CrowdStrike
Company Info
About
CrowdStrike Holdings, Inc. is an American cybersecurity technology company that provides cloud workload and endpoint security, threat intelligence, and cyberattack response services. The company's flagship offering is the Falcon platform, an AI-native, cloud-based platform designed to prevent breaches by consolidating cybersecurity measures. The Falcon platform utilizes a single, lightweight sensor to collect telemetry data, which is then analyzed by the CrowdStrike Security Cloud to deliver hyper-accurate detections, automated protection, and remediation. CrowdStrike has been involved in investigations of several high-profile cyberattacks and aims to address the limitations of traditional malware-based defenses with its advanced approach. The company emphasizes its AI-driven capabilities, partner-first go-to-market model, and international expansion.
21.0k+
9144Total headcount
1.1M+
20513Social media followers
+94
Rapid Expansion
+84
Surging
Merger & Acquisition
Acquisitions
CrowdStrike, a cybersecurity provider, is acquiring identity security startup SGNL for approximately $740 million. Announced January 8, 2026, with an expected close in Q1 2027, the acquisition aims to bolster CrowdStrike's Falcon platform against AI cyberattacks by enhancing identity access management and real-time risk capabilities. This strategic move strengthens CrowdStrike's market position in AI-driven cybersecurity. SGNL will be integrated to improve human and AI identity protection for customers. This is a pending acquisition.
CrowdStrike is set to acquire Pangea (AI security startup, GenAI guardrails) for an estimated $260 million, as reported by The Wall Street Journal. Announced during Fal.Con 2025, this strategic acquisition aims to expand CrowdStrike's AI security portfolio, enabling "AI detection and response" capabilities. The deal is currently pending, enhancing CrowdStrike's offerings for securing AI-powered applications and bolstering its competitive stance in the evolving cybersecurity landscape. Product integration is expected to focus on new AI security features.
CrowdStrike announced its intent to acquire Madrid-based telemetry startup Onum for $290M, expected around August 27, 2025. This strategic move aims to accelerate CrowdStrike’s Falcon Next-Gen SIEM development by integrating Onum's proprietary in-memory architecture. The acquisition will eliminate data integration bottlenecks and enable in-stream threat detection, strengthening CrowdStrike's AI-powered security portfolio and competitive stance. Onum will likely be integrated into CrowdStrike's offerings, enhancing product capabilities. The event status is MA_PENDING.
Acquired by
Est Employees
Historical growth data
Est Followers
Follower momentum
Momentum Analysis
Growth vs Heat index comparison
Unlock More Insights & Analysis
Gain access to historical headcount trends, social momentum, certifications, and proprietary growth analytics.
Understand how CrowdStrike products map to security capabilities vs frameworks.
CrowdStrike Falcon for Mobile
CrowdStrike
CrowdStrike Falcon for Mobile extends the unified CrowdStrike Falcon platform's endpoint detection and response (EDR) and extended detection and response (XDR) capabilities to iOS and Android devices. It provides comprehensive security against mobile-specific threats such as phishing attempts, mobile malware, network disruptions, and unauthorized access, including jailbreaking/rooting. The solution delivers real-time detection and prevention by analyzing telemetry from the device's file system, network stack, and applications. It integrates with existing Unified Endpoint Management (UEM) and Mobile Device Management (MDM) systems for streamlined deployment, supporting zero-touch enrollment. Falcon for Mobile incorporates Zero Trust Assessment (ZTA) for continuous evaluation of device security posture and integrates with Android Enterprise for enhanced trust signals, enabling dynamic conditional access policies. It also includes FalconID for phishing-resistant multi-factor authentication (MFA) and identity protection. Detections are mapped to the MITRE ATT&CK Matrices for Mobile, enabling proactive threat hunting and rapid incident investigation through a unified console alongside traditional endpoint data, leveraging CrowdStrike's AI-powered Security Cloud and Falcon Fusion for automated response. The solution prioritizes user privacy by focusing monitoring on corporate applications and maintains a lightweight design to minimize impact on device performance and battery life.
