Live from Fal.Con: Watch keynotes live each day, and register for Fal.Con Digital for the full experience. Learn more
CrowdStrike® Charlotte AI™

Agentic AI for the modern SOC

Charlotte AI reasons, decides, and acts at machine speed, coordinating agents across domains, powered by world-class expertise.

New from Fal.Con 2026

AI-accelerated adversaries are exploiting the gaps in legacy defenses

Context Gap

Adversaries hit multiple domains, all at once. Fragmented tools don’t provide the unified, cross-domain context analysts need to investigate.
Labor Gap

Alert volume is multiplying. AI agents trigger 2.5x more detection leads than humans.1 Hiring more analysts can't close a gap that scales this fast.
Speed Gap

Attacks unfold in seconds. The fastest eCrime breakout time in 2025 was 27 seconds.2 Manual investigations still take minutes, or hours.

Close the gaps with Charlotte AI


Charlotte AI assembles unified cross-domain context, coordinates multi-agent investigations, and orchestrates governed response actions, always under your control.

Visual representing  answer, orchestrate, automate

See the full picture, instantly

Get instant clarity in plain language. Cross-domain context is assembled before your investigation starts.


Let agents handle the queue

Scale your capacity without adding headcount. Charlotte AI coordinates agents to drive investigations and converge on a single verdict.


Take action across your stack

Respond at machine speed. Build, orchestrate and govern agentic workflows in a single workspace with Charlotte Agentic SOAR.

Scale elite security judgment at machine speed


Charlotte AI is built on CrowdStrike’s elite expertise and the industry’s richest AI data layer.

3x Faster MTTR graphic

>98%

Decision accuracy with agentic detection triage4


70%

Reduced manual effort during investigations5


90%

Reduced incident response time6

New

Investigate across every domain, simultaneously


Attacks hit endpoints, identities, cloud, and network surfaces, all at once. Charlotte AI investigates the same way. It dispatches specialized agents to work in parallel across every domain, sharing one memory of the environment. Trained on the frontline decisions of CrowdStrike's elite analysts and sharpened by every breach stopped, each investigation makes the next one more precise.

Charlotte AI product screenshot
×
Charlotte AI product screenshot
×

Automate repetitive tasks with CrowdStrike’s agentic security workforce


Delegate the work that slows your team down: exposure prioritization, malware analysis, reconnaissance, query writing, and more to out-of-the-box agents. Every task returns unified context and structured, ready-to-use insights, so your team makes faster, sharper decisions at every turn.

Build custom security agents in AgentWorks, no code required


Encode your team’s hard-earned insights and institutional knowledge (playbooks, SOPs, and unique context) into agents that work alongside your team, 24/7 at machine speed. Build from the ground up on the models of your choice: define your agent’s mission, connect its data, and configure what gets automated and what’s gated behind analyst approval.

Charlotte AI product screenshot
×
Charlotte AI product screenshot
×

Govern automation across your ecosystem with Agentic SOAR


Charlotte Agentic SOAR unites agentic reasoning and deterministic workflows in a single governed workspace. For every workflow, you define the triggers, data, rules, agents, and actions. Build no-code agents with AgentWorks on the model of your choice, or design custom apps with Falcon Foundry. Connect to any tool or third-party agent through bidirectional MCP.

Deploy AI with confidence, always under your command


Charlotte AI enables security teams to scale their agentic defense with accountability and control, ISO 42001-certified for AI governance. Every answer traces back to the data behind it. Every action is bounded, user-authorized, and logged. Every response respects the permissions the user already has, so Charlotte AI never surfaces what a user isn't cleared to see.

product screenshot
×

Customer Stories

Charlotte AI makes the agentic SOC real

Hear how Charlotte AI empowers defenders to cut through the noise, slash complexity, and respond at machine speed.

