Founded in 2011, CrowdStrike reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.
−Removed: When we started CrowdStrike, cyberattackers had an asymmetric advantage over legacy cybersecurity products that could not keep pace with the rapid changes in adversary tactics.
+Added: When we started CrowdStrike, cyberattackers had an asymmetric advantage over legacy cybersecurity products that could not keep pace with rapid changes in adversary tactics.
We took a fundamentally different approach to solve this problem with the CrowdStrike Falcon platform – the first, true cloud-native platform capable of harnessing vast amounts of security and enterprise data to deliver highly modular solutions through a single lightweight agent.
1 unchanged sentence
We believe our approach has defined a new category called the Security Cloud, which has the power to transform the cybersecurity industry the same way the cloud has transformed the customer relationship management, human resources, and service management industries.
−Removed: Using cloud-scale AI, our Security Cloud enriches and correlates trillions of cybersecurity events per week with indicators of attack, threat intelligence and enterprise data (including data from across endpoints, workloads, identities, DevOps, IT assets and configurations) to create actionable data, identify shifts in adversary tactics and automatically prevent threats in real-time across our customer base.
+Added: Using cloud-scale AI, our Security Cloud enriches and correlates trillions of cybersecurity events per week with indicators of attack, threat intelligence and enterprise data (including data from across endpoints, workloads, identities, IT assets and configurations) to create actionable information, identify shifts in adversary tactics and automatically detect and prevent threats in real-time across our customer base.
The more data that is fed into our Falcon platform, the more intelligent our Security Cloud becomes, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
The Architectural Purpose Behind the Platform
−Removed: Our Falcon platform was purpose-built in the cloud to harness the power of our Security Cloud to deliver the next generation of automated protection and provide threat hunters with the intelligence required to stop sophisticated attacks, including non-malware based attacks.
−Removed: This approach has made CrowdStrike an industry leader in endpoint and cloud workload protection (capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices) and enables us to rapidly scale this best in class protection across new and emerging areas of enterprise risk.
−Removed: Today, we offer 22 cloud modules on our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection, and log management.
+Added: Our Falcon platform was purpose-built in the cloud to harness the power of data to deliver the next generation of automated protection and provide threat hunters with the intelligence required to stop sophisticated attacks, including non-malware based attacks.
+Added: This approach has made CrowdStrike an industry leader in protection across endpoints, cloud workloads, identity and data (capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices) and enables us to rapidly scale this best in class protection across new and emerging areas of enterprise risk.
+Added: Today, we offer 23 cloud modules on our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, managed security services, security and vulnerability management, IT operations management, identity protection, log management, threat intelligence services, and data protection.
Our Falcon platform is composed of tightly integrated, proprietary technologies that enable us to deliver superior protection and performance, while reducing customer complexity.
2 unchanged sentences
With the lightweight agent installed on each endpoint or cloud workload, our Falcon platform automates detection and prevention capabilities in real time across our entire global customer base.
−Removed: This also enables our Falcon platform to intelligently ingest and stream high fidelity data back into the Security Cloud to continuously improve our Falcon platform’s AI algorithms and make its real-time decision-making faster and smarter to keep customers ahead of changing adversary tactics.
+Added: This also enables our Falcon platform to intelligently ingest data once and stream high fidelity data back into the Security Cloud to be re-used for multiple use cases, continuously improve our Falcon platform’s AI algorithms and make its real-time decision-making faster and smarter to keep customers ahead of changing adversary tactics.
Our graph technology correlates and contextualizes the vast data of our Security Cloud so we can collect data once and reuse it repeatedly to deliver solutions that solve our customers’ biggest problems.
−Removed: Our Threat Graph uses a combination of AI and behavioral pattern-matching techniques to correlate and analyze trillions of cybersecurity events, enriched with threat intelligence, and third-party data to identify and link threat activity together to automatically prevent threats in real time across CrowdStrike’s global customer base.
+Added: The highly advanced graph technologies underpinning the Falcon platform now include:
+Added: Our Threat Graph, which uses a combination of AI and behavioral pattern-matching techniques to correlate and analyze trillions of cybersecurity events, enriched with threat intelligence, and third-party data to identify and link threat activity together to automatically prevent threats in real time across CrowdStrike’s global customer base.
This also provides customers with increased visibility of attacks for proactive threat hunting and timely detection and remediation of novel threats.
+Added: Our Intel Graph, which analyzes and correlates data and threat intelligence to visualize the connections between adversaries and attacks to help customers prioritize investigations and gain a deep understanding of the threat landscape.
+Added: The latest intel on adversaries, tactics, techniques, and procedures is delivered seamlessly within the CrowdStrike Falcon platform and is mapped to the MITRE ATT&CK® framework.
+Added: Our Asset Graph, which dynamically monitors and tracks the complex interactions among assets, providing a single holistic view of the risks those assets pose.
+Added: Asset Graph provides graph visualizations of the relationships among all assets such as devices, users, accounts, applications, cloud workloads and operations technology (“OT”), along with the rich context necessary for proper security hygiene and proactive security posture management to reduce risk in their organizations — without impacting IT.
The Falcon platform was purpose-built with the foresight that the future of cybersecurity would need to be cloud-native and AI-driven.
−Removed: While AI is revolutionizing many technology fields, including cybersecurity solutions, to be truly effective,
−Removed: algorithms that enable AI depend on the quality and volume of data that trains them and the selection of the right differentiating features from that data.
+Added: While AI is revolutionizing many technology fields, including cybersecurity solutions, to be truly effective, algorithms that enable AI depend on the quality and volume of data that trains them and the selection of the right differentiating features from that data.
This is why we believe our Security Cloud and our cloud-native architecture creates a fundamental differentiator from our competitors.