Falcon Adversary Intelligence Premium
CrowdStrike
CrowdStrike Falcon Adversary Intelligence Premium is a comprehensive threat intelligence solution designed to enhance an organization's security posture by providing in-depth insights into adversarial tactics and tradecraft. It integrates world-class research, including over 265 tracked adversaries and thousands of annual intelligence reports, directly into security operations. The product offers advanced capabilities such as personalized threat models, real-time Indicators of Compromise (IoCs), automated malware analysis, and proactive brand and fraud monitoring across the open, deep, and dark web. It leverages AI-powered workflows and pre-built detection libraries to streamline security engineering, reduce the need for extensive in-house threat research, and accelerate incident investigation and response. Falcon Adversary Intelligence Premium is a prerequisite for Falcon Counter Adversary Operations Elite, which provides dedicated human analyst support. It is delivered as a SaaS solution within the CrowdStrike Falcon platform.
Falcon Device Control
CrowdStrike
CrowdStrike Falcon Device Control is a module within the cloud-native CrowdStrike Falcon platform, designed to provide comprehensive visibility and granular control over the usage of removable media and peripheral devices across Windows and macOS endpoints. This includes USB drives, SD cards, Bluetooth, and Thunderbolt devices. The solution enables administrators to define and enforce policies to mitigate risks associated with malware introduction and data exfiltration. It automatically discovers connected devices, reporting details such as device types, manufacturers, and serial numbers, which are then presented through detailed usage dashboards. Policies can be configured for read/write or read-only access controls, and can block the execution of applications directly from removable media. Granular policy exceptions can be established based on device class, vendor, product, or serial number. When integrated with Falcon Insight XDR, the solution extends visibility by offering searchable historical logs of device usage, including files written to devices, and leverages machine learning to detect source code movement and identify over 40 programming languages for enhanced data loss prevention. Policies are centrally managed and apply consistently to both online and offline endpoints, all delivered via a single, lightweight agent architecture. This capability is crucial for safeguarding sensitive data and maintaining compliance by ensuring only approved devices are utilized within an organization's environment.
CrowdStrike Falcon Insight for Forensics and Response
CrowdStrike
CrowdStrike Falcon Insight for Forensics and Response is a module within the unified Falcon platform that provides comprehensive capabilities for forensic data collection, analysis, and incident response. It enables security teams to efficiently gather both point-in-time and historical forensic artifacts from endpoints across Windows, macOS, and Linux operating systems. Leveraging a lightweight, dissolvable executable and the CrowdStrike Security Cloud, the solution minimizes endpoint impact while facilitating rapid data acquisition. It integrates with the broader Falcon platform to enrich forensic data with threat intelligence and behavioral analytics, offering customizable dashboards and filters for in-depth investigation and compromise assessments. This module empowers incident responders to accelerate investigations, understand attack timelines, and effectively remediate cyber incidents by providing detailed visibility into adversary activity and system changes.
CrowdStrike Falcon Cloud Security
CrowdStrike
CrowdStrike Falcon Cloud Security is a unified, AI-native Cloud-Native Application Protection Platform (CNAPP) designed to secure multi-cloud and hybrid environments across the entire application lifecycle, from code development through runtime. It integrates both agent-based and agentless protection mechanisms, offering continuous visibility, robust posture management, and advanced threat detection and response for cloud workloads, containers, serverless functions, and AI models. The platform actively prevents misconfigurations, identifies and prioritizes vulnerabilities, and mitigates risks using AI-driven insights and extensive threat intelligence, including adversary-informed risk prioritization. Key capabilities encompass Cloud Security Posture Management (CSPM), Cloud Workload Protection Platform (CWPP), Container Security, Infrastructure as Code (IaC) scanning, and Data Security Posture Management (DSPM) for data at rest and in motion. It also provides real-time Cloud Detection and Response (CDR), AI Security Posture Management (AI-SPM) for securing AI applications and models, including LLMs, and enhanced identity protection within cloud environments. Falcon Cloud Security aims to stop cloud breaches by unifying security operations, enhancing compliance, and providing a single console for managing diverse cloud security challenges, leveraging a lightweight agent architecture for rapid deployment and performance, and offering full lifecycle protection for AI models.
CrowdStrike Falcon® Fusion SOAR
CrowdStrike
CrowdStrike Falcon® Fusion SOAR is a cloud-native Security Orchestration, Automation, and Response (SOAR) solution seamlessly integrated within the unified CrowdStrike Falcon platform. It empowers security operations teams to streamline workflows, automate repetitive tasks, and orchestrate incident response across the Falcon platform and various third-party security and IT tools. The platform leverages advanced AI and automation, including agentic workflows and deep integration with Charlotte AI, to enhance efficiency and accelerate threat investigation and remediation. Key capabilities include a no-code interface for rapid workflow deployment, pre-built playbooks, customizable actions, and a metrics dashboard for continuous improvement of security posture and reduction of Mean Time To Respond (MTTR). Falcon Fusion SOAR supports a wide range of use cases, from automating alert triage and enrichment to orchestrating containment actions and vulnerability patch management, thereby enabling security analysts to focus on high-impact threats and improve overall operational effectiveness and consistency.
