CrowdStrike Delivers the Next Evolution of the Agentic SOC

The agentic SOC provides a foundation that agents can reason over, teams of expert agents that learn each environment, and one workspace to build and govern it all, delivered on the Falcon platform.

September 02, 2026

Agentic SOC

The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to the CrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real time.

CrowdStrike is delivering new innovations with the next evolution of the agentic SOC, in which analysts and AI agents work together in a unified system.

In the legacy SOC, evidence lives in disconnected systems. Automation is split across separate interfaces and execution logs. Analysts toggle between tools and manually stitch together context. Only a subset of detections receives real investigation while everything else piles up as a structural blind spot.

But most security teams struggle to achieve an agentic SOC transformation, for three key reasons. First, fragmented data prevents cross-domain investigations. When context lives in separate tools and isn't AI-ready, agents can't connect the dots across identity, cloud, endpoint, SaaS, and network. Second, isolated agents reach incorrect or late verdicts. Because they work in silos with sequential handoffs, they see only a partial picture, which reverts the work back to analysts. Third, ungoverned automation creates breach points. Agents act in your environment and connect to your systems; if you can't build, monitor, and control them, you can't see what's running, what it's connected to, or what it costs.

CrowdStrike takes a different path. The CrowdStrike Falcon® platform is not just where agents run. It is where the data is generated, enriched, investigated, orchestrated, and governed.

New at Fal.Con 2026: The Evolution of the Agentic SOC

At Fal.Con, CrowdStrike is delivering the next evolution of the agentic SOC, a production operating model where expert agents and analysts stop breaches as one system. New capabilities in the Falcon platform include:

  • A more unified foundation: Third-party data now arrives detection-ready through certified pipelines, with detection logic running inside the pipeline before data reaches its destination. This accelerates both time-to-value and mean time to detect (MTTD).
  • Coordinated teams of specialist agents: For actions ranging from cross-domain investigations to proactive reconnaissance, teams can deploy fleets of battle-tested agents built by CrowdStrike experts and coordinated by an orchestrator agent, all of which work out of the box. 
  • A unified agentic SOAR workspace. Charlotte AI AgentWorks, SOAR orchestration, and CrowdStrike Falcon® Foundry converge in one place to build and govern rule-based and agentic automation alike, with expanded flexibility for how security teams can build agents and connect them to their security stack via MCP. 

See it in action: Coordinated expert agents investigate every domain at once and converge on a single verdict

Let’s take a closer look at what’s new.

Certified Data, Ready for Agents 

The Falcon platform starts from native telemetry and extends outward, delivering petabytes of cross-domain data refined by elite security experts in one unified foundation. Teams decide what is ingested and what is federated, and critical first-party data has no ingestion cost. The result is agents with a complete view of their environment that is AI-ready from the start. 

Third-party data traditionally depends on pipelines customers build and maintain themselves, with no guarantee that data lands complete or usable. A single dropped field or schema change can break a detection without anyone noticing. In an agentic SOC, where agents act on data automatically, that risk compounds.

CrowdStrike is closing this gap with new capabilities that optimize how third-party data gets in, what happens to it in flight, and whether teams can trust it when it lands. These include:

  • Certified data pipelines (Public Preview). Teams will get pre-built, pre-tested data flows that CrowdStrike validates and maintains, starting with Zscaler and Palo Alto Networks. Sources go live in hours and arrive detection-ready, so coverage starts when a new source is connected. There is no pipeline overhead to carry, and only security-relevant data reaches the platform.

Figure 1. Certified pipelines connect third-party data sources, detection-ready on arrival Figure 1. Certified pipelines connect third-party data sources, detection-ready on arrival
  • Detection in the pipeline (Public Preview). Detection normally waits until data is ingested and normalized. With this new capability, detection logic will run inside the pipeline itself. Because pipelines can execute at the edge, threats are caught in transit, which reduces MTTD.

Coordinated Expert Agents That Know Your Environment

Agents need intelligent coordination that summons the right expertise at the right time. CrowdStrike now delivers out-of-the-box multi-agent workflows that coordinate teams of expert agents to accomplish tasks. These agents reason over shared context unique to each organization and sharpen their accuracy over time. These coordinated workflows span critical security operations, from investigations to digital risk protection.

New capabilities include:

  • Agentic investigations with shared context (Public Preview). When detections warrant an investigation, an orchestrator agent summons specialist agents, built and used every day by CrowdStrike Falcon® Complete managed detection and response. These agents work across every associated domain and data source in parallel. They build on each other's findings through shared context and converge on a single verdict. From there, they drive the next step: clearing queues, or escalating with pre-assembled context for human review. Coverage no longer depends on who is available.

Figure 2. Agentic investigation view showing specialist agents and converged verdict Figure 2. Agentic investigation view showing specialist agents and converged verdict
  • Agentic Recon (Public Preview). As frontier AI accelerates how quickly adversaries can identify exposed credentials, leaked data, impersonation, and other paths into the enterprise, coordinated intelligence agents continuously investigate threats across the open, deep, and dark web. They turn natural language questions into targeted queries, assess related findings and impact, and recommend actions for mitigation and response. Security teams can move from manual triage to continuously uncovering and acting on exposures before adversaries can use them to gain access.

Watch the demo:

CrowdStrike's agents are shaped by two loops that compound over time. The first loop is global. Our agents are informed by millions of real detections from around the world and get sharper with every incident the Falcon Complete team stops.

Complementing that is a second, local loop. The same shared context layer that agents reason over during an investigation is where their learning accumulates. Every decision, correction, and resolution in a customer's environment is collected there, unique to that organization and accessible to all of their CrowdStrike agents. This improves agents’ accuracy over time.

With access to global expertise defeating adversaries anywhere, and local knowledge to operate fluently in a specific environment, CrowdStrike's agents continually improve accuracy and earn the trust to run at scale.

One Workspace to Build and Govern Automation

Building agents is one thing; operating them at scale is another. Charlotte Agentic SOAR now lets teams build and govern automation, both rule-based and agentic, in a single place with expanded flexibility. 

New capabilities include: 

  • Unified agentic SOAR workspace (Public Preview): A new interface to build and govern automation enables teams to build with Charlotte AI AgentWorks, SOAR orchestration, and Falcon Foundry in a single UI. For each workflow, teams can define the triggers, data, conditions, agents, and actions. They can set what is fully automated or requires approval, and connect to the tools of their choice.
  • Bring your own model (GA): Teams can use their existing OpenAI and Anthropic licenses to match the right AI model to each job. This allows them to optimize for reasoning complexity, latency, or cost, resulting in a more flexible and economical way to build, test, and run agents.
  • Connect to any tool, any agent (GA): Third-party agents can now connect into Falcon tools through a CrowdStrike-managed MCP server, while Charlotte AI AgentWorks agents can reach out to the tools and data that security teams already run. The existing stack automatically becomes part of the agentic SOC. Agents reach the data they need wherever it lives and act through the tools teams already use; no overhaul required.
  • Hybrid Analysis, reengineered (Public): As CrowdStrike’s community malware analysis tool, Hybrid Analysis helps security teams analyze suspicious files and connect findings to threat intelligence. Now reengineered with API-first access, it can plug directly into AI agent workflows, via an open-source MCP server, extending them with CrowdStrike malware analysis and intelligence.
Figure 3. Unified Charlotte Agentic SOAR workspace Figure 3. Unified Charlotte Agentic SOAR workspace

The Agentic SOC: Only Possible on a Unified Platform

The agentic SOC is the operating model that connects the data, detection, investigation, orchestration, and response capabilities already deployed across the Falcon platform. Agentic investigations, delivered through CrowdStrike Falcon® Next-Gen SIEM and powered by Charlotte AI, run on existing Falcon telemetry with no new sensors required. They draw on signals from CrowdStrike Falcon® Next-Gen Identity Security and CrowdStrike Falcon® Cloud Security alongside endpoint data.

Each layer makes the next stronger. Better data produces faster, more accurate investigations, which in turn permit more informed workflow decisions. Governed workflows turn intelligence into accountable action.

The value of AI in security is enabling every investigation to begin with the right data, reason across the full attack, and produce an outcome defenders can trust. Only CrowdStrike brings together native and third-party data, agents built by the experts who stop breaches every day, a context layer that learns each environment, and governed orchestration in one platform. The agentic SOC from CrowdStrike is the operating model modern security demands.

Additional Resources

  • Want to learn more about how CrowdStrike delivers the agentic SOC? Visit the Agentic SOC Transformation solution page.
  • Want to learn more about Falcon Next-Gen SIEM? Visit the Falcon Next-Gen SIEM product page.
  • Establish real-time telemetry control to streamline onboarding and route high-fidelity data across SIEM, AI, storage, and analytics with Falcon Onum.

Forward-Looking Statements 

This blog may include discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.

 


CrowdStrike Falcon Platform
Ready to protect your business?

Try CrowdStrike free today

Subscribe

Sign up now to receive the latest notifications and updates from CrowdStrike

See CrowdStrike Falcon in action