolster CrowdStrike's Falcon platform against AI cyberattacks by enhancing identity access management and real-time risk capabilities. This strategic move strengthens CrowdStrike's market position in AI-driven cybersecurity. SGNL will be integrated to improve human and AI identity protection for customers. This is a pending acquisition.
CrowdStrike is set to acquire Pangea (AI security startup, GenAI guardrails) for an estimated $260 million, as reported by The Wall Street Journal. Announced during Fal.Con 2025, this strategic acquisition aims to expand CrowdStrike's AI security portfolio, enabling "AI detection and response" capabilities. The deal is currently pending, enhancing CrowdStrike's offerings for securing AI-powered applications and bolstering its competitive stance in the evolving cybersecurity landscape. Product integration is expected to focus on new AI security features.
CrowdStrike announced its intent to acquire Madrid-based telemetry startup Onum for $290M, expected around August 27, 2025. This strategic move aims to accelerate CrowdStrike’s Falcon Next-Gen SIEM development by integrating Onum's proprietary in-memory architecture. The acquisition will eliminate data integration bottlenecks and enable in-stream threat detection, strengthening CrowdStrike's AI-powered security portfolio and competitive stance. Onum will likely be integrated into CrowdStrike's offerings, enhancing product capabilities. The event status is MA_PENDING.
Acquired by
Est Employees
Historical growth data
Est Followers
Follower momentum
Momentum Analysis
Growth vs Heat index comparison
Unlock More Insights & Analysis
Gain access to historical headcount trends, social momentum, certifications, and proprietary growth analytics.
Understand how CrowdStrike products map to security capabilities vs frameworks.
CrowdStrike Falcon for Mobile
CrowdStrike
CrowdStrike Falcon for Mobile extends the unified CrowdStrike Falcon platform's endpoint detection and response (EDR) and extended detection and response (XDR) capabilities to iOS and Android devices. It provides comprehensive security against mobile-specific threats such as phishing attempts, mobile malware, network disruptions, and unauthorized access, including jailbreaking/rooting. The solution delivers real-time detection and prevention by analyzing telemetry from the device's file system, network stack, and applications. It integrates with existing Unified Endpoint Management (UEM) and Mobile Device Management (MDM) systems for streamlined deployment, supporting zero-touch enrollment and offering iOS unmanaged support for securing devices without traditional MDM. Falcon for Mobile incorporates Zero Trust Assessment (ZTA) for continuous evaluation of device security posture and integrates with Android Enterprise for enhanced trust signals, enabling dynamic conditional access policies. It also includes FalconID for phishing-resistant multi-factor authentication (MFA) and identity protection, leveraging real-time identity and endpoint telemetry for access decisions. Detections are mapped to the MITRE ATT&CK Matrices for Mobile, enabling proactive threat hunting and rapid incident investigation through a unified console alongside traditional endpoint data, leveraging CrowdStrike's AI-powered Security Cloud and Falcon Fusion for automated response workflows. The solution prioritizes user privacy by focusing monitoring on corporate applications and maintains a lightweight design to minimize impact on device performance and battery life.
Falcon Adversary Intelligence Premium
CrowdStrike
CrowdStrike Falcon Adversary Intelligence Premium is a comprehensive threat intelligence solution designed to enhance an organization's security posture by providing in-depth insights into adversarial tactics and tradecraft. It integrates world-class research, including over 265 tracked adversaries and thousands of annual intelligence reports, directly into security operations. The product offers advanced capabilities such as personalized threat models, real-time Indicators of Compromise (IoCs), automated malware analysis, and proactive brand and fraud monitoring across the open, deep, and dark web. It leverages AI-powered workflows and pre-built detection libraries to streamline security engineering, reduce the need for extensive in-house threat research, and accelerate incident investigation and response. Falcon Adversary Intelligence Premium is a prerequisite for Falcon Counter Adversary Operations Elite, which provides dedicated human analyst support. It is delivered as a SaaS solution within the CrowdStrike Falcon platform.
Falcon Device Control
CrowdStrike
CrowdStrike Falcon Device Control is a module within the cloud-native CrowdStrike Falcon platform, providing comprehensive visibility and granular control over removable media and peripheral devices across Windows, macOS, and Linux endpoints. It supports various connection types, including USB drives, SD cards, Bluetooth, and Thunderbolt devices. The solution enables administrators to define and enforce policies to mitigate risks associated with malware introduction and data exfiltration. It automatically discovers connected devices, reporting details such as device types, manufacturers, and serial numbers, which are presented through detailed usage dashboards. Policies can be configured for read/write, read-only, or no-execute access controls, and can block the execution of applications directly from removable media. Granular policy exceptions can be established based on device class, vendor, product, or serial number. When integrated with Falcon Insight XDR, the solution extends visibility by offering searchable historical logs of device usage, including files written to devices, and leverages machine learning to detect source code movement and identify over 40 programming languages for enhanced data loss prevention. Policies are centrally managed and apply consistently to both online and offline endpoints, all delivered via a single, lightweight agent architecture. This capability is crucial for safeguarding sensitive data, maintaining compliance, and preventing insider threats by ensuring only approved devices are utilized within an organization's environment.