CrowdStrike Falcon Adversary Intelligence
CrowdStrike
CrowdStrike Falcon Adversary Intelligence is a cloud-native threat intelligence solution that provides real-time, actionable insights into adversary methods and emerging threats. It integrates within the CrowdStrike Falcon platform and with third-party security tools, leveraging AI-powered workflows for automated threat intelligence orchestration and accelerated incident response. The platform offers comprehensive adversary profiles, dark web monitoring, and contextual indicators of compromise (IOCs) to proactively defend against cyberattacks. It significantly reduces the time required for threat research, malware analysis, and triage efforts, enabling faster detection, investigation, and response. Falcon Adversary Intelligence also includes proactive brand and fraud monitoring, identifying external threats such as domain impersonations and data leaks, and supports automated security workflows with prebuilt playbooks and APIs. It delivers personalized, real-time threat intelligence aligned to an organization's unique environment and risk profile, enhancing detection, investigation, and response capabilities. It is part of the broader Falcon Counter Adversary Operations portfolio, which also includes Falcon Adversary Intelligence Premium, Falcon Counter Adversary Operations Elite, and Falcon Adversary OverWatch.
CrowdStrike Falcon for XIoT
CrowdStrike
CrowdStrike Falcon for XIoT provides unified security for Extended Internet of Things (XIoT) assets, encompassing Operational Technology (OT), Industrial IoT (IIoT), and medical devices (IoMT). The solution delivers real-time visibility, AI-powered threat prevention, detection, and response capabilities across converged IT and OT environments. It leverages a lightweight, cloud-native architecture for zero-touch asset discovery and continuous monitoring, enabling organizations to identify and inventory industrial assets without disrupting critical operations. Falcon for XIoT integrates AI-powered analytics to prioritize vulnerabilities with contextual intelligence, offering tailored remediation guidance. The platform is designed to defend against advanced threats like malware and ransomware targeting industrial systems, ensuring business continuity by facilitating rapid response actions and reducing operational risks. It supports flexible deployment and is validated for interoperability with leading Industrial Control System (ICS) vendors like Rockwell Automation and Siemens. Recent innovations include enhanced zero-touch asset discovery, real-time segmentation visibility, and unified insight within a dynamic user experience, extending protection to healthcare environments and integrating with CrowdStrike Falcon® Next-Gen Identity Security and Falcon Complete Next-Gen MDR for unified oversight and expert protection.
Charlotte AI
CrowdStrike
CrowdStrike Charlotte AI is an advanced agentic and generative AI assistant integrated within the CrowdStrike Falcon platform, designed to enhance cybersecurity operations for users of all skill levels. It leverages a multi-model AI architecture, CrowdStrike's extensive security telemetry, and threat intelligence to provide real-time insights and automate complex security workflows. Charlotte AI acts as an AI-native security analyst, enabling teams to triage detections with high accuracy, accelerate investigations, and automate response actions through natural language interactions. Key capabilities include agentic workflows for autonomous reasoning and action, such as Detection Triage, Agentic Response, and Agentic Workflows, which streamline incident response, malware analysis, and exposure prioritization. The platform also features Charlotte AI AgentWorks, a no-code development environment for building custom security agents, and Charlotte Agentic SOAR for orchestrating human-AI collaboration and automated playbooks across the security ecosystem. It aims to reduce manual tasks, mitigate the cybersecurity skills gap, and enable faster, more precise threat detection and response with bounded autonomy and built-in guardrails for responsible AI adoption.
