Agentic is the name of the game for CrowdStrike's Falcon Platform Fall Release

CrowdStrike has unveiled the Fall release of the CrowdStrike Falcon platform – the Agentic Security Platform. Built AI-native from day-one and revolutionised for the agentic era, the Falcon platform is the foundation powering the agentic security operations centres (SOCs), the company said.

This release features an AI-ready data layer and expands agentic capabilities across the platform – unifying data, intelligence, agents, and governance to secure and operationalise AI securely, intelligently, and at scale.

“The world is entering an arms race for AI superiority as adversaries weaponise AI to accelerate attacks,” said George Kurtz, CEO and founder of CrowdStrike.

“In the AI era, security comes down to three things: the quality of your data, the speed of your response, and the precision of your enforcement.”

With the Agentic Security Platform, CrowdStrike introduces what modern security requires: an AI-ready data layer, mission-ready agents, secure orchestration, and a dynamic AI-powered user experience. The following pillars define the Agentic Security Platform:

Enterprise Graph

Data is the lifeblood of AI, and the new Enterprise Graph is an AI-ready data layer and the foundation of the Agentic Security Platform. Enterprise Graph unifies CrowdStrike’s graph technology with telemetry from across the enterprise to build a living, connected model of the enterprise – with one common query language built for AI. This makes every signal instantly actionable by both agents and analysts. Supercharged by the addition of Onum’s real-time streaming technology and enriched with millions of expert analyst decisions from Falcon Complete Next-Gen MDR, Enterprise Graph will provide a strong data foundation for the AI era, CrowdStrike said.

Charlotte AI AgentWorks

Charlotte AI AgentWorks is a no-code platform giving every team the ability to build, test, deploy, and orchestrate trusted security agents. Using natural language, defenders set the mission, define the data, and control the behaviour of their agents, without writing a single line of code.

Every agent inherits Falcon’s telemetry, intelligence, and governance, ensuring automation is precise, explainable, and secure.

Operating centre of the ecosystem

Leveraging the popular Model Context Protocol (MCP), the Falcon platform acts as the operating centre of the agentic ecosystem, securely connecting Charlotte AI and any agent – CrowdStrike-delivered, customer-built, and trusted third-party agents – into a single, coordinated defence powered by Enterprise Graph. Falcon-grade governance is enforced via MCP across every connection, ensuring that multi-agent collaboration happens safely and at scale across IT and security environments.

Dynamic user experience

The new persona-aware console delivers natural language querying and customisation, role-specific workspaces, and instant dashboards that let defenders see, visualise, and act across domains with a single click. This eliminates silos and transforms complexity into clarity, enabling decisions at the speed of AI.

CrowdStrike is expanding agentic capabilities in two ways: mission-ready agents available in Falcon modules, and Charlotte AI AgentWorks. Together, these innovations deliver machine-speed capabilities to automate repetitive tasks, accelerate outcomes, and empower analysts to focus on the strategic decisions that strengthen security. As part of this launch, CrowdStrike also introduced the Agentic Security Workforce – mission-ready agents built on the Falcon platform to deliver machine-speed capabilities that automate repetitive tasks and accelerate outcomes.

CrowdStrike’s first fleet of agents – powered by Charlotte AI – are designed to handle critical security workflows and automate repetitive tasks, freeing analysts to focus on higher-value work and accelerating outcomes. Informed by millions of real-world decisions from Falcon Complete Next-Gen MDR, these agents scale expertise and accelerate investigations:

- Exposure Prioritization Agent (Falcon Exposure Management): Automates vulnerability triage, shrinking backlogs and focusing remediation on exploitable risks.

- Malware Analysis Agent (Falcon Threat Intelligence): Analyses files, maps malware families, and generates YARA rules – enabling defense at the family level instead of file-by-file.

- Hunt Agent (Falcon Threat Intelligence): Automates proactive threat hunting, continuously scanning for emerging threats.

- Search Analysis Agent (Falcon Next-Gen SIEM): Summarises and interprets query results in seconds, reducing hours of manual analysis.

- Correlation Rule Generation Agent (Falcon Next-Gen SIEM): Recommends and tunes detection rules for advanced threats and insider risks.

- Data Transformation Agent (Falcon Next-Gen SIEM): Normalises and translates data across tools, removing errors that stall automation.

- Workflow Generation Agent (Falcon Next-Gen SIEM): Converts natural language into automated workflows in Falcon Fusion, no coding required.

*MDR stands for managed detection and response, SIEM for security information and event management, and YARA for yet another recursive acronym. YARA is a tool for malware research.

Comments

Popular posts from this blog

Fortinet enhances FortiRecon to align with CTEM framework

SentinelOne recognised as a 2025 Gartner Peer Insights Customers’ Choice for XDR

AWS: AI adoption grows 20% in Singapore