CrowdStrike Falcon Insight for Forensics and Response
CrowdStrike
CrowdStrike Falcon Insight for Forensics and Response is a module within the unified Falcon platform that provides comprehensive capabilities for forensic data collection, analysis, and incident response. It enables security teams to efficiently gather both point-in-time and historical forensic artifacts from endpoints across Windows, macOS, and Linux operating systems. Leveraging a lightweight, dissolvable executable and the CrowdStrike Security Cloud, the solution minimizes endpoint impact while facilitating rapid data acquisition. It integrates with the broader Falcon platform to enrich forensic data with threat intelligence and behavioral analytics, offering customizable dashboards and filters for in-depth investigation and compromise assessments. This module empowers incident responders to accelerate investigations, understand attack timelines, and effectively remediate cyber incidents by providing detailed visibility into adversary activity and system changes.
CrowdStrike Falcon Cloud Security
CrowdStrike
CrowdStrike Falcon Cloud Security is a unified, AI-native Cloud-Native Application Protection Platform (CNAPP) that provides comprehensive security across multi-cloud and hybrid environments, spanning the entire application lifecycle from code development to runtime. It integrates both agent-based and agentless protection mechanisms to deliver continuous visibility, robust posture management, and advanced threat detection and response for cloud workloads, containers, serverless functions, and AI models. The platform actively prevents misconfigurations, identifies and prioritizes vulnerabilities, and mitigates risks using AI-driven insights and extensive threat intelligence, including adversary-informed risk prioritization. Key capabilities encompass Cloud Security Posture Management (CSPM), Cloud Workload Protection Platform (CWPP), Container and Kubernetes Security, Infrastructure as Code (IaC) scanning, and Data Security Posture Management (DSPM) for data at rest and in motion. It also provides real-time Cloud Detection and Response (CDR), AI Security Posture Management (AI-SPM) for securing AI applications and models (including LLMs and AI agents), Application Security Posture Management (ASPM), Cloud Infrastructure Entitlement Management (CIEM), and enhanced identity protection within cloud environments. Falcon Cloud Security aims to stop cloud breaches by unifying security operations, enhancing compliance, and providing a single console for managing diverse cloud security challenges, leveraging a lightweight agent architecture for rapid deployment and performance, and offering full lifecycle protection for AI models.
CrowdStrike Falcon® Fusion SOAR
CrowdStrike
CrowdStrike Falcon® Fusion SOAR is a cloud-native Security Orchestration, Automation, and Response (SOAR) solution integrated within the unified CrowdStrike Falcon platform. It enables security operations teams to automate repetitive tasks, streamline workflows, and orchestrate incident response across the Falcon platform and various third-party security and IT tools. The platform leverages advanced AI and automation, including agentic workflows and deep integration with Charlotte AI, to enhance efficiency and accelerate threat investigation and remediation. Key capabilities include a no-code visual workflow builder for rapid deployment, pre-built playbooks, customizable actions, and a metrics dashboard for continuous improvement of security posture and reduction of Mean Time To Respond (MTTR). Falcon Fusion SOAR supports a wide range of use cases, from automating alert triage and enrichment to orchestrating containment actions, vulnerability patch management, and data protection workflows. It also offers HTTP Actions for direct API integrations and Falcon Foundry for building custom actions, allowing security analysts to focus on high-impact threats and improve overall operational effectiveness and consistency.
CrowdStrike Falcon Adversary Intelligence
CrowdStrike
CrowdStrike Falcon Adversary Intelligence is a cloud-native threat intelligence solution designed to provide real-time, personalized insights into adversary methods and emerging threats. It integrates within the broader CrowdStrike Falcon platform and with third-party security tools, leveraging AI-powered workflows for automated threat intelligence orchestration and accelerated incident response. The platform offers comprehensive adversary profiles, dark web monitoring (including Falcon Adversary Intelligence Recon for digital risk protection), and contextual indicators of compromise (IOCs) to proactively defend against cyberattacks. It aims to significantly reduce the time required for threat research, malware analysis, and triage efforts, enabling faster detection, investigation, and response. Falcon Adversary Intelligence also includes proactive brand and fraud monitoring, identifying external threats such as domain impersonations, exposed credentials, and data leaks. It supports automated security workflows with prebuilt playbooks and APIs, delivering tailored threat intelligence aligned to an organization's unique environment and risk profile. This enhances detection, investigation, and response capabilities by operationalizing intelligence at scale. It is a core component of the Falcon Counter Adversary Operations portfolio, which also includes Falcon Adversary Intelligence Premium, Falcon Counter Adversary Operations Elite, and Falcon Adversary OverWatch.