CrowdStrike Falcon Platform
CrowdStrike
The CrowdStrike Falcon Platform is a cloud-native, AI-powered cybersecurity solution delivered via a single, lightweight agent, designed to provide comprehensive protection across endpoints, cloud workloads, identity, and data. It unifies next-generation antivirus (NGAV) with AI-powered detection, endpoint detection and response (EDR), extended detection and response (XDR), managed threat hunting (Falcon OverWatch), and integrated threat intelligence. The platform offers continuous raw event capture for comprehensive visibility, enabling rapid investigation and remediation through intelligent prioritization and an Incident Workbench. It supports proactive threat hunting and leverages real-time threat intelligence for accelerated response against a wide spectrum of attacks, from common malware to sophisticated nation-state threats. Emphasizing an AI-native architecture, the Falcon platform provides advanced threat detection and prevention, including capabilities for AI agent discovery, shadow AI governance, and runtime threat detection. It is available in various tiers, such as Falcon Go, Falcon Pro, Falcon Enterprise, Falcon Premium, and Falcon Complete, offering scalable protection and performance without requiring constant signature updates or on-premises management infrastructure. The platform's architecture is built on the CrowdStrike Security Cloud, leveraging components like CrowdStrike Threat Graph, Asset Graph, Risk Graph, and Intel Graph for unified data analysis.
CrowdStrike Falcon Exposure Management
CrowdStrike
CrowdStrike Falcon Exposure Management is an AI-powered platform designed to proactively reduce cyber risk by providing real-time visibility and continuous assessment across the entire attack surface. It offers comprehensive asset discovery, encompassing managed, unmanaged, external, cloud, network, OT/IoT, and shadow AI assets, along with applications, accounts, and identities. The platform performs maintenance-free vulnerability assessments, including software CVEs, misconfigurations, end-of-support-life detection, and browser extension risks. Leveraging its patented ExPRT.AI model, threat intelligence, and adversary context, it prioritizes vulnerabilities based on exploitability likelihood, asset criticality, and real-world attack paths, enabling security teams to focus on the most critical risks. Falcon Exposure Management integrates natively with the broader CrowdStrike Falcon platform, utilizing a single, lightweight agent for deployment and facilitating consolidated visibility, attack path visualization, and automated remediation actions through Falcon Fusion SOAR. Recent enhancements include Network Vulnerability Assessment for network devices, AI Discovery for identifying AI components across environments, and expanded support for third-party environments, allowing organizations to gain exploitability-driven prioritization and continuous visibility without requiring CrowdStrike endpoint solutions. It supports compliance with industry standards like CIS Benchmarks and ingests third-party vulnerability data, aiming to unify exposure management and improve overall security posture.
Falcon Cloud Security
CrowdStrike
CrowdStrike Falcon Cloud Security is a unified cloud-native application protection platform that provides comprehensive security across multi-cloud and hybrid environments. It integrates application security posture management, data security posture management, and AI security posture management to deliver real-time visibility and risk-based prioritization. The platform aims to prevent misconfigurations, reduce alert fatigue, and enhance threat intelligence, enabling organizations to secure their cloud infrastructure and applications effectively.
Falcon Next-Gen SIEM
CrowdStrike
CrowdStrike Falcon Next-Gen SIEM is a cloud-native platform designed to enhance security operations by providing rapid data integration, real-time threat detection, and automated incident response. It consolidates data from various sources, enabling security teams to detect and respond to breaches with unprecedented speed and efficiency. The platform leverages AI to streamline investigations and automate workflows, significantly reducing the time and cost associated with traditional SIEM solutions.
Falcon Discover
CrowdStrike
CrowdStrike Falcon Discover is a module within the unified CrowdStrike Falcon platform that provides comprehensive IT hygiene and asset visibility across an organization's environment. It offers real-time inventory and continuous monitoring of managed and unmanaged assets, including endpoints, servers, cloud instances (like AWS EC2), applications, and user accounts. Leveraging the same lightweight agent architecture as the broader Falcon platform, Discover identifies unauthorized systems, applications, and activities, helping security operations teams maintain a defensible security posture. Key capabilities include tracking asset additions and removals, monitoring application usage for licensing and security, identifying unmanaged or unauthorized software, and gaining insights into user account activity, including privileged access and password changes. Falcon Discover extends visibility to cloud environments by integrating with cloud logs to enumerate existing deployments and monitor modifications. It provides dashboards and automated reporting to support audit and compliance requirements, offering crucial context for vulnerability management and incident response by integrating with other Falcon modules like Falcon Spotlight for vulnerability insights. The solution helps reduce the attack surface by providing granular visibility into the IT landscape, enabling proactive identification and remediation of potential security gaps. Recent enhancements include zero-touch discovery for XIoT assets (including IoT and OT environments), providing continuous operational insight without intrusive scans, and improved system insights for hardware attributes, resource usage, drive encryption status, and OS security settings.