1 unchanged sentence
We call this cloud-scale AI.
−Removed: Our technology is uniquely effective because we not only have a massive amount of high fidelity data to continuously train our AI models but also because of our deep cybersecurity expertise, which supports our industry-leading efficacy and low false positives.
+Added: Our technology is uniquely effective because we not only have a massive amount of high fidelity data to continuously train our AI models but also because we couple that data with deep human cybersecurity expertise, which supports our industry-leading efficacy and low false positives.
By analyzing and correlating information across our massive, crowdsourced dataset, we are able to deploy our AI algorithms at cloud-scale and build a more intelligent, effective solution to detect threats and stop breaches that on-premise, cloud-hosted and hybrid products cannot match due to the inherent architectural limitations those products have with respect to data storage and analysis.
2 unchanged sentences
The Trends Driving a Need for a New Approach to Security
−Removed: We believe there are a number of important macro trends that drive the need for a new approach to security.
+Added: We believe there are a number of important trends that drive the need for a new approach to security.
These include:
−Removed: • Cybersecurity Threats are More Sophisticated and More Damaging:
+Added: • The Increasing Sophistication and Disruption of Cybersecurity Threats:
The sophistication of adversaries continues to increase as militaries and intelligence services of well-funded nation-states, technically advanced criminal organizations and hackers use advanced, easily obtained methods of attack – including non-malware based attacks that exploit user identities and credentials.
4 unchanged sentences
At this stage in the threat lifecycle, the adversary is able to encrypt, destroy, or silently exfiltrate sensitive data.
−Removed: In 2021 alone, adversaries launched multiple, destructive attacks that disrupted business and resulted in significant cumulative losses.
−Removed: • Hybrid, Remote Workforces and the Proliferation of Workloads Expands the Attack Surface:
+Added: • An Expanded Attack Surface Driven By Hybrid and Remote Workforces:
Organizations everywhere are embracing digital transformation and are becoming more distributed as they adopt the cloud, increase workforce mobility, and grow their number of connected devices.
2 unchanged sentences
In addition, technologies like Cloud and Containers are being adopted quickly, but rather than becoming full-scale replacements, they are often being used as supplements to existing on-premise, bare metal, and virtualized workloads.
−Removed: • Growing Cyber Skills Gap:
+Added: • A Growing Cyber Skills Gap:
Trained cybersecurity professionals are in high demand, and organizations continue to face a dire shortage of talent to fill much needed cybersecurity positions.
1 unchanged sentence
Adversaries exploit this vacuum by continuing to accelerate their sophisticated attacks.
+Added: • The Need to Reduce Complexity and Simplify Security Operations:
+Added: Organizations are increasingly looking to reduce the complexity of their security and IT stack.
+Added: Modern security requires fewer point products, fewer agents and technologies that consume fewer resources.
+Added: Increasingly, organizations are looking to standardize on trusted platforms that deliver an immediate return on investment and lower total cost of ownership.
Competitive Market:
Existing Security Solutions Are Limited and Exacerbate Ongoing Trends:
−Removed: We believe the aforementioned trends are exacerbated by the architectural limitations of legacy cybersecurity products, which include:
−Removed: • On-Premise Security and Bolt-On Cloud Products Lead to Constrained and Impacted Users :
+Added: We believe the aforementioned trends are exacerbated by the architectural limitations of legacy cybersecurity products, which are characterized by:
+Added: • On-Premise Security and Bolt-On Cloud Products That Lead to Constrained and Impacted Users :
On-premise products are siloed, lack integration, and have limited ability to collect, process, and analyze vast amounts of data—attributes that are required to be effective in today’s increasingly dynamic threat landscape.
1 unchanged sentence
Many on-premise vendors have since tried to solve this problem by simply extending on-premise products to the cloud.
−Removed: Since their products were not purpose built to run in the cloud, the traditional on-premise issues - complex to deploy, siloed nature, lack of integration, limited ability to scale, costly to maintain - continue to manifest.
+Added: Since their products were not purpose built to run in the cloud, traditional on-premise issues – complex to deploy, siloed nature, lack of integration, limited ability to scale, costly to maintain – continue to manifest.
We believe that any product that was originally designed for on-premise deployments and migrated to the cloud cannot by definition be a cloud native solution.
−Removed: • Legacy Signature-Based Products Are Not Effective Against Unknown Threats :
+Added: • Legacy Signature-Based Products That Are Not Effective Against Unknown Threats :
Signature-based products are designed to detect attacks that are already cataloged as previously identified threats.
2 unchanged sentences
Many significant breaches seen in the last two decades have involved the failure of a legacy signature-based antivirus product to detect a previously unknown or modified version of a previously known attack.
−Removed: • Malware-Focused Machine Learning Products Miss Sophisticated Attacks:
+Added: • Malware-Focused Machine Learning Products That Miss Sophisticated Attacks:
Traditionally, organizations have focused on protecting their networks and endpoints against malware-based attacks.
These attacks involve malware built for the specific purpose of performing malicious activities, stealing data, or destroying systems.
−Removed: A malware-centric defensive approach will leave the organization vulnerable to attacks that do not leverage malware.
−Removed: • Application Whitelisting Products Are Ineffective:
−Removed: Application whitelisting products resort to an “always allow” or “always block” policy on an endpoint in order to allow or prevent processes from executing.
+Added: We have observed that over 60% of attacks comprise non-malware, hands-on-keyboard activity.
+Added: Therefore, a malware-centric defensive approach will leave the organization vulnerable to attacks that do not leverage malware.
+Added: • Application Whitelisting Products That Are Ineffective:
+Added: Application whitelisting products resort to an “always allow” or “always block” policy on an endpoint to allow or prevent processes from executing.
