CrowdStrike
Also known as: Charlotte AI, Charlotte AI AgentWorks, CrowdStrike Falcon
CrowdStrike is a cybersecurity platform whose Charlotte AI delivers agentic detection, triage, and response in the SOC.
CrowdStrike is a public cybersecurity company, and Charlotte AI is how it brings agentic operations to the security operations center. Rather than a standalone product, Charlotte is an agentic analyst layer woven through the Falcon platform, built to automate the repetitive work of a SOC, triage, investigation, malware analysis, at machine speed while keeping human analysts in control. The pitch is urgency driven: CrowdStrike cites attacker breakout times as fast as twenty seven seconds and AI powered attacks rising nearly ninety percent year over year, arguing that human reaction time alone can no longer keep pace.
The agentic stack has three layers. The Agentic Security Workforce is a library of purpose built agents delivered natively through Falcon modules, fifteen of them named, that triage detections, drive investigations, analyze malware and build YARA rules, prioritize exposures, onboard data and generate workflows.
Charlotte AI AgentWorks, launched in March 2026, is a no code platform where a security team builds custom agents in plain language, defining mission, data, and authorized actions, on a model it chooses from OpenAI, Anthropic and NVIDIA, or its own.
And Charlotte Agentic SOAR is the orchestration layer that runs CrowdStrike native, custom, and third party agents as one coordinated workflow, with the autonomy of each workflow set anywhere from human approval to fully autonomous, and bidirectional MCP into and out of the Falcon platform.
Trust is the recurring theme. Charlotte AI is certified to ISO/IEC 42001 for AI governance, and CrowdStrike lists SOC 2 Type 2, ISO 27001 and FedRAMP High among its attestations. Prebuilt agents only recommend by default, every agent execution is logged, and developers reach the platform through a public API and SDKs. CrowdStrike reports a seventy percent cut in manual investigation work and triage accuracy above ninety eight percent against its own analysts' decisions; those are its own figures.
It does not document an evaluation harness for custom agents, or how long the shared context its agents learn from is kept. For an enterprise already running Falcon that wants agentic triage and response with governance built in, Charlotte AI extends the platform it already has; teams not on CrowdStrike, or wanting agents outside security operations, will find it built for the SOC rather than general use.
Vendor details
Canonical URL
https://crowdstrike.com
Category
Security / SOC agent
Subcategory
Charlotte AI agentic SOC
Funding status
CrowdStrike is a large public company listed on Nasdaq as CRWD, built on its cloud native Falcon platform and reporting more than four billion dollars in annual revenue. It has invested heavily in agentic security, launching Charlotte AI AgentWorks and Charlotte Agentic SOAR with an ecosystem of partners including AWS, Anthropic, NVIDIA, Accenture, and Deloitte.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Charlotte AI is delivered natively across the Falcon platform, including Next Gen SIEM and Fusion SOAR, spanning endpoint, identity, cloud, and data, and grounded in the CrowdStrike Enterprise Graph. Charlotte Agentic SOAR orchestrates CrowdStrike, custom, and trusted third party agents, with ecosystem integrations including IBM ATOM and frontier models from Anthropic, OpenAI, and NVIDIA.
In practice
Your SOC analysts drown in alert triage and investigation while attackers move in seconds. Charlotte AI's agents classify detections, drive investigations, and analyze malware at machine speed, reportedly cutting manual investigation work by seventy percent.
You want security agents tailored to your environment without hiring agent developers. Charlotte AI AgentWorks lets your team build, test, and deploy custom agents in plain language, powered by a choice of frontier models, under strict guardrails.
You need autonomous response you can still govern. Charlotte Agentic SOAR orchestrates native, custom, and third party agents with bounded autonomy, user authorized actions, and audit ready logs, so analysts set intent and stay in control.