Charlotte AI helps our analysts understand what’s happening  fast… It’s not just about speed, it’s about confidence and consistency across the team.”
Emmett Koen, Senior Director of Cybersecurity Operations
Mondelez logo
With AgentWorks, agents immediately access the high-quality data native to the CrowdStrike platform. We can create a reliable, scalable agent with a fraction of the time and effort it takes on other agentic platforms. It has allowed us to rapidly advance select use cases.”
Dr. Sean Hays, Ph.D., Senior Manager of Cyber Defense
American Express logo
The organizations that will lead in agentic security aren't the ones who just move the fastest, they're the ones who also move with control. AgentWorks gives us the governance infrastructure to deploy AI responsibly: testable, traceable, capped, and versioned.”
Steve Tieland, Senior Director of Corporate Security Operations
Pegasystems logo

See Charlotte AI in action

Is your SOC ready for the AI era?

Benchmark your security operations and see where you stand.

 

Latest innovations from

CrowdStrike unveils the next evolution of the agentic SOC
Coordinated, cross-domain investigations, out of the box
Proactively uncover external risk with agentic recon

FAQs

CrowdStrike Charlotte AI is an agentic AI security analyst built natively on the CrowdStrike Falcon® platform. It powers agentic and generative AI capabilities across Falcon modules, including conversational AI, prebuilt agents, and Charlotte AI AgentWorks for no-code custom agent development.

Charlotte AI is neither a chatbot nor a single agent - it uses a multi-agent architecture that supports a broad range of security functions. These include natural language interaction, command-line analysis, exposure analysis, query writing, workflow generation, custom agent development, and threat intelligence analysis.

Yes. Charlotte AI Detection Triage automatically evaluates first-party security detections and has been benchmarked at over 98% accuracy against decisions from the CrowdStrike Falcon® Complete Next-Gen MDR team. The agent generates a detection verdict, a confidence score, a recommendation, and an explanation of its reasoning. Security teams decide whether to escalate, close, or route detections based on their own criteria and configured playbooks.

Yes. Charlotte AI supports multiple approaches to generating incident reports and executive summaries. Teams can build agents in Charlotte AI AgentWorks that generate reports to their specifications, use the "LLM-Completion" action in the Falcon® Fusion workflow editor to automate reporting, or use promptbooks to produce structured output on demand.

Charlotte AI does not take automated response actions by default. Security teams configure which actions get automated - and under what conditions - using Charlotte Agentic SOAR (in workflows) and Charlotte AI AgentWorks (in the case of agents). Actions can be set to execute autonomously or require human approval before running, giving teams full control over automation in their environment.

Yes. Charlotte AI AgentWorks enables security teams to build custom AI agents in plain language, no code and no AI engineering required. Teams define agent instructions, provide knowledge files, configure outputs, assign authorized tools, and set the conditions under which agents activate. Agents are built on the CrowdStrike Falcon® platform's security data foundation and include built-in governance controls: role-based permissions, execution traces, audit logs, credit caps, and configurable approvals.

No. Modern adversaries operate faster than any analyst team can manually match. Charlotte AI closes that gap by automating high-volume, time-consuming work - including alert triage, enrichment, and routine investigation steps - so analysts can focus on the complex, judgment-intensive work that requires human expertise. The result is a force-multiplied team.

Yes. Qualifying CrowdStrike customers can access Charlotte AI at no cost through the CrowdStrike Falcon® console, with 50 AI credits that renew each month. Learn how to opt in for free access.

Charlotte AI includes built-in governance controls that support safe, auditable AI deployment. These include role-based access controls, execution traces, agent version history and rollback, credit caps to control agent consumption, and configurable approval workflows that require human sign-off before specified actions execute. Charlotte AI is certified under ISO/IEC 42001:2023.

Yes. Charlotte AI AgentWorks enables security teams to configure which agent actions execute automatically and which require human review before running. This lets organizations apply different levels of oversight based on action type, environment sensitivity, or internal compliance requirements. By default, Charlotte AI's prebuilt agents are limited to generating information, summaries, and recommendations. Any actions that affect an organization's environment require explicit configuration and approval by an authorized member of the security team.

12026 CrowdStrike Threat Hunting Report

22026 CrowdStrike Global Threat Report.

3Based on customer-reported assessment. See case study.

4Accuracy rating is a measure of Charlotte AI triage decisions that match the expert decisions from the CrowdStrike Falcon Complete Next-Gen MDR team.

5Based on customer-reported assessment. See case study.

6Based on customer-reported assessment. See case study.