Whitelisting relies in part on manually creating and maintaining a complex list of rules, burdening end users and IT organizations.
1 unchanged sentence
Built for This Moment and the Future
−Removed: We believe that the cloud-native architecture of the Falcon platform and Security Cloud provides a sustainable advantage in addressing the needs of our customers as their business and the threat landscape continues to evolve.
−Removed: We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed security products in a single solution.
+Added: We believe that the cloud-native architecture of the Falcon platform and Security Cloud provides a sustainable advantage in addressing the needs of our customers as their businesses and the threat landscape continues to evolve.
+Added: We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed, and multi-agent security products in a single solution.
We also allow thinly-stretched security organizations to automate previously manual tasks, freeing them to focus on their most important objectives.
11 unchanged sentences
Our cloud-native platform approach gives customers a unified approach to address their most critical areas of risk seamlessly.
−Removed: We empower customers to rapidly deploy and scale cloud workload security, next-generation antivirus, endpoint detection and response (“EDR”), device control, host firewall management, vulnerability management, forensic analysis, IT hygiene, threat hunting, identity protection, log management, automated threat intelligence, and Extended Detection and Response (“XDR”) from a single platform.
+Added: We empower customers to rapidly deploy and scale industry leading technologies across endpoint detection and response (“EDR”) and Extended Detection and Response (“XDR”), Identity Threat Protection, Threat Intelligence, ITSecOps and Risk, Cloud Security, and Modern Log Management from a single platform.
• Reducing Agent Bloat :
10 unchanged sentences
Stopping today’s sophisticated attacks requires a combination of powerful automation and elite threat hunting.
−Removed: Our OverWatch threat hunting cloud module combines world-class human intelligence from our elite security experts with the power of the Security Cloud.
+Added: Falcon Complete provides a comprehensive monitoring, management, response, and remediation solution to our customers and is designed to bring enterprise level security to companies that may lack enterprise level resources.
+Added: CrowdStrike Falcon OverWatch combines world-class human intelligence from our elite security experts with the power of the Security Cloud.
OverWatch is a force multiplier that extends the capabilities and improves the productivity of our customers’ security teams.
3 unchanged sentences
CrowdStrike automates manual tasks to free security teams to focus on their most important job – stopping the breach.
−Removed: Our Falcon Fusion module automates workflows to reduce the need to switch between different security tools and tasks, while our Falcon XDR module provides a unified solution that enables security teams to rapidly and efficiently identify, hunt, and eliminate threats across multiple security domains.
+Added: Our Falcon Fusion module automates workflows to reduce the need to switch between different security tools and tasks, while our Falcon Insight XDR module provides a unified solution that enables security teams to rapidly and efficiently identify, hunt, and eliminate threats across multiple security domains.
• Lower Total Cost of Ownership :
1 unchanged sentence
Additionally, our comprehensive platform reduces overall personnel costs associated with ongoing maintenance, as well as the need for software patches and upgrades for separate products.
+Added: Enforcing Zero Trust Across the Pillars of Modern Enterprise Security
+Added: As modern attacks and adversaries grow more sophisticated, CrowdStrike believes that stopping breaches in the modern era requires security that delivers unified visibility and protection across three critical areas:
+Added: Endpoint and Cloud workloads, Identity Threat Protection and Data Protection.
+Added: Eighty percent of breaches today use stolen credentials and identities.
+Added: Stopping these advanced attacks requires a Zero Trust approach that delivers true end-to-end protection across workloads, identities, and data.
+Added: CrowdStrike is able to natively enforce Zero Trust protection at the device layer, the identity layer, and the data layer, extending our bold vision for security by driving modern Defense in Depth to the enterprise.
+Added: By delivering these powerful capabilities through a unified platform, CrowdStrike is able to connect the endpoint and workload to user identity, and the data that is being used and accessed.
+Added: Customers can see the full health and state of endpoints and workloads, in context with the identity that is using and accessing them, aligned with where data is being created, who is using it, where it flows and how it is protected.
+Added: CrowdStrike delivers this through a unified platform experience.
+Added: This is how CrowdStrike believes security should and must be delivered today to combat advanced adversaries and stop breaches in the modern era.
+Added: This means security solutions that are:
+Added: a) Easy to deploy;
+Added: b) Easy to manage;
+Added: and c) Highly effective, without interference on good user behavior.
The CrowdStrike Falcon Platform:
4 unchanged sentences
our lightweight agent and our Security Cloud.
−Removed: The Falcon platform offers a unified set of cloud-delivered technologies that power a wide range of modules including next-generation antivirus, EDR, device control, host firewall management, managed threat hunting, IT hygiene, vulnerability management, and threat intelligence.
+Added: The Falcon platform offers a unified set of cloud-delivered technologies that power a wide range of modules across EDR and XDR, Identity Threat Protection, Threat Intelligence, ITSecOps and Risk, Cloud Security, and Modern Log Management.
The Falcon platform also encompasses recently acquired technologies where integration may be ongoing.
3 unchanged sentences
Our modules address the most critical areas of enterprise risk and friction.
+Added: CrowdStrike Falcon Platform:
Our Cloud Modules
9 unchanged sentences
• Discover for Cloud and Containers—Cloud Service Discovery.
−Removed: Discover for Cloud and Containers delivers comprehensive visibility of cloud assets, security configurations, workloads and containers across multi-cloud environments so customers can mitigate risks and reduce the attack surface.
−Removed: Endpoint Security
+Added: Discover for Cloud and Containers delivers comprehensive visibility of cloud assets, security configurations, workloads and containers across multi-cloud environments so customers can mitigate risks and reduce their attack surface.
+Added: Endpoint Security and XDR
• Falcon Prevent—Next-Generation Antivirus .
