SoftwareLore

Software profile Cybersecurity

CrowdStrike Falcon

Cloud-native cybersecurity platform built on a single lightweight agent

CrowdStrike Falcon is CrowdStrike’s cloud-based cybersecurity platform. First offered in 2013, it uses one lightweight sensor to protect endpoints, cloud workloads and identities, with AI-assisted detection, response and managed services.

Made by 18 2011 CrowdStrike Security & Infrastructure CrowdStrike Founded 2011 · Austin, Texas, United States Company profile

CrowdStrike Falcon at a glance

Developer
CrowdStrike
First released
2013Cloud-based endpoint detection and response first offered in June 2013
Pricing model
Subscription
Platforms
Windows, macOS, Linux, Cloud, Web
Deployment
Cloud (SaaS), Endpoint agent
License
Proprietary

What is CrowdStrike Falcon?

CrowdStrike Falcon is a cybersecurity platform delivered from the cloud. Organizations install a single lightweight sensor on laptops, desktops, servers and cloud workloads running Windows, macOS or Linux. The sensor blocks threats locally and streams security telemetry to CrowdStrike’s cloud, where the company correlates trillions of events a week with threat intelligence to detect attacks. New capabilities are switched on as subscription modules rather than installed as additional agents, and the sensor keeps protecting a device even when it is offline.

Falcon began with endpoint detection and response and a machine learning-based antivirus product and has grown to 33 modules. They cover cloud workload and container security, identity protection, exposure and vulnerability management, a cloud SIEM for log data, data loss prevention, SaaS security, IT automation and protection for organizations’ own AI applications and agents. Charlotte AI, an agentic AI assistant, triages detections and automates investigation steps within limits set by each customer, and Falcon Complete provides round-the-clock managed detection and response run by CrowdStrike analysts.

Falcon was also the software behind the outage of July 19, 2024, when a faulty content configuration update for the Windows sensor crashed an estimated 8.5 million computers and disrupted airlines, hospitals, banks and broadcasters. CrowdStrike withdrew the update within 78 minutes, apologized and changed how it tests and releases such updates, including giving customers more control over when they receive them. The platform has continued to grow since, and CrowdStrike reported $5.84 billion in annual recurring revenue in July 2026.

Key features of CrowdStrike Falcon

  1. 01

    Single lightweight sensor

    One agent on each Windows, macOS or Linux system collects telemetry and enforces protection, so customers can add modules without deploying more software, and the sensor needs no reboots to install.

  2. 02

    Endpoint detection and response

    Falcon Insight records process, file and network activity so analysts can detect intrusions, reconstruct attack timelines and isolate compromised machines from the network remotely.

  3. 03

    Antivirus and prevention

    Machine learning and behavioral indicators of attack block malware, ransomware and fileless attacks, and protection continues when a device is disconnected from the internet.

  4. 04

    Threat Graph and intelligence

    CrowdStrike’s cloud correlates trillions of security events a week with intelligence on named adversary groups, giving detections context about which attackers and techniques are likely involved.

  5. 05

    Identity and cloud security

    Modules detect identity-based attacks, such as lateral movement with stolen credentials, and protect cloud workloads, containers and cloud configurations across multiple providers.

  6. 06

    Next-Gen SIEM

    A log management and SIEM service ingests data from CrowdStrike and third-party sources for AI-driven detection, investigation, case management and automated response.

  7. 07

    Charlotte AI

    An agentic AI analyst triages alerts, answers questions in natural language and carries out investigation steps within guardrails defined by each customer’s security team.

  8. 08

    Falcon Complete managed service

    CrowdStrike analysts monitor, investigate and remediate threats around the clock for organizations that want fully managed detection and response rather than running it themselves.

Who uses CrowdStrike Falcon?

  • Large enterprises replace legacy antivirus and separate point products with one agent that handles prevention, detection and response across tens of thousands of devices.
  • Security operations centers use Falcon’s SIEM, threat intelligence and Charlotte AI to triage alerts and investigate incidents faster.
  • Organizations without large security teams rely on Falcon Complete for continuous monitoring and remediation by CrowdStrike analysts.
  • Small businesses buy packaged Falcon Go, Pro or Enterprise bundles online to protect a limited number of devices.
  • Companies adopting generative AI use Falcon’s AI detection and response module to monitor how employees and AI agents use models and to block prompt injection.