CrowdStrike Falcon for XIoT
CrowdStrike
CrowdStrike Falcon for XIoT delivers unified, AI-native security for Extended Internet of Things (XIoT) assets, encompassing Operational Technology (OT), Industrial IoT (IIoT), and Internet of Medical Things (IoMT). Built on the CrowdStrike Falcon platform, it provides real-time visibility, AI-powered threat prevention, detection, and response across converged IT and OT environments. The solution leverages a lightweight, cloud-native architecture for zero-touch asset discovery and continuous monitoring, enabling organizations to identify and inventory industrial assets without disrupting critical operations. Falcon for XIoT integrates AI-powered analytics, including ExPRT.AI, to prioritize vulnerabilities with contextual intelligence, offering tailored remediation guidance. It defends against advanced threats like malware and ransomware targeting industrial systems, ensuring business continuity through rapid response and reduced operational risks. The platform supports flexible deployment, is validated for interoperability with leading Industrial Control System (ICS) vendors like Rockwell Automation and Siemens, and offers enhanced zero-touch asset discovery, real-time segmentation visibility, and unified insight within a dynamic user experience. Recent expansions include extended protection to healthcare environments and integration with CrowdStrike Falcon® Next-Gen Identity Security and Falcon Complete Next-Gen MDR for comprehensive oversight and expert protection. It also provides FedRAMP High authorized OT and IT asset visibility and protection for government agencies.
Charlotte AI
CrowdStrike
CrowdStrike Charlotte AI is an advanced agentic and generative AI assistant integrated within the CrowdStrike Falcon platform, designed to enhance cybersecurity operations for users of all skill levels. It leverages a multi-model AI architecture, CrowdStrike's extensive security telemetry, and threat intelligence to provide real-time insights and automate complex security workflows. Charlotte AI acts as an AI-native security analyst, enabling teams to triage detections with high accuracy, accelerate investigations, and automate response actions through natural language interactions. Key capabilities include agentic workflows for autonomous reasoning and action, such as Detection Triage, Agentic Response, and Agentic Workflows, which streamline incident response, malware analysis, and exposure prioritization. The platform also features Charlotte AI AgentWorks, a no-code development environment for building custom security agents, and Charlotte Agentic SOAR for orchestrating human-AI collaboration and automated playbooks across the security ecosystem. It aims to reduce manual tasks, mitigate the cybersecurity skills gap, and enable faster, more precise threat detection and response with bounded autonomy and built-in guardrails for responsible AI adoption. It has achieved FedRAMP High Authorization, making it available to federal, state, and local agencies through the Falcon platform in GovCloud.
CrowdStrike Falcon Platform
CrowdStrike
The CrowdStrike Falcon Platform is a cloud-native, AI-powered cybersecurity solution delivered via a single, lightweight agent, providing comprehensive protection across endpoints, cloud workloads, identity, and data. It unifies next-generation antivirus (NGAV), endpoint detection and response (EDR), extended detection and response (XDR), managed threat hunting (Falcon OverWatch), and integrated threat intelligence. Leveraging the CrowdStrike Security Cloud and its proprietary Threat Graph, Asset Graph, Risk Graph, and Intel Graph, the platform offers continuous raw event capture for comprehensive visibility, enabling rapid investigation and remediation through intelligent prioritization and an Incident Workbench. Recent advancements, including the 'Raptor' release, have re-architected the platform for petabyte-scale data collection and introduced generative AI-powered investigations with Charlotte AI Investigator, extending XDR capabilities to all customers. The platform emphasizes an AI-native architecture, providing advanced threat detection and prevention, including capabilities for AI agent discovery, shadow AI governance, and runtime threat detection. It is available in various tiers, such as Falcon Go, Falcon Pro, Falcon Enterprise, Falcon Premium, and Falcon Complete, offering scalable protection and performance without requiring constant signature updates or on-premises management infrastructure. The Falcon platform is positioned as an "Agentic Security Platform" designed to secure AI across the enterprise and stop AI-accelerated adversaries.
CrowdStrike Falcon Exposure Management
CrowdStrike
CrowdStrike Falcon Exposure Management is an AI-powered platform designed to proactively reduce cyber risk by providing real-time visibility and continuous assessment across the entire attack surface. It offers comprehensive asset discovery, encompassing managed, unmanaged, external, cloud, network, OT/IoT, and shadow AI assets, along with applications, accounts, and identities. The platform performs maintenance-free vulnerability assessments, including software CVEs, misconfigurations, end-of-support-life detection, and browser extension risks. Leveraging its patented ExPRT.AI model, threat intelligence, and adversary context, it prioritizes vulnerabilities based on exploitability likelihood, asset criticality, and real-world attack paths, enabling security teams to focus on the most critical risks. Falcon Exposure Management integrates natively with the broader CrowdStrike Falcon platform, utilizing a single, lightweight agent for deployment and facilitating consolidated visibility, attack path visualization, and automated remediation actions through Falcon Fusion SOAR. Recent enhancements include Network Vulnerability Assessment for network devices, AI Discovery for identifying AI components across environments, and expanded support for third-party environments, allowing organizations to gain exploitability-driven prioritization and continuous visibility without requiring CrowdStrike endpoint solutions. It supports compliance with industry standards like CIS Benchmarks and ingests third-party vulnerability data, aiming to unify exposure management and improve overall security posture. The platform is recognized as a leader in the Exposure Management market, emphasizing real-time, continuous monitoring over traditional periodic scans to keep pace with evolving threats.
Falcon Cloud Security
CrowdStrike
CrowdStrike Falcon Cloud Security is a unified Cloud-Native Application Protection Platform (CNAPP) that delivers comprehensive security across multi-cloud and hybrid environments, from code to runtime. It integrates agentless visibility with the Falcon sensor, combining real-time detection, AI-driven insights, and automated response. The platform provides Cloud Security Posture Management (CSPM) to detect and remediate misconfigurations, Cloud Workload Protection (CWP) for preventing threats and protecting workloads, and Cloud Detection and Response (CDR) to accelerate incident response. It also includes Cloud Infrastructure Entitlement Management (CIEM) for least-privilege access, Container and Kubernetes Security, Application Security Posture Management (ASPM), Infrastructure as Code (IaC) Scanning, AI Security Posture Management (AI-SPM) for securing AI models and infrastructure, and Data Security Posture Management (DSPM) for sensitive data discovery and classification. Leveraging the CrowdStrike Security Cloud and AI, Falcon Cloud Security aims to prevent breaches, reduce alert fatigue, and enhance threat intelligence, enabling organizations to secure their cloud infrastructure and applications effectively and maintain continuous compliance with various industry regulations and frameworks.
Falcon Next-Gen SIEM
CrowdStrike
CrowdStrike Falcon Next-Gen SIEM is a cloud-native platform designed to enhance security operations by providing rapid data integration, real-time threat detection, and automated incident response. It consolidates data from various sources, enabling security teams to detect and respond to breaches with unprecedented speed and efficiency. The platform leverages AI to streamline investigations and automate workflows, significantly reducing the time and cost associated with traditional SIEM solutions.
Falcon Discover
CrowdStrike
CrowdStrike Falcon Discover is a core module within the unified CrowdStrike Falcon platform, providing comprehensive IT hygiene and real-time asset visibility across an organization's entire environment. It continuously monitors and inventories managed and unmanaged assets, including endpoints, servers, cloud instances (like AWS EC2), applications, and user accounts, leveraging the same lightweight agent architecture as the broader Falcon platform. Falcon Discover identifies unauthorized systems, applications, and activities, enabling security operations teams to maintain a defensible security posture and reduce the attack surface. Key capabilities include tracking asset additions and removals, monitoring application usage for licensing and security, identifying unmanaged or unauthorized software, and gaining insights into user account activity, including privileged access and password changes. It extends visibility to cloud environments by integrating with cloud logs to enumerate existing deployments and monitor modifications. Recent enhancements include zero-touch discovery for XIoT assets (including IoT and OT environments), providing continuous operational insight without intrusive scans, and improved system insights for hardware attributes, resource usage, drive encryption status, and OS security settings. The module provides dashboards and automated reporting to support audit and compliance requirements, offering crucial context for vulnerability management and incident response by integrating with other Falcon modules like Falcon Spotlight for vulnerability insights. It is also a key component of CrowdStrike Falcon Exposure Management, offering unparalleled real-time asset discovery to help prioritize and remediate risks.