Falcon Prevent provides next-generation antivirus capabilities to customers, delivering comprehensive protection to defend customers against both malware and fileless attacks.
−Removed: • Falcon Insight—Endpoint Detection and Response .
−Removed: Falcon Insight provides EDR capabilities to customers, allowing for continuous and comprehensive visibility to notify our customers what is happening on their endpoints in real time.
+Added: • Falcon Insight XDR—Endpoint Detection and Response .
+Added: With industry-leading EDR at its core, Falcon Insight XDR synthesizes cross-domain telemetry and activates extended capabilities with one unified, threat-centric command console to unlock cross-domain detections, investigations and responses across the security stack.
• Falcon Device Control—Device Control .
2 unchanged sentences
Falcon Firewall Management provides centralized management of the firewall capabilities native to the host operating system, allowing customers to create, enforce, and maintain host firewall policies.
−Removed: Extended Detection and Response
−Removed: • Falcon XDR - Extended Detection and Response .
−Removed: Falcon XDR extends our industry leading detection, investigation, and response capabilities by incorporating relevant third-party security data.
−Removed: We correlate signals from multiple disparate technologies to deliver XDR detections across the attack surface.
−Removed: We allow customers to investigate these detections and to search and hunt using data from CrowdStrike, as well as third party security sources such as email, cloud access security broker (“CASB”) network threat detection, and identity and firewall data.
−Removed: The CrowdXDR Alliance offers a first-of-its-kind technology ecosystem to enable unified, threat-centric detection and response across an organization’s security and technology ecosystem.
−Removed: We believe the CrowdXDR Alliance is differentiating - bringing together industry leaders and cutting-edge solutions to establish an open-source, common XDR ontology for data sharing.
−Removed: Falcon XDR is designed to enhance threat correlation and speeds response times against sophisticated attacks.
Security and IT Operations
−Removed: • Falcon Discover—IT Hygiene .
+Added: • Falcon Discover—IT Hygiene and IoT .
Falcon Discover identifies rogue systems and applications in our customers’ networks, and monitors the use of privileged user accounts anywhere in a customer’s environments.
−Removed: The module also enables use cases outside of security, such as application license management, AWS spend analysis, and asset inventory.
+Added: The module also enables use cases outside of security, such as application license management, Amazon Web Services (“AWS”) spend analysis, and asset inventory.
+Added: New enhancements in Falcon Discover for IoT minimize risk for IoT/OT (“Other Technology”) devices with comprehensive asset visibility, monitoring, and security hygiene.
• Falcon Spotlight—Vulnerability Management .
2 unchanged sentences
• Falcon Forensics—Forensic Data for Analysis of Cybersecurity Incidents .
−Removed: Falcon Forensics streamlines the collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents, enabling responders to quickly identify relevant data with preset dashboards and rapidly investigate.
+Added: Based on years of incident response experience and forensics investigative services from CrowdStrike’s leading services team, Falcon Forensics streamlines the collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents, threat hunting as well as enabling responders to quickly identify relevant evidence of an intrusion with preset dashboards, allowing for rapid investigation, triage and remediation.
• Falcon FileVantage—File Integrity Monitoring .
Falcon FileVantage reduces compliance complexity by building in the services an additional agent would normally provide, including being able to monitor all files on the protected systems.
−Removed: This in turn provides alerts and reports to help meet various compliance requirements imposed by PCI, CIS Controls, and Sarbanes-Oxley.
+Added: This in turn provides alerts and reports to help meet various compliance requirements imposed by the Payment Card Industry (“PCI”), the Center for Internet Security (“CIS”) Controls, and Sarbanes-Oxley.
Managed Services
2 unchanged sentences
It is backed by an underwritten limited warranty policy for breaches.
−Removed: We also offer Falcon Cloud Workload Protection Complete and Falcon Identity Threat Protection Complete as add-ons to our Falcon Complete solution to extend its capabilities to include our cloud workload protection and identity protection modules.
+Added: We also offer Falcon Cloud Workload Protection Complete, Falcon Identity Threat Protection Complete, and Falcon Complete LogScale as add-ons to our Falcon Complete solution to extend its capabilities to include our cloud workload protection, identity protection, and log management modules.
• Falcon OverWatch—Threat Hunting .
−Removed: Falcon OverWatch is a threat hunting solution that consists of an elite team of dedicated security experts who work with the power of Threat Graph to proactively identify threats for our customers.
+Added: Falcon OverWatch is a threat hunting solution that consists of an elite team of dedicated security experts who work with the power of Threat Graph to proactively hunt on telemetry collected in the platform around the clock 24/7/365 to identify novel threats and attacks that might otherwise go unnoticed by security teams and the tools they use to monitor and detect advancing new threats in support of our customers.
Threat Intelligence
−Removed: • Falcon X—Threat Intelligence .
−Removed: Falcon X integrates threat intelligence into endpoint protection and provides automated analysis of detected threats to provide insight into the capabilities, motivation and attribution of attacks.
−Removed: In addition to the standard Falcon X offering, we also offer premium options that include global threat research and reporting from our team of intelligence analysts.
+Added: • Falcon Intelligence—Threat Intelligence .
+Added: Falcon Intelligence integrates threat intelligence into endpoint protection and provides automated analysis of detected threats to provide insight into the capabilities, motivation and attribution of attacks.
+Added: In addition to the standard Falcon Intelligence offering, we also offer premium options that include global threat research and reporting from our team of intelligence analysts.
• Falcon Search Engine—Malware Search .
−Removed: Falcon Search Engine enables customers to search in real time across approximately 5.0 petabytes of malware collected in our Falcon platform and indexed by our proprietary binary data indexing technology.