History of CrowdStrike Falcon

CrowdStrike spent its first two years mainly selling threat intelligence and incident response services while it built Falcon. In June 2013 it began offering cloud-based endpoint detection and response, and in 2017 it launched Falcon Prevent, its antivirus product, and started selling capabilities as separate cloud modules. The company also became known for investigating high-profile breaches, including the 2014 attack on Sony Pictures and the 2016 hack of the Democratic National Committee.

Acquisitions widened the platform: Preempt Security added identity protection in 2020, Humio brought log management in 2021, and later purchases added cloud, SaaS, data pipeline, AI and browser security. After the July 2024 outage, CrowdStrike faced lawsuits, including one by Delta Air Lines that was still in discovery in 2026, and changed its update process. It has since expanded the Falcon Flex licensing model and added agentic AI capabilities through Charlotte AI.

  1. 2013

    CrowdStrike begins offering cloud-based endpoint detection and response, the start of the Falcon platform.

  2. 2017

    The Falcon Prevent antivirus product launches, and capabilities are sold as separate cloud modules.

  3. 2021

    The Humio acquisition adds log management, the foundation for Falcon’s later SIEM offering.

  4. 2023

    CrowdStrike introduces Charlotte AI, a generative AI assistant for security analysts.

  5. 2024

    A faulty content update for the Falcon Windows sensor crashes an estimated 8.5 million computers on July 19.

  6. 2026

    The SGNL and Seraphic acquisitions add continuous identity and browser security to the platform.

CrowdStrike Falcon pricing

Pricing modelSubscription

Small-business bundles are priced per device with monthly or annual billing; enterprises buy modules or Falcon Flex commitments. A 15-day free trial is available.

CrowdStrike Falcon alternatives

Well-known alternativesMicrosoft Defender for Endpoint, SentinelOne Singularity, Palo Alto Networks Cortex XDR, Sophos Intercept X and Trend Vision One

CrowdStrike Falcon: frequently asked questions

Who makes CrowdStrike Falcon?

CrowdStrike Falcon is made by CrowdStrike Holdings, the cybersecurity company based in Austin, Texas, that George Kurtz, Dmitri Alperovitch and Gregg Marston founded in 2011. Kurtz remains CEO, and Falcon is the company’s core product, sold as a subscription platform with dozens of modules.

What is CrowdStrike Falcon used for?

CrowdStrike Falcon is used to protect computers, servers, cloud workloads and user identities from cyberattacks. Security teams use it for antivirus protection, endpoint detection and response, threat hunting, log management, vulnerability management and managed detection and response.

Is CrowdStrike Falcon free?

No. Falcon is a paid subscription service. Small businesses can buy bundles priced per device with monthly or annual billing, and larger organizations buy individual modules or Falcon Flex agreements. CrowdStrike offers a 15-day free trial that includes its Falcon Prevent antivirus and device control.

When was CrowdStrike Falcon released?

CrowdStrike began offering Falcon’s cloud-based endpoint detection and response in June 2013, two years after the company was founded. It added the Falcon Prevent antivirus product in 2017 and has since expanded the platform to more than 30 modules.

Did CrowdStrike Falcon cause the July 2024 outage?

Yes. On July 19, 2024, a faulty content configuration update for the Falcon sensor on Windows caused an estimated 8.5 million computers to crash. CrowdStrike said the problem was not a cyberattack, withdrew the update 78 minutes after its release and later changed its update procedures.

Sources

  1. CrowdStrike Falcon platform crowdstrike.com
  2. CrowdStrike pricing crowdstrike.com
  3. CrowdStrike Holdings annual report on Form 10-K, fiscal 2026 sec.gov
  4. CrowdStrike Form 8-K on the July 19, 2024 event sec.gov
  5. 2024 CrowdStrike-related IT outages, Wikipedia en.wikipedia.org

Last reviewed . Spotted an error? Send a correction.

to move · Enter to open · Esc to close