CrowdStrike Falcon Complete Next-Gen MDR
CrowdStrike
CrowdStrike Falcon Complete Next-Gen MDR is a fully managed detection and response (MDR) service that integrates advanced cybersecurity technology with expert human oversight to proactively stop breaches across the entire attack surface. Built on the cloud-native CrowdStrike Falcon platform, it combines next-generation antivirus (Falcon Prevent), endpoint detection and response (Falcon Insight), and managed threat hunting (Falcon OverWatch) with 24/7 monitoring, investigation, and full-cycle remediation by CrowdStrike's elite security professionals. This comprehensive solution extends beyond traditional endpoints to include cloud workloads, identity, and third-party data sources via Falcon Next-Gen SIEM and XDR capabilities, providing unified cross-domain visibility. Falcon Complete aims to reduce cybersecurity risks and operational burdens by delivering agentic MDR, leveraging adaptive AI and automation alongside expert-led response, and is backed by a breach prevention warranty.
CrowdStrike Falcon Data Security
CrowdStrike
CrowdStrike Falcon Data Security is an AI-native data security solution integrated within the CrowdStrike Falcon platform, designed to prevent unauthorized data movement and mitigate insider threats across diverse environments. Leveraging a single, lightweight agent, it provides real-time visibility and control over sensitive data at rest and in motion across endpoints (Windows and macOS), cloud infrastructure, SaaS applications, and generative AI (GenAI) workflows. The platform employs a combination of content and context-aware analysis, including proprietary Similarity Detection DNA technology, to accurately identify and classify sensitive information, even when modified or repackaged. It enables organizations to define granular policies for data egress, detect encryption attempts on sensitive files, and block data leakage to managed and unmanaged GenAI tools. Falcon Data Security extends Data Security Posture Management (DSPM) into runtime for cloud environments, utilizing eBPF for real-time monitoring of data flows without requiring additional infrastructure. It offers a unified console for investigations, policy simulation, and dynamic risk scoring for insider threat detection, aiming to replace fragmented legacy Data Loss Prevention (DLP) solutions with a streamlined, integrated approach to data protection. It also includes AI-powered data classification tools and an Insider Threat Dashboard for correlated identity and data protection telemetry.
CrowdStrike Falcon® Next-Gen Identity Security
CrowdStrike
CrowdStrike Falcon® Next-Gen Identity Security is an AI-native, unified platform designed to protect all identity types—human, non-human, and AI agents—across the entire hybrid identity lifecycle. It integrates initial access prevention, modern privileged access management (PAM) with just-in-time access, identity threat detection and response (ITDR), and SaaS identity security into a single solution. Leveraging a lightweight sensor and the CrowdStrike Security Cloud, the platform provides continuous visibility into identity security gaps, automatically classifies accounts, and offers real-time threat detection powered by advanced machine learning and behavioral analytics. It extends protection to legacy and unmanaged systems, including Microsoft Active Directory and Entra ID, and supports various identity providers and SaaS applications. The solution enables dynamic, risk-based conditional access, phishing-resistant MFA (FalconID), and automated response actions to mitigate identity-based breaches, prevent lateral movement, and stop privilege escalation. This comprehensive approach unifies endpoint and identity security, aiming to eliminate fragmented security controls and provide end-to-end identity protection across endpoints, cloud, and SaaS environments. It also offers 24/7 managed identity protection through CrowdStrike Falcon® Complete and Falcon Adversary OverWatch®.
CrowdStrike Falcon Identity Protection
CrowdStrike
CrowdStrike Falcon Identity Protection is a comprehensive identity threat detection and response (ITDR) module within the CrowdStrike Falcon platform, designed to secure hybrid identity infrastructures. It provides unified visibility and control over user access across multi-directory environments, including on-premises Active Directory and cloud identity providers like Entra ID and Okta. Leveraging advanced AI and machine learning, the solution continuously analyzes live traffic against behavioral baselines to detect and prevent identity-based attacks, such as credential compromise, lateral movement, and privilege escalation, in real time. It offers hyper-accurate threat detection, reducing false positives and improving incident response by correlating events around user and device activities. Falcon Identity Protection also enables risk-based conditional access policies, dynamically enforcing multi-factor authentication (MFA) based on risk levels to ensure frictionless security for legitimate users while blocking anomalous activity. The platform extends protection to legacy and unmanaged systems, providing extensive MITRE ATT&CK® coverage and can secure the entire SaaS stack by detecting threats across over 150 SaaS applications. It integrates with the Falcon platform's single lightweight sensor, allowing for unified endpoint and identity security without requiring separate deployments for identity-specific agents on domain controllers. The latest evolution of this offering is often referred to as CrowdStrike Falcon Next-Gen Identity Security, which expands unified protection to human, non-human, and AI agent identities, integrating initial access prevention, modern privileged access management (PAM), ITDR, and SaaS identity security.