+Added: Falcon Search Engine enables customers to search in real time across over 8 petabytes of malware collected in our Falcon platform and indexed by our proprietary binary data indexing technology.
• Falcon Sandbox—Malware Analysis .
Falcon Sandbox allows our customers to analyze unknown files for malicious behavior by detonating them safely in virtual machines.
−Removed: • Falcon X Recon—Situational Awareness .
−Removed: Falcon X Recon allows our customers to identify and mitigate digital risks on the hidden areas of the clear, deep and dark web.
+Added: • Falcon Intelligence Recon—Situational Awareness .
+Added: Falcon Intelligence Recon allows our customers to identify and mitigate digital risks on the hidden areas of the clear, deep and dark web.
These risks include, but are not limited to, digital fraud, data theft exposure, social media impersonations.
+Added: • Falcon Surface—External Attack Surface Management.
+Added: Falcon Surface (previously, Reposify) allows customers to discover and map all internet-facing assets to shut down potential exposures with guided mitigation plans to reduce the attack surface and organizational risk.
Identity Protection
−Removed: • Falcon Zero Trust—Zero Trust Security .
−Removed: Frictionless Zero Trust security with real-time threat prevention and IT policy enforcement using identity, behavioral and risk analytics.
+Added: • Falcon Identity Threat Protection—Zero Trust Security .
+Added: Falcon Identity Threat Protection provides frictionless Zero Trust security with real-time threat prevention and IT policy enforcement using identity, behavioral and risk analytics.
• Falcon Identity Threat Detection—Identity Threat Detection .
−Removed: Visibility for identity-based attacks and anomalies, comparing live traffic against behavior baselines and rules to detect attacks and lateral movement.
−Removed: Log Management
−Removed: • Humio—Log Management .
−Removed: Humio is a high-performance, index-free cloud log management solution that allows customers to collect logs from any data source and to search and query streaming data in real-time.
−Removed: Recently Acquired Technologies
−Removed: • SecureCircle – Data Protection .
−Removed: SecureCircle is a recently acquired technology that extends Zero Trust security to data on the endpoint.
−Removed: As data security drives business value for our customers, end users operate without obstacles,
−Removed: while data is continuously secured against breaches and insider threats.
−Removed: Instead of relying on complex reactive measures, we believe integrating SecureCircle will help us simply secure data persistently in transit, at rest, and even in use.
+Added: Falcon Identity Threat Detection provides visibility for identity-based attacks and anomalies, comparing live traffic against behavior baselines and rules to detect attacks and lateral movement.
+Added: Observability
+Added: • Falcon LogScale—Log Management .
+Added: Falcon LogScale is a high-performance, index-free cloud log management solution that allows customers to collect logs from any data source and to search and query streaming data in real-time.
Bringing CrowdStrike to the Market
23 unchanged sentences
We continue to look for new ways to broaden our reach into new customer segments.
−Removed: • Extending Our Falcon Platform and Ecosystem.
−Removed: We designed our architecture to be open, interoperable, and highly extensible.
−Removed: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity, which allows customers to purchase CrowdStrike products and provides an ecosystem of trusted partners and applications for our customers to choose from.
−Removed: In the future we plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us.
−Removed: • Broadening Our Reach into the U.S.
−Removed: Federal Government Vertical.
−Removed: We are investing in the acquisition of customers in the U.S.
−Removed: federal government vertical.
+Added: • Broadening Our Reach into U.S.
+Added: Public Sector Verticals.
+Added: We continue to invest heavily in the acquisition of customers in the U.S.
+Added: federal government as well as the state, local, and higher education verticals.
Our platform is authorized by several federal agencies via the Federal Risk and Authorization Management Program (“FedRAMP”).
−Removed: To further meet the compliance demands of the federal government, customers can elect to deploy the Falcon platform in the AWS GovCloud.
+Added: Additionally, Department of Defense organizations can rely upon CrowdStrike’s Impact Level 4 provisional authorization to satisfy their cloud-based security requirements.
+Added: To further meet the compliance demands of the government, customers can elect to deploy the Falcon platform in the AWS GovCloud.
We have also successfully been embedded into several strategic government-wide cybersecurity programs and contracts, such as the Department of Homeland Security’s Continuous Diagnostics and Mitigation Approved Products List, which serves to provide federal agencies with innovative security tools.
+Added: As a result, the Cybersecurity and Infrastructure Security Agency has leveraged a significant investment in our platform to support modernization efforts within the Federal Civilian Executive Branch.
+Added: Further evidence of our progress into these critical markets is demonstrated by virtue of fact that 22 of the 50 U.S.
+Added: states have standardized on CrowdStrike’s platform at the enterprise level.
• Expanding Our International Footprint.
2 unchanged sentences
We intend to grow our international customer base by increasing our investments in our overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, including Japan, and expanding current data centers overseas.
−Removed: We have experienced significant growth, with revenue increasing from $874.4 million in fiscal 2021 to $1.5 billion in fiscal 2022, representing year-over-year growth of 66%, and from $481.4 million in fiscal 2020 to $874.4 million in fiscal 2021, representing year-over-year growth of 82%.
−Removed: Subscription revenue grew from $804.7 million in fiscal 2021 to $1.4 billion in fiscal 2022, a 69% increase, and from $436.3 million in fiscal 2020 to $804.7 million in fiscal 2021, an 84% increase.
−Removed: Our Annual Recurring Revenue (“ARR”), has grown from a $1.1 billion as of January 31, 2021 to $1.7 billion as of January 31, 2022, a 65% increase, and from $600.5 million as of January 31, 2020 to $1.1 billion as of January 31, 2021, a 75% increase.
+Added: • Extending Our Falcon Platform and Ecosystem.