CrowdStrike Falcon Complete Next-Gen MDR
CrowdStrike
CrowdStrike Falcon Complete Next-Gen MDR is a fully managed detection and response (MDR) service that leverages the AI-native CrowdStrike Falcon platform to proactively stop breaches across the entire attack surface. It integrates next-generation antivirus (Falcon Prevent), endpoint detection and response (Falcon Insight), and managed threat hunting (Falcon OverWatch) with 24/7 monitoring, investigation, and full-cycle remediation by CrowdStrike's security experts. The service extends protection beyond traditional endpoints to include cloud workloads, identity, and third-party data sources via Falcon Next-Gen SIEM and XDR capabilities, providing unified cross-domain visibility. Falcon Complete Next-Gen MDR utilizes adaptive AI and automation alongside expert-led response, aiming to reduce cybersecurity risks and operational burdens, and is backed by a breach prevention warranty. It focuses on rapid detection, investigation, and remediation, often measured in minutes, and is continuously refined with frontline threat intelligence.
CrowdStrike Falcon Data Security
CrowdStrike
CrowdStrike Falcon Data Security is an AI-native, unified data protection solution integrated within the CrowdStrike Falcon platform, designed to prevent unauthorized data movement and mitigate insider threats across diverse enterprise environments. Leveraging a single, lightweight agent, it provides real-time visibility and control over sensitive data at rest and in motion across endpoints (Windows and macOS), cloud infrastructure, SaaS applications, and generative AI (GenAI) workflows. The platform employs a combination of content and context-aware analysis, including proprietary Similarity Detection DNA technology, to accurately identify and classify sensitive information, even when modified or repackaged. It enables organizations to define granular policies for data egress, detect encryption attempts on sensitive files, and block data leakage to managed and unmanaged GenAI tools. Falcon Data Security extends Data Security Posture Management (DSPM) into runtime for cloud environments, utilizing eBPF for real-time monitoring of data flows without requiring additional infrastructure. It offers a unified console for investigations, policy simulation, and dynamic risk scoring for insider threat detection, aiming to replace fragmented legacy Data Loss Prevention (DLP) solutions with a streamlined, integrated approach to data protection. It also includes AI-powered data classification tools and an Insider Threat Dashboard for correlated identity and data protection telemetry.
CrowdStrike Falcon® Next-Gen Identity Security
CrowdStrike
CrowdStrike Falcon® Next-Gen Identity Security is an AI-native, unified platform designed to provide continuous identity security across human, non-human, and AI agent identities throughout the hybrid identity lifecycle. It integrates initial access prevention, modern privileged access management (PAM) with just-in-time access, identity threat detection and response (ITDR), and SaaS identity security into a single solution. Leveraging a lightweight sensor and the CrowdStrike Security Cloud, the platform offers real-time visibility into identity security gaps, automatically classifies accounts, and provides dynamic threat detection powered by advanced machine learning and behavioral analytics. It extends protection to legacy and unmanaged systems, including Microsoft Active Directory and Entra ID, and supports various identity providers and SaaS applications. The solution enables dynamic, risk-based conditional access, phishing-resistant MFA (FalconID), and automated response actions to mitigate identity-based breaches, prevent lateral movement, and stop privilege escalation. This comprehensive approach unifies endpoint and identity security, aiming to eliminate fragmented security controls and provide end-to-end identity protection across endpoints, cloud, and SaaS environments. It also offers 24/7 managed identity protection through CrowdStrike Falcon® Complete and Falcon Adversary OverWatch®.
CrowdStrike Falcon Next-Gen Identity Security
CrowdStrike
CrowdStrike Falcon Next-Gen Identity Security is a comprehensive, AI-native solution within the CrowdStrike Falcon platform designed to protect human, non-human, and AI agent identities across hybrid environments, including on-premises Active Directory, cloud identity providers like Entra ID and Okta, and SaaS applications. It unifies initial access prevention, modern privileged access management (PAM), identity threat detection and response (ITDR), and SaaS identity security. Leveraging advanced AI and machine learning, the solution continuously analyzes live traffic and behavioral baselines to detect and prevent identity-based attacks such as credential compromise, lateral movement, and privilege escalation in real time. It offers hyper-accurate threat detection, reducing false positives and improving incident response by correlating events around user and device activities. The platform enables risk-based conditional access policies, dynamically enforcing multi-factor authentication (MFA) based on risk levels to ensure frictionless security for legitimate users while blocking anomalous activity. It extends protection to legacy and unmanaged systems, provides extensive MITRE ATT&CK® coverage, and secures the entire SaaS stack by detecting threats across over 150 SaaS applications. Integrated with the Falcon platform's single lightweight sensor, it delivers unified endpoint and identity security without requiring separate identity-specific agents on domain controllers. Key innovations include FalconID for phishing-resistant MFA and Falcon Privileged Access for just-in-time access and zero standing privileges.