CrowdStrike Falcon Prevent
CrowdStrike
CrowdStrike Falcon Prevent is a cloud-native, AI-powered next-generation antivirus (NGAV) solution designed to deliver comprehensive endpoint protection against a broad spectrum of cyber threats, including known and unknown malware, ransomware, fileless attacks, exploits, and potentially unwanted programs (PUPs). Operating via a single, lightweight agent, it eliminates the need for constant signature updates and on-premises management infrastructure, simplifying deployment and reducing system impact. The solution leverages advanced machine learning, artificial intelligence (AI), behavioral analytics, and real-time threat intelligence to proactively identify and prevent malicious activities, even when endpoints are offline. It integrates AI-powered Indicators of Attack (IOAs) and script control to detect sophisticated behaviors and provides robust exploit blocking. Falcon Prevent is a core component of the broader CrowdStrike Falcon platform, offering high-fidelity detection with minimal false positives and comprehensive visibility into threats and incidents. Its architecture supports rapid, large-scale deployment without requiring reboots and is delivered as a software-as-a-service (SaaS) offering, ensuring continuous updates and protection across diverse operating systems including Windows, macOS, and Linux. It is recognized as a leading solution for replacing legacy antivirus products.
CrowdStrike Falcon Adversary Intelligence Premium
CrowdStrike
CrowdStrike Falcon Adversary Intelligence Premium is a cloud-native threat intelligence solution that provides security teams with in-depth insights into adversary tactics, techniques, and procedures (TTPs) to proactively defend against cyber threats. It delivers world-class research, real-time threat alerts, and detailed intelligence reports from CrowdStrike's global intelligence team, tracking over 281 adversaries including nation-state, eCrime, and hacktivist groups. The solution integrates threat intelligence directly into security operations workflows, enhancing detection engineering with pre-built hunting queries and detection rules, and accelerating incident response. Key capabilities include automated malware analysis, real-time global Indicators of Compromise (IOCs), and brand and fraud monitoring to identify external threats across the open, deep, and dark web. It also incorporates CrowdStrike Threat AI, an Agentic Threat Intelligence suite, to accelerate analyst workflows and improve security posture. Falcon Adversary Intelligence Premium is designed to augment or replace in-house threat research, reduce investigation times, and enable organizations to adapt security controls as adversary tactics evolve.
CrowdStrike Falcon Shield
CrowdStrike
CrowdStrike Falcon Shield is a SaaS security solution that provides comprehensive visibility and control over an organization's SaaS application environment. It integrates with over 180 applications, including Google Workspace, Microsoft 365, Salesforce, and ServiceNow, to continuously monitor for misconfigurations, identity risks, and threats. The platform offers real-time security checks, automated remediation, and proactive threat detection to identify and mitigate vulnerabilities across sanctioned and shadow applications. Falcon Shield secures human and non-human identities, detecting over-permissioned, high-risk, or dormant accounts, and enforces security policies to prevent unauthorized access and lateral movement. With over 3,500 built-in security checks, it helps organizations maintain compliance, reduce their SaaS attack surface, and protect sensitive data. Falcon Shield also provides visibility into AI agents across SaaS platforms, mapping their access and detecting risky behavior. It is an integral part of CrowdStrike's Falcon Next-Gen Identity Security, delivering unified, AI-native protection against identity-driven, cross-domain attacks.