+Added: We designed our architecture to be open, interoperable, and highly extensible.
+Added: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity, which allows customers to purchase CrowdStrike products and provides an ecosystem of trusted partners and applications for our customers to choose from.
+Added: We plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us.
+Added: We have experienced significant growth, with revenue increasing from $1.5 billion in fiscal 2022 to $2.2 billion in fiscal 2023, representing year-over-year growth of 54%, and from $874.4 million in fiscal 2021 to $1.5 billion in fiscal 2022, representing year-over-year growth of 66%.
+Added: Subscription revenue grew from $1.4 billion in fiscal 2022 to $2.1 billion in fiscal 2023, a 55% increase, and from $804.7 million in fiscal 2021 to $1.4 billion in fiscal 2022, a 69% increase.
+Added: Our Annual Recurring Revenue (“ARR”) has grown from $1.7 billion as of January 31, 2022 to $2.6 billion as of January 31, 2023, a 48% increase, and from $1.1 billion as of January 31, 2021 to $1.7 billion as of January 31, 2022, a 65% increase.
We had net losses of $183.2 million, $234.8 million, and $92.6 million in fiscal 2023, fiscal 2022, and fiscal 2021, respectively.
18 unchanged sentences
Threat Graph.
−Removed: Threat Graph is a proprietary, powerful, and dynamic graph database.
+Added: Threat Graph is our proprietary, powerful, and dynamic graph database.
Threat Graph continually looks for malicious activity by combining AI with behavioral pattern-matching techniques to look beyond file features and track the behaviors of every software program executed on an endpoint in a customer’s network environment.
By applying powerful graph analytics and AI algorithms to cybersecurity, we enrich the data collected with our proprietary and third-party threat intelligence, such as adversary capabilities, motivations, attributions, and threat indicators.
−Removed: The graph data model allows the AI algorithms to identify relationships between events that are not directly related but which could indicate an attack that would otherwise remain undetected.
+Added: The graph data model allows our AI algorithms to identify relationships between events that are not directly related but which could indicate an attack that would otherwise remain undetected.
We believe that our AI algorithms are advantaged by the rich proprietary dataset that we use to train them.
3 unchanged sentences
This collect-once, use repeatedly approach is the reason why we have been able to deliver new cloud modules covering IT hygiene and vulnerability management quickly and enables us to continue expanding the Falcon platform rapidly in the future.
+Added: Intel Graph analyzes and correlates massive amounts of data on adversaries, their victims and their tools, providing unrivaled insights into the shifts in tactics and techniques, powering our adversary-focused approach with world-class threat intelligence.
+Added: Asset Graph dynamically monitors and tracks the complex interactions among assets, providing a single holistic view of the risks those assets pose.
+Added: Asset Graph provides graph visualizations of the relationships among all assets such as devices, users, accounts, cloud workloads, and OT along with the rich context necessary for proper security hygiene and proactive security posture management to reduce risk in their organizations.
High Fidelity Data and Smart Filtering.
2 unchanged sentences
The presence of a local graph model in our agent enables it to track the state of the machine in real time, perform rapid machine learning and behavioral analysis, and provide efficient event streaming to the cloud.
−Removed: We call this “smart filtering.” This allows us to keep performance overhead on the endpoint to a minimum, dramatically reduce the bandwidth required for agent-cloud communication, efficiently process large volumes of data, and separate the signal from the noise.
+Added: We call this “smart filtering.” This allows us to keep performance overhead on the endpoint to a minimum, dramatically reduce the bandwidth required for agent-cloud communication, efficiently process large volumes of data, and separate signals from noise.
The Falcon agent collects and analyzes unfiltered data with local machine learning and behavioral algorithms on the endpoint but only streams high fidelity endpoint events to the cloud to only send what is necessary for detection, prevention and investigation of attacks.
−Removed: This smart filtering architecture allows us to reduce network load for customers to approximately five megabytes per endpoint per day.
+Added: This smart filtering architecture allows us to reduce network load for customers on average between five to eight megabytes per endpoint per day.
The Falcon platform collects an array of high fidelity endpoint events, such as code execution, network, file system and user activity.
15 unchanged sentences
• Incident Response and Forensics Services.
−Removed: Our incident response services typically begin by deploying our lightweight agent to a customer’s endpoints to provide comprehensive visibility in order to determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done.
−Removed: The Falcon platform’s next-gen prevention capabilities, cloud posture management and identity protection offerings can also be leveraged to enrich the response team’s visibility and understanding of the attack as well as help to slow down and prevent an active attacker from moving at-will throughout a compromised customer’s environment, increasing the risk and potential damage to the customer.
−Removed: We also provide customized remediation planning by providing a strategy to eject attackers out of the network, lock down credentials from further use, and ensure adversaries stay out.
+Added: Our incident response services typically begin by deploying our lightweight agent to a customer’s endpoints or cloud workloads to provide comprehensive visibility in order to determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done.
+Added: The full suite of Falcon platform’s next-gen prevention capabilities, cloud posture management, vulnerability/asset management, identity protection and now attack surface management offerings can also be leveraged to enrich the response team’s visibility and understanding of the attack as well as help to slow down and prevent an active attacker from moving at-will throughout a compromised customer’s environment, increasing the risk and potential damage to the customer.
+Added: We also provide customized surgical remediation services by providing the tools and staffing to eject attackers out of the network, lock down credentials from further use, remediate impacted systems and ensure adversaries stay out.
In addition to providing valuable breach remediation to our customers, our incident response services also act as a strong lead generation engine for our Falcon platform and cloud modules.
After experiencing the benefits of our platform firsthand, many of our incident response customers become subscription customers.
−Removed: Among organizations who first became a customer after February 1, 2020, for each $1.00 spent by those customers on their initial engagement for our incident response or proactive services, as of January 31, 2022, we derived an average of $5.71 in ARR from those subscription contracts.
+Added: Among organizations who first became a customer after February 1, 2021, for each $1.00 spent by those
+Added: customers on their initial engagement for our incident response or proactive services, as of January 31, 2023, we derived an average of $6.07 in ARR from those subscription contracts.
• Technical Assessment and Strategic Advisory Services .
Our proactive security services include technical assessment services designed to help organizations understand their cyber maturity levels.
−Removed: These services include compromise assessments, cybersecurity maturity assessments, security program in-depth assessments, service
−Removed: organization control assessments, cloud security assessments, IT hygiene assessments, and active directory security assessments.
+Added: These services include both endpoint and cloud workload compromise assessments, cybersecurity maturity assessments, security program in-depth assessments, service organization control assessments, IT hygiene assessments, and active directory security assessments.
We also advise customers on readiness and preparation through the execution of table-top exercises, live fire exercises, red team/blue team assessments, and advanced adversary emulation exercises.
7 unchanged sentences
We engage our customers through our global customer and technical advisory boards in which we solicit feedback from our customers on a regular basis allowing us to understand their evolving needs.
−Removed: We have used this feedback to develop new cloud modules, such as Falcon Insight, and we intend to continue to develop new cloud modules based on our customer’s feedback.
+Added: We have used this feedback to develop new cloud modules, such as Falcon FileVantage, and we intend to continue to develop new cloud modules based on our customer’s feedback.
Our business is not dependent on any particular end customer.
1 unchanged sentence
Our sales and marketing organizations work together closely to drive market awareness, build a strong sales pipeline and cultivate customer relationships to drive revenue growth.
−Removed: We primarily sell subscriptions to our Falcon platform and cloud modules through our direct sales team, which is comprised of field sales and inside sales professionals who are segmented by a customer’s number of endpoints.
−Removed: Our sales team also leverages our network of channel partners.
+Added: We primarily sell subscriptions to our Falcon platform and cloud modules through our world-class, global sales team, which is comprised of field sales and inside sales professionals who are segmented by a customer’s organizational size.
+Added: Our sales team also leverages a powerful go-to-market sales motion with our vast ecosystem of channel and alliances partners.
We also use our sales team to identify current customers who may be interested in free trials of additional cloud modules, which serves as a powerful driver of our land and expand model.
9 unchanged sentences
Our technology alliance partnerships focus on security analytics, network and infrastructure security, threat platforms and orchestration, and automation.
−Removed: We launched the CrowdStrike Store, the first
−Removed: open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications.
−Removed: In addition, Falcon for Amazon Web Services (“AWS”), available in the AWS Marketplace, allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
+Added: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications.
+Added: In addition, Falcon for AWS, available in the AWS Marketplace, allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
Research and Development
18 unchanged sentences
Our competitors currently include the following by general category:
−Removed: • legacy antivirus product providers, such as Trellix (formerly McAfee Enterprise), Broadcom Inc.’s Symantec Enterprise division, and Microsoft Corporation, who offer a broad range of approaches and solutions including traditional signature-based antivirus protection;
−Removed: • alternative endpoint security providers, such as Blackberry Cylance, VMware Carbon Black and SentinelOne, who generally offer a mix of on-premises and cloud-hosted products that rely heavily on malware-only or application whitelisting techniques;
−Removed: • network security vendors, such as Palo Alto Networks, Inc., who are supplementing their core perimeter-based offerings with endpoint security solutions;
−Removed: • professional service providers, such as Mandiant and Microsoft Corporation, who offer cybersecurity response services.
+Added: • legacy antivirus product providers who offer a broad range of approaches and solutions including traditional signature-based antivirus protection;
+Added: • alternative endpoint security providers who generally offer a mix of on-premises and cloud-hosted products that rely heavily on malware-only or application whitelisting techniques;
+Added: • network security vendors who are supplementing their core perimeter-based offerings with endpoint security solutions;
+Added: • professional service providers who offer cybersecurity response services.
We compete on the basis of a number of factors, including but not limited to our:
11 unchanged sentences
Though we rely in part upon these legal and contractual protections, we believe that factors such as the skills and ingenuity of our employees and the functionality and frequent enhancements to our solutions are larger contributors to our success in the marketplace.
−Removed: As of January 31, 2022, we had 132 issued patents and 90 pending patent applications in the United States and other countries.
−Removed: These patents and patent applications seek to protect our proprietary inventions relevant to our business.
−Removed: We intend to pursue additional intellectual property protection to the extent we believe it would be beneficial and cost-effective.
+Added: We continue to grow our global portfolio and intellectual property rights in connection with our products, services, research and development, and other activities to protect our proprietary technology relevant to our business.
+Added: We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.
+Added: We intend to continue pursuing additional intellectual property protection to the extent we believe it would be beneficial and cost-effective.
Despite our efforts to protect our intellectual property rights, they may not be respected in the future or may be invalidated, circumvented, or challenged.
9 unchanged sentences
Until such time as these amounts are invoiced, they are not recorded in deferred revenue or elsewhere in our consolidated financial statements, and are considered by us to be backlog.
−Removed: As of January 31, 2022, we had backlog of approximately $735.8 million.
+Added: As of January 31, 2023, we had backlog of approximately $1.0 billion.
We expect backlog will change from period to period for several reasons, including the timing and duration of customer agreements, varying billing cycles of subscription agreements, and the timing and duration of customer renewals.
2 unchanged sentences
Given the annual budget approval process of many of our customers, we see seasonal patterns in our business.
−Removed: We expect these seasonal variations to become more pronounced in future periods, with net new ARR generation being greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year.