CrowdStrike Falcon® Prevent
CrowdStrike
CrowdStrike Falcon® Prevent is a cloud-native, AI-powered next-generation antivirus (NGAV) solution that delivers comprehensive endpoint protection against a broad spectrum of cyber threats. It leverages advanced machine learning, artificial intelligence (AI), behavioral analytics, high-performance memory scanning, and real-time threat intelligence to proactively identify and prevent malicious activities, including known and unknown malware, ransomware, fileless attacks, exploits, poisoned open-source packages, and the abuse of trusted applications. Operating via a single, lightweight agent, Falcon Prevent eliminates the need for constant signature updates and on-premises management infrastructure, simplifying deployment and reducing system impact. It provides high-fidelity detection with minimal false positives and offers continuous protection across diverse operating systems such as Windows, macOS, and Linux, even when endpoints are offline. As a core component of the broader CrowdStrike Falcon platform, it integrates AI-powered Indicators of Attack (IOAs) and script control to detect sophisticated behaviors and provides robust exploit blocking. The solution is delivered as a software-as-a-service (SaaS) offering, ensuring continuous updates and protection, and is recognized as a leading solution for replacing legacy antivirus products.
CrowdStrike Falcon Adversary Intelligence Premium
CrowdStrike
CrowdStrike Falcon Adversary Intelligence Premium is a cloud-native threat intelligence solution that provides security teams with in-depth insights into adversary tactics, techniques, and procedures (TTPs) to proactively defend against cyber threats. It delivers world-class research, real-time threat alerts, and detailed intelligence reports from CrowdStrike's global intelligence team, tracking over 281 adversaries including nation-state, eCrime, and hacktivist groups. The solution integrates threat intelligence directly into security operations workflows, enhancing detection engineering with pre-built hunting queries and detection rules, and accelerating incident response. Key capabilities include automated malware analysis, real-time global Indicators of Compromise (IOCs), and brand and fraud monitoring to identify external threats across the open, deep, and dark web. It also incorporates CrowdStrike Threat AI, an Agentic Threat Intelligence suite, to accelerate analyst workflows and improve security posture, including the Malware Analysis Agent and Hunt Agent. Falcon Adversary Intelligence Premium is designed to augment or replace in-house threat research, reduce investigation times by up to 97%, and enable organizations to adapt security controls as adversary tactics evolve. It provides personalized threat intelligence aligned to an organization's unique environment and risk profile, delivering tactical, operational, and strategic insights. The product is part of the broader Falcon Counter Adversary Operations portfolio.
CrowdStrike Falcon Shield
CrowdStrike
CrowdStrike Falcon Shield is an AI-native SaaS security solution that provides comprehensive visibility, posture management, and threat protection across an organization's SaaS application environment. It integrates with over 150 critical SaaS applications, including Google Workspace, Microsoft 365, Salesforce, and ServiceNow, to continuously monitor for misconfigurations, identity risks, and active threats. The platform offers real-time security checks, automated remediation, and proactive threat detection to identify and mitigate vulnerabilities across sanctioned and shadow applications. Falcon Shield secures human and non-human identities, detecting over-permissioned, high-risk, or dormant accounts, and enforces security policies to prevent unauthorized access and lateral movement. With over 3,500 built-in security checks, it helps organizations maintain compliance, reduce their SaaS attack surface, and protect sensitive data. Falcon Shield also provides visibility into AI agents across SaaS platforms, mapping their access, detecting risky behavior, and enabling governance. It is an integral part of CrowdStrike's Falcon Next-Gen Identity Security and integrates with Falcon Next-Gen SIEM, delivering unified, AI-native protection against identity-driven, cross-domain attacks.
Falcon FileVantage
CrowdStrike
CrowdStrike Falcon FileVantage is a cloud-native File Integrity Monitoring (FIM) solution integrated within the CrowdStrike Falcon platform, designed to provide real-time visibility and contextual intelligence into changes affecting critical files, folders, and registry settings across an organization's environment. Leveraging the Falcon platform's lightweight agent, it continuously monitors for modifications, creations, deletions, and access attempts on sensitive system, configuration, and content files. The solution enables security operations teams to define and apply granular policies, including predefined and custom rules, to focus monitoring efforts and reduce alert fatigue. By correlating file change data with CrowdStrike's extensive threat intelligence and detection capabilities, Falcon FileVantage enriches alerts with adversary activity context, allowing for rapid prioritization and response to potentially malicious changes. It offers comprehensive dashboards for both macro and micro views of file integrity, aiding in compliance adherence for various regulatory standards such as PCI DSS and HIPAA, and enhancing the overall security posture by enabling swift identification and remediation of unauthorized or suspicious alterations. The architecture is SaaS-based, ensuring scalability and ease of deployment.