Falcon FileVantage
CrowdStrike
CrowdStrike Falcon FileVantage is a cloud-native File Integrity Monitoring (FIM) solution integrated within the CrowdStrike Falcon platform, designed to provide real-time visibility and contextual intelligence into changes affecting critical files, folders, and registry settings across an organization's environment. Leveraging the Falcon platform's lightweight agent, it continuously monitors for modifications, creations, deletions, and access attempts on sensitive system, configuration, and content files. The solution enables security operations teams to define and apply granular policies, including predefined and custom rules, to focus monitoring efforts and reduce alert fatigue. By correlating file change data with CrowdStrike's extensive threat intelligence and detection capabilities, Falcon FileVantage enriches alerts with adversary activity context, allowing for rapid prioritization and response to potentially malicious changes. It offers comprehensive dashboards for both macro and micro views of file integrity, aiding in compliance adherence for various regulatory standards such as PCI DSS and HIPAA, and enhancing the overall security posture by enabling swift identification and remediation of unauthorized or suspicious alterations. The architecture is SaaS-based, ensuring scalability and ease of deployment.
CrowdStrike Falcon Adversary OverWatch Next-Gen SIEM
CrowdStrike
CrowdStrike Falcon Adversary OverWatch Next-Gen SIEM is a managed threat hunting service that extends proactive detection and disruption of sophisticated adversaries across an organization's entire attack surface, including third-party data sources. Leveraging the AI-native CrowdStrike Falcon platform, this service combines artificial intelligence with an elite team of human threat hunters to identify novel attacks, advanced persistent threats, and stealthy adversary tradecraft that often evades automated defenses. It provides 24/7 expert-led threat hunting across endpoints, identity, cloud environments, and now integrates with third-party data ingested by Falcon Next-Gen SIEM, such as network edge devices, identity and access management tools, SaaS applications, and email security tools. Key capabilities include advanced user and entity behavior analytics (UEBA) for insider threat detection, unified identity security, and integrated case management for accelerated response. This managed service significantly reduces the operational burden and costs associated with maintaining an in-house threat hunting team, ensuring robust defense against evolving digital threats by continuously hunting, investigating, and advising on threat activity across both first-party and third-party telemetry.
CrowdStrike Falcon® Insight XDR
CrowdStrike
CrowdStrike Falcon® Insight XDR is a cloud-native extended detection and response (XDR) solution built on the CrowdStrike Falcon platform, leveraging its single lightweight agent architecture. It unifies security telemetry from endpoints, cloud workloads, identity, and third-party sources to provide comprehensive visibility and accelerate threat detection, investigation, and response across the enterprise. The solution integrates Endpoint Detection and Response (EDR) capabilities with broader XDR functionality, correlating diverse security data through AI-powered analytics, machine learning, and CrowdStrike's proprietary Threat Graph® to identify sophisticated attack patterns and prioritize high-fidelity alerts. Key features include real-time threat hunting, incident workflows, AI-powered investigations with Charlotte AI™, and integration with Falcon Fusion SOAR for automated remediation. It aims to reduce mean time to detect and respond to threats by providing a unified command console for security operations, enhancing situational awareness, and streamlining collaboration among security analysts. Falcon Insight XDR supports both native CrowdStrike telemetry and ingestion of data from various third-party security tools, offering a flexible approach to XDR deployment and enabling cross-domain context to understand the full scope of an attack and automate response actions.
CrowdStrike Falcon Sandbox
CrowdStrike
CrowdStrike Falcon Sandbox is a cloud-native malware analysis solution designed to provide in-depth behavioral insights into evasive and unknown threats. It utilizes advanced sandboxing techniques to safely detonate suspicious files and URLs in an isolated virtual environment, observing their complete execution path and system interactions. The platform generates comprehensive reports detailing malicious activities, network communication patterns, exploited vulnerabilities, and persistence mechanisms. These reports are enriched with threat intelligence, delivering actionable indicators of compromise (IOCs) to security teams. Falcon Sandbox supports a wide range of file types, including executables, documents, and scripts, and offers both hosted and on-premises deployment options. It integrates with existing security ecosystems through extensive APIs and pre-built connectors, enhancing incident response workflows, threat hunting, and security control validation. The solution aids in understanding sophisticated malware attacks, prioritizing incidents, and proactively strengthening an organization's security posture by providing detailed context around threat behaviors. It is a module within the broader CrowdStrike Falcon platform, leveraging its resources and expertise for continuous feature enhancements and automated analysis.