Sources & related URLs
Research sources
Agentic Index coverage score
12.0 / 14 capabilities · 86%
| Integrations & Tool Calling | Full |
|---|---|
|
Charlotte agents take authorized actions through first party Falcon tools and built in connectors across identity, cloud, network, ITSM and collaboration tools, with bidirectional MCP to third party tools and agents. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/agentic-soarread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Charlotte Agentic SOAR runs CrowdStrike native, custom and third party agents as one coordinated workflow, with the buyer defining the triggers, data and handoffs of each workflow beside deterministic SOAR workflows in a no code workspace. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/agentic-soarread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
Agents reason over a shared context layer built from the customer's own Falcon data across endpoint, identity, cloud and network, and every answer traces back to the data behind it; the layer persists per organization and stays queryable. Its internals are not documented. Sourcecrowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-socread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Autonomy is set for every workflow, from human in the loop approval to fully autonomous execution, and prebuilt agents by default only generate information and recommendations, with any action affecting the environment requiring explicit configuration and approval. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/agentic-soarread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
Role based access controls scope what each agent can access and do, and responses respect the permissions the user already holds. SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023 and FedRAMP High are named on the compliance page. Sourcecrowdstrike.com/en-us/why-crowdstrike/crowdstrike-compliance-certificationread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every agent execution is recorded in a full audit log, and every agent action and workflow execution is logged and auditable, with answers traced back to their source data. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/charlotte-ai-agentworksread 2026-09-28 |
|
| Memory & State Persistence | Partial |
|
A shared context layer collects every decision, correction and resolution in a customer's environment, unique to that organization. No lifetime, retention or delete path for that store is documented. Sourcecrowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-socread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
Falcon tenants run in named clouds, us-1, us-2, us-3, eu-1, us-gov-1 and us-gov-2 in the developer documentation, with regional clouds for Saudi Arabia, India and the UAE announced in January 2026 as planned. Charlotte AI availability per region is not published, and self hosting is not offered. Sourcedeveloper.crowdstrike.com/falcon-sensor/ansible/roles/falcon-configureread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Fifteen named prebuilt agents across detection and response, threat intelligence and hunting, exposure management, Next-Gen SIEM and SOAR, among them Detection Triage, Malware Analysis (which builds YARA rules), Exposure Prioritization and Workflow Generation, each doing its own job. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/agentic-security-workforceread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
The Detection Triage Agent classifies new detections, an orchestrating agent calls investigation agents when detections warrant it, and Agentic SOAR workflows run on triggers the buyer defines, so work starts on the alert rather than on an analyst's prompt. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/agentic-security-workforceread 2026-09-28 |
|
| Model Flexibility & Routing | Full |
|
The buyer selects a model for each agent from OpenAI GPT, Anthropic Claude and NVIDIA Nemotron, on infrastructure including Amazon Bedrock, or brings its own. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/charlotte-ai-agentworksread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The developer portal publishes an API reference and SDKs in Python, PowerShell, Go, TypeScript, Rust and Ruby for the Falcon platform, plus Falcon MCP for AI assistants and Falcon Foundry for custom apps and workflows. Sourcedeveloper.crowdstrike.comread 2026-09-28 |
|
| Testing, Debugging & Optimization | Partial |
|
AgentWorks is described as letting teams build, test and deploy custom agents. No evaluation harness, scored test cases, quality gate or optimization loop is documented, and the triage accuracy above 98 percent against Falcon Complete analysts is CrowdStrike's own benchmark of its own agent, not a surface the buyer runs. Sourcecrowdstrike.com/en-us/platform/charlotte-ai/charlotte-ai-agentworksread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Charlotte agents act through Falcon tools, built in connectors and MCP; driving a browser, desktop or remote computer is not documented. Sourcecrowdstrike.com/en-us/platform/charlotte-airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
CrowdStrike expanded its Project QuiltWorks cyber risk framework to small and mid-sized businesses globally. Supported by a network of distributors including Pax8 and TD SYNNEX, the expansion provides smaller organizations with access to CrowdStrike's frontier AI risk protection capabilities.
Bears on: Security / enterprise
View sourceCrowdStrike extended its Falcon AI Detection and Response (AIDR) module to provide active protection for AI agents built in Microsoft Copilot Studio and Anthropic's Claude Code. The update safeguards against threats originating from third-party AI tool usage.
Bears on: Security / enterprise
View sourceCrowdStrike has formed a strategic partnership with Cerebras Systems to power its Falcon AI Detection and Response (AIDR) platform using Cerebras's high-speed AI inference technology. Under the reciprocal agreement, Cerebras will also standardize on the CrowdStrike Falcon platform to secure its own business operations.
Bears on: Security / enterprise
View sourcePricing
Not public; sold within the Falcon platform through enterprise sales, with agent usage metered by credits
Falcon platform subscription plus agent credit usage
What is public
Charlotte AI has no public rate. It is sold with the Falcon platform and modules through sales, with agent usage metered as AI credits; qualifying customers get 50 AI credits a month at no charge. The pricing page publishes per device prices for the Falcon Go, Pro and Enterprise endpoint bundles, which do not name Charlotte AI.
Billing mechanics
Charlotte AI rides on Falcon platform and module subscriptions, with agent activity metered by credits that administrators can control centrally. Cost combines the underlying Falcon licensing with agent consumption.
Cost watchouts
Charlotte AI depends on underlying Falcon platform and module licensing, and agent credits add usage cost. Confirm which modules are prerequisites and how credit consumption scales with SOC volume.
Variable cost rationale
Agent activity is metered by credits on top of Falcon platform and module subscriptions, so heavy agent and investigation volume adds consumption cost.
Additional watchouts
Because agent usage is credit metered on top of Falcon subscriptions, model both the platform module cost and expected agent and investigation volume; confirm which Falcon modules Charlotte AI requires.
Sales call required
Yes, required for paid access
Free / trial
Qualifying customers get 50 Charlotte AI credits a month at no charge; Falcon endpoint bundles carry a 15 day trial; no public Charlotte AI rate
Key ambiguities
There is no public rate; pricing depends on Falcon platform and module subscriptions plus agent credit consumption, all quoted through sales.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to CrowdStrike
The closest documented capability profiles to CrowdStrike among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Tines11.5 / 14A lighter documented profile than CrowdStrike
- Torq12.5 / 14Fuller documented coverage on Testing, Debugging & Optimization
- ContraForce11.0 / 14A lighter documented profile than CrowdStrike
- Dropzone AI11.0 / 14A lighter documented profile than CrowdStrikeCrowdStrike vs Dropzone AI →
- BlinkOps10.5 / 14A lighter documented profile than CrowdStrike
- D3 Security (Morpheus)10.5 / 14A lighter documented profile than CrowdStrike
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded