Our website uses cookies to enhance your browsing experience.


Falcon OverWatch: Proactive Managed Threat Hunting

Falcon OverWatchTM is a human threat detection engine that operates as an extension of your team, hunting relentlessly to see and stop the most sophisticated hidden threats
Download Data Sheet


Why Choose Falcon OverWatch

  • See and Stop Hidden Advanced Attacks

    See and Stop Hidden Advanced Attacks

    The OverWatch team hunts relentlessly to see and stop the most stealthy sophisticated threats: the 1% of 1% of threats that blend in silently and lead to a breach if they remain undetected.

  • Maximum Effectiveness and Efficiency

    Maximum Effectiveness and Efficiency

    OverWatch delivers the best results by augmenting skilled analysts with the most advanced technology. Our elite human experts use cloud-scale data, custom tools, and up-to-the-minute threat intelligence to hunt with unprecedented speed and scale.

  • Seamless Extension of Your Team

    Seamless Extension of Your Team

    As a core component of the Falcon platform, OverWatch delivers results for organizations of all sizes, operating as a seamless extension of your team — minimizing overhead, complexity and cost.

Technical Features

People, Process, and Technology are All Key to Stopping Breaches

24 x 7 Human Expertise

24 x 7 Human Expertise

  • Attacker mentality. Effective threat hunting requires the ability and expertise to think like an attacker.
  • Cross-disciplinary expertise. OverWatch employs elite experts from a wide range of backgrounds, including government, law enforcement, commercial enterprise, the intelligence community and defense.
  • 24/7/365 availability. When a sophisticated intrusion occurs, time is critical. Your adversaries do not sleep and are not restricted by time zones or geography — neither should your threat hunting team.
  • Continuous vigilance. OverWatch’s continuous, proactive operations deliver results every minute of every day.
  • Finely-tuned response. OverWatch identifies and responds to hundreds of potential breaches per week. Each threat handled helps the team fine-tune their skills and processes, ensuring they are always sharp and effective.

Insights from the 2019 OverWatch Mid-year Report

Cloud-scale Security Telemetry

Cloud-scale Security Telemetry

  • Tools for the hunt. Threat hunting requires more than just expert hunters — those hunters need the right tools. Scalable and effective threat hunting requires access to vast amounts of data, and the ability to mine that data in real time for signs of intrusions.
  • Real-time visibility. OverWatch takes advantage of the cloud-scale telemetry of the proprietary CrowdStrike Threat Graph® to get broad, deep visibility, delivered in real time.
  • Massive data. Threat Graph ingests trillions of events each week, giving Falcon OverWatch an extensive, global real-time view of threat activity, as it happens.

Learn More about CrowdStrike Threat Graph

Up-to-the-minute Threat Intelligence

Up-to-the-minute Threat Intelligence

  • Threat context. You can’t detect a threat you don’t understand.
  • CrowdStrike Threat Intelligence. This intel empowers OverWatch with detailed, always-current knowledge of tradecraft from more than 120 adversaries.
  • Current TTPs. This intimate knowledge of the latest TTPs (tactics, techniques, and procedures) in use today ensures that OverWatch is able to hunt effectively and efficiently.

Learn More about CrowdStrike Threat Intelligence

Seamless Part of the Falcon Platform

Seamless Part of the Falcon Platform

  • One team, one fight. OverWatch operates as an extension of the Falcon platform and your team, delivering timely threat information via the single cloud-native console.
  • Alerts augmented with context. OverWatch analysts deliver alerts that are augmented with contextual details and global insights to help organizations understand threats and act faster.

Explore the Falcon Platform

Technical Center

For technical information on Falcon OverWatch, please visit the CrowdStrike Tech Center.

  • Technical Center
  • Technical Center
  • Technical Center
How Falcon OverWatch Proactively Hunts
for Threats in Your Environment

Product Validation

Customers Trust CrowdStrike

Third-Party Validation

Since 2016, CrowdStrike has demonstrated a strong commitment to continuous industry collaboration, scrutiny, and testing. Time and time again, CrowdStrike has been independently certified to replace legacy solutions.

  • Forrester Total Economic Impact

    Falcon OverWatch helps organizations reduce risks and improve efficiencies, resulting in 316% ROI.

    Read the Report

  • SANS Review of OverWatch

    SANS experts review how Falcon OverWatch responds in real time to sophisticated threats including credential theft, lateral movement and defense evasion.

    Read the Report

Visit our third-party evaluations page to see how CrowdStrike performed against the industry’s most rigorous tests and trials.

Falcon OverWatch Offerings

Choose the one that meets your requirements:

  • OverWatch Standard

    OverWatch Standard

    See and stop hidden advanced attacks and reduce dwell time with 24 x 7 proactive human threat hunting.

    See Below

  • OverWatch Premium

    OverWatch Premium

    Falcon OverWatch Premium expands the basic OverWatch offering by adding direct access to OverWatch threat analysts to consult on root causes, assist with analysis, perform weekly health checks, and provide proactive configuration recommendations and customized quarterly briefings.

    Learn More

OverWatch StandardOverWatch Premium
Cross-disciplinary human experts tooltip checkcheck
Continuous vigilance tooltip checkcheck
Cloud-scale telemetry tooltip checkcheck
Intelligence-driven tooltip checkcheck
Seamless integration with the Falcon platform tooltip checkcheck
Alerts augmented with context tooltip checkcheck
Email notifications tooltip checkcheck
OverWatch onboarding tooltip check
Proactive recommendations and tuning tooltip check
Access to OverWatch threat response analyst tooltip check
Detailed response recommendations tooltip check
Preventative health checks and security recommendations tooltip check
Phone notifications for critical alerts tooltip check

Get Answers to Commonly Asked Questions

Falcon OverWatch FAQ

Purchase Falcon OverWatch as a Part of a Bundle

CrowdStrike Falcon bundles are specifically tailored to meet a wide range of endpoint security needs.

Explore the Bundles