Falcon for IT
CrowdStrike
CrowdStrike Falcon for IT is a module of the AI-native CrowdStrike Falcon platform, designed to unify IT and security operations for comprehensive endpoint management and infrastructure security across Windows, macOS, and Linux environments. It leverages AI-native capabilities, including CrowdStrike Charlotte AI, to provide real-time visibility and control over endpoints, servers, and cloud workloads. The solution facilitates natural language querying of the entire IT estate and supports a robust query language, enabling use cases such as fleet management, compliance enforcement, and forensic investigations. Key features include AI Discovery and Governance for identifying and managing AI technologies on endpoints, risk-based patching that prioritizes vulnerabilities based on adversary intelligence and generates Patch Safety Scores, and automated baseline enforcement to prevent configuration drift and maintain secure endpoint states. Falcon for IT consolidates disparate tools into a single, lightweight agent and console, empowering organizations to rapidly remediate issues, enforce security standards, and optimize IT operations by bridging the gap between security and IT teams. It also offers turnkey automations through content packs for various operational workflows, enhancing application resilience and device control, and supports secure boot certificate lifecycle management at scale.
CrowdStrike Falcon Firewall Management
CrowdStrike
CrowdStrike Falcon Firewall Management is a cloud-native module within the CrowdStrike Falcon platform, designed to centralize and simplify the management of host firewalls across Windows, macOS, and Linux operating systems. Leveraging a single, lightweight Falcon agent and a unified management console, it enables organizations to create, enforce, and maintain granular firewall rules and policies. The platform provides instant visibility into network activities, matched rules, potential threats, and anomalies, enhancing protection against network-based attacks. Key capabilities include flexible policy creation using templates, the ability to define reusable rule groups, and rapid propagation of changes. It streamlines operations by eliminating the complexity associated with native firewalls, offering an intuitive interface for monitoring and troubleshooting. Falcon Firewall Management supports compliance by allowing auditing of rule changes and consistent policy application across diverse environments, deploying rapidly without complex configurations or reboots. It integrates with other Falcon modules, providing a cohesive approach to endpoint security and threat response.
Falcon Counter Adversary Operations Elite
CrowdStrike
CrowdStrike's Falcon Counter Adversary Operations Elite provides organizations with access to dedicated analysts who specialize in adversarial intelligence and advanced threat hunting. This service focuses on identifying and disrupting sophisticated threats targeting the organization by leveraging extensive threat intelligence and real-time monitoring. The assigned analyst collaborates closely with the organization to tailor threat hunting strategies and provide proactive notifications about potential threats, enhancing the organization's overall cybersecurity posture.
Falcon Spotlight
CrowdStrike
CrowdStrike Falcon Spotlight is a cloud-native, scanless vulnerability management solution that provides real-time assessment and prioritization of security exposures across endpoints. Leveraging the single, lightweight agent of the CrowdStrike Falcon platform, it continuously identifies vulnerabilities in operating systems and applications without the need for traditional, resource-intensive scanning. This deep integration with the Falcon platform enables a unified approach to endpoint protection, threat detection, and incident response. Falcon Spotlight utilizes AI-powered Exploit Prediction Rating (ExPRT.AI) to dynamically prioritize vulnerabilities based on their exploit status and real-world threat intelligence, allowing security teams to focus on the most critical risks. It offers comprehensive visibility across physical, virtual, on-premise, off-network, and cloud environments, providing intuitive dashboards and detailed reports for enhanced security posture management. By streamlining vulnerability assessment and offering automated remediation guidance, Falcon Spotlight helps organizations reduce their attack surface, improve response times, and strengthen their overall cybersecurity posture with minimal operational impact.
CrowdStrike Falcon
CrowdStrike
CrowdStrike Falcon is an AI-native cybersecurity platform designed to protect organizations from breaches. It provides endpoint security, threat intelligence, and cyberattack response services. The platform unifies various security modules, including next-generation antivirus (NGAV), endpoint detection and response (EDR), threat intelligence, and managed threat hunting, all through a single lightweight agent and a cloud-native architecture. This approach aims to simplify deployment, reduce complexity, and offer scalable protection across endpoints, cloud workloads, identities, and data. Falcon leverages artificial intelligence (AI) and machine learning (ML) to detect and prevent both known and unknown threats, including malware, fileless attacks, and zero-day exploits. It offers capabilities such as real-time monitoring, behavioral analysis, automated remediation, and vulnerability management. The platform is targeted at businesses of all sizes seeking to bolster their security posture against sophisticated cyber threats and streamline their security operations. CrowdStrike Falcon can be deployed across Windows, macOS, and Linux operating systems, covering desktops, servers, and virtual machines.