CrowdStrike Falcon Adversary OverWatch Next-Gen SIEM
CrowdStrike
CrowdStrike Falcon Adversary OverWatch Next-Gen SIEM is a managed threat hunting service that extends proactive detection and disruption of sophisticated adversaries across an organization's entire attack surface. Leveraging the AI-native CrowdStrike Falcon platform, this service combines artificial intelligence with an elite team of human threat hunters to identify novel attacks, advanced persistent threats, and stealthy adversary tradecraft that often evades automated defenses. It provides 24/7 expert-led threat hunting across endpoints, identity, cloud environments, and integrates with third-party data ingested by Falcon Next-Gen SIEM, such as network edge devices, identity and access management tools, SaaS applications, and email security tools. Key capabilities include advanced user and entity behavior analytics (UEBA) for insider threat detection, unified identity security, and integrated case management for accelerated response. This managed service significantly reduces the operational burden and costs associated with maintaining an in-house threat hunting team, ensuring robust defense against evolving digital threats by continuously hunting, investigating, and advising on threat activity across both first-party and third-party telemetry.
CrowdStrike Falcon® Insight XDR
CrowdStrike
CrowdStrike Falcon® Insight XDR is a cloud-native extended detection and response (XDR) solution built on the CrowdStrike Falcon platform, leveraging its single lightweight agent architecture. It unifies security telemetry from endpoints, cloud workloads, identity, and third-party sources to provide comprehensive visibility and accelerate threat detection, investigation, and response across the enterprise. The solution integrates Endpoint Detection and Response (EDR) capabilities with broader XDR functionality, correlating diverse security data through AI-powered analytics, machine learning, and CrowdStrike's proprietary Threat Graph® to identify sophisticated attack patterns and prioritize high-fidelity alerts. Key features include real-time threat hunting, incident workflows, AI-powered investigations with Charlotte AI™, and integration with Falcon Fusion SOAR for automated remediation. It aims to reduce mean time to detect and respond to threats by providing a unified command console for security operations, enhancing situational awareness, and streamlining collaboration among security analysts. Falcon Insight XDR supports both native CrowdStrike telemetry and ingestion of data from various third-party security tools, offering a flexible approach to XDR deployment and enabling cross-domain context to understand the full scope of an attack and automate response actions. The platform is continuously updated and offers broad compatibility across various operating systems, including Windows, macOS, Linux, ChromeOS, iOS, and Android.
CrowdStrike Falcon® Seraphic® Enterprise Browser
CrowdStrike
CrowdStrike Falcon® Seraphic® Enterprise Browser is a next-generation browser runtime security and access solution that turns any standard browser (such as Chrome, Edge, Safari, Firefox, or Chromium-based browsers) into a secure enterprise browser without forcing users into restrictive walled gardens or requiring separate browser apps. By decoupling security controls from the underlying browser binary, it delivers continuous in-session visibility and protection. The platform bridges the gap between endpoints, identities, and cloud environments by combining deep runtime protection against zero-days, session hijacking, and malicious extensions with granular data loss prevention (DLP), AI and generative AI governance, and clientless Zero Trust access for corporate and unmanaged (BYOD/contractor) devices. It enables organizations to secure the modern digital workspace directly where work happens.
CrowdStrike Falcon Sandbox
CrowdStrike
CrowdStrike Falcon Sandbox is a cloud-native malware analysis solution that provides in-depth behavioral insights into evasive and unknown threats by safely detonating suspicious files and URLs within an isolated virtual environment. It observes the complete execution path and system interactions, generating comprehensive reports that detail malicious activities, network communication patterns, exploited vulnerabilities, and persistence mechanisms. These reports are enriched with threat intelligence, delivering actionable indicators of compromise (IOCs) to security teams. The platform supports a wide range of file types, including executables, documents, and scripts, and offers both hosted cloud and on-premises deployment options. It integrates with existing security ecosystems through extensive APIs and pre-built connectors, enhancing incident response workflows, threat hunting, and security control validation. Falcon Sandbox aids in understanding sophisticated malware attacks, prioritizing incidents, and proactively strengthening an organization's security posture by providing detailed context around threat behaviors. It operates as a module within the broader CrowdStrike Falcon platform, leveraging its resources and expertise for continuous feature enhancements and automated analysis.
Falcon for IT
CrowdStrike
CrowdStrike Falcon for IT is an AI-native module within the unified CrowdStrike Falcon platform, designed to converge IT and security operations for comprehensive endpoint management and infrastructure security across Windows, macOS, and Linux environments. Leveraging AI-native capabilities, including CrowdStrike Charlotte AI, it provides real-time visibility and control over endpoints, servers, and cloud workloads. The solution facilitates natural language querying of the entire IT estate and supports a robust query language (osquery), enabling use cases such as fleet management, compliance enforcement, and forensic investigations. Key features include AI Discovery and Governance for identifying and managing AI technologies on endpoints, risk-based patching that prioritizes vulnerabilities based on adversary intelligence and generates Patch Safety Scores, and automated baseline enforcement to prevent configuration drift and maintain secure endpoint states. Falcon for IT consolidates disparate tools into a single, lightweight agent and console, empowering organizations to rapidly remediate issues, enforce security standards, and optimize IT operations by bridging the gap between security and IT teams. It also offers turnkey automations through content packs for various operational workflows, enhancing application resilience and device control, and supports secure boot certificate lifecycle management at scale. The platform's real-time response (RTR) capabilities allow for immediate actions like policy changes, software updates, and file management directly on endpoints.
CrowdStrike Falcon Firewall Management
CrowdStrike
CrowdStrike Falcon Firewall Management is a cloud-native module within the CrowdStrike Falcon platform that centralizes and simplifies the management of host firewalls across Windows, macOS, and Linux operating systems. It leverages a single, lightweight Falcon agent and a unified management console to enable organizations to create, enforce, and maintain granular firewall rules and policies. The platform provides real-time visibility into network activities, matched rules, potential threats, and anomalies, thereby enhancing protection against network-based attacks. Key capabilities include flexible policy creation using templates, the ability to define reusable rule groups, and rapid propagation of changes. It streamlines operations by eliminating the complexity associated with native firewalls, offering an intuitive interface for monitoring and troubleshooting. Falcon Firewall Management supports compliance by allowing auditing of rule changes and consistent policy application across diverse environments, deploying rapidly without complex configurations or reboots. It integrates seamlessly with other Falcon modules, providing a cohesive approach to endpoint security and threat response. This module is available as an add-on or as part of the Falcon Pro bundle and higher tiers.
Falcon Counter Adversary Operations Elite
CrowdStrike
CrowdStrike's Falcon Counter Adversary Operations Elite provides organizations with access to dedicated analysts who specialize in adversarial intelligence and advanced threat hunting. This service focuses on identifying and disrupting sophisticated threats targeting the organization by leveraging extensive threat intelligence and real-time monitoring. The assigned analyst collaborates closely with the organization to tailor threat hunting strategies and provide proactive notifications about potential threats, enhancing the organization's overall cybersecurity posture.
Falcon Spotlight
CrowdStrike
CrowdStrike Falcon Spotlight is a cloud-native, scanless vulnerability management solution that provides real-time assessment and prioritization of security exposures across endpoints. Leveraging the single, lightweight agent of the CrowdStrike Falcon platform, it continuously identifies vulnerabilities in operating systems and applications without the need for traditional, resource-intensive scanning. This deep integration with the Falcon platform enables a unified approach to endpoint protection, threat detection, and incident response. Falcon Spotlight utilizes AI-powered Exploit Prediction Rating (ExPRT.AI) to dynamically prioritize vulnerabilities based on their exploit status and real-world threat intelligence, allowing security teams to focus on the most critical risks. It offers comprehensive visibility across physical, virtual, on-premise, off-network, and cloud environments, providing intuitive dashboards and detailed reports for enhanced security posture management. By streamlining vulnerability assessment and offering automated remediation guidance, Falcon Spotlight helps organizations reduce their attack surface, improve response times, and strengthen their overall cybersecurity posture with minimal operational impact.
CrowdStrike Falcon
CrowdStrike
CrowdStrike Falcon is an AI-native cybersecurity platform designed to protect organizations from breaches. It provides endpoint security, threat intelligence, and cyberattack response services. The platform unifies various security modules, including next-generation antivirus (NGAV), endpoint detection and response (EDR), threat intelligence, and managed threat hunting, all through a single lightweight agent and a cloud-native architecture. This approach aims to simplify deployment, reduce complexity, and offer scalable protection across endpoints, cloud workloads, identities, and data. Falcon leverages artificial intelligence (AI) and machine learning (ML) to detect and prevent both known and unknown threats, including malware, fileless attacks, and zero-day exploits. It offers capabilities such as real-time monitoring, behavioral analysis, automated remediation, and vulnerability management. The platform is targeted at businesses of all sizes seeking to bolster their security posture against sophisticated cyber threats and streamline their security operations. CrowdStrike Falcon can be deployed across Windows, macOS, and Linux operating systems, covering desktops, servers, and virtual machines.