−Removed: In addition, we also
−Removed: experience seasonality in our operating margin, with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes, new hires, and annual sales and marketing events.
+Added: Net new ARR generation is typically greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year.
+Added: In addition, we also experience seasonality in our operating margin, typically with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes, new hires, and annual sales and marketing events.
This also impacts the timing of operating cash flow.
8 unchanged sentences
We believe the company’s success depends on our ability to attract, develop and retain key personnel.
−Removed: The skills, experience and industry knowledge of key employees significantly benefit our operations and performance.
+Added: The skills, experience and industry knowledge of key employees significantly benefit our customers, operations and performance.
Our talent sourcing is aligned to our organizational strategy to provide the expertise and skills needed to move our mission forward.
11 unchanged sentences
We deliver numerous training opportunities, provide rotational assignment opportunities, have expanded our focus on continuous learning and development, and implemented new methodologies to manage performance, provide feedback, and develop talent.
−Removed: Remote-First Distributed Workforce
−Removed: For CrowdStrike, the ability to work remotely is a deliberate strategy that we believe fuels rapid innovation and attracts the best and brightest around the world, regardless of their specific location.
−Removed: Our culture is purpose-built around a remote-first way of working, creating a competitive advantage for both the company and its customers and minimizing disruption from localized issues such as natural disasters, political events, or health emergencies, such as the COVID-19 pandemic.
+Added: Distributed Workforce
+Added: For CrowdStrike, the ability to work remotely or in a hybrid arrangement is a deliberate strategy that we believe fuels rapid innovation and helps us attract, hire and retain the best and brightest around the world, regardless of their specific location.
+Added: Our culture is purpose-built around this ability, creating a competitive advantage for both the company and its customers and minimizing disruption from localized issues such as natural disasters, political events, or health emergencies, such as the COVID-19 pandemic.
CrowdStrike has had a distributed workforce since its inception.
−Removed: Even prior to the COVID-19 pandemic, roughly 70% of our workforce, including engineering and technology teams, worked on a remote basis.
−Removed: During the pandemic, we quickly went
−Removed: to 100% of our workforce working remotely.
−Removed: We have recently started to open offices again following the local guidelines, but have continued to encourage employees to follow local guidance on COVID-19 protocols to protect the health and safety of themselves and of those around them.
−Removed: Since the beginning, we recognized that creating high-functioning, effective remote-first teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically.
−Removed: We have designed our processes, systems, and teams so that people can perform their jobs without needing to be physically present in the same room or even in the same time zone.
−Removed: Part of supporting our remote-first culture also involves actively encouraging personal well-being through initiatives, including wellness programs, engagement programs (speaker series, employee resource groups, gift exchanges, mentorship opportunities, virtual events, etc.), community outreach activities, recognition programs, and groups to connect people, no matter where they are geographically, with similar interests, life circumstances or backgrounds.
+Added: While working remotely has its advantages, we also believe that building community and engagement happens at a faster pace when people can come together.
+Added: Since the beginning, we recognized that creating high-functioning, effective remote and hybrid teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically.
+Added: We have designed our processes, systems, and teams so that most employees can perform their jobs without needing to be physically present in the same room or even in the same time zone.
+Added: Part of supporting our remote and hybrid culture also involves actively encouraging personal well-being through initiatives, including wellness programs, engagement programs (speaker series, employee resource groups, gift exchanges, mentorship opportunities, virtual events, etc.), community outreach activities, recognition programs, and groups to connect people, no matter where they are geographically, with similar interests, life circumstances or backgrounds.
Diversity, Equity, and Inclusion
7 unchanged sentences
Employee Resource Groups are an integral component of our commitment to foster community, promote a sense of belonging, facilitate organizational change, and drive a greater understanding of the diversity of perspectives we have across CrowdStrike.
−Removed: In addition to the Embracing Equity majority ally group, we have five official Employee Resource Groups and we are anticipate additional groups in the future:
+Added: In addition to the Embracing Equity majority ally group, we have seven official Employee Resource Groups and we anticipate additional groups in the future:
• Women of CrowdStrike
3 unchanged sentences
• Team BELIEVE (Black employees)
+Added: • AbilityStrikers (Cognitive and physical disabilities)
+Added: • Communidad (Latine and Hispanic employees)
Our Employee Resource Groups are employee led, self-directed, voluntary groups that align with our organizational mission, values, and goals that offer opportunities for groups to network, recommend business initiatives and process improvements, increase organizational awareness and allyship, and create opportunities for talent development.
3 unchanged sentences
• Identify initiatives and best practices throughout the organization and make recommendations to the business to help spark and facilitate change.
−Removed: Executive Officers
+Added: Information about our Executive Officers
The following table sets forth certain information with respect to our current executive officers as of March 8, 2023:
+Added: Name Age Position
George Kurtz 52 President, Chief Executive Officer and Director
Podbere 57 Chief Financial Officer
−Removed: Shawn Henry 59 President, CrowdStrike Services and Chief Security Officer
+Added: Shawn Henry 60 Chief Security Officer
+Added: Michael Sentonas 49 President
There is no family relationship between any of our directors or executive officers and any other director or executive officer.
21 unchanged sentences
from McGill University.
−Removed: Shawn Henry - President, CrowdStrike Services and Chief Security Officer
−Removed: Henry has served as President of CrowdStrike Services and our Chief Security Officer since March 2012.
+Added: Shawn Henry - Chief Security Officer
+Added: Henry has served as our Chief Security Officer since March 2012.
+Added: From March 2012 to October 2022, Mr.
+Added: Henry also served as President of CrowdStrike Services.
Henry previously worked for the FBI from 1987 through March 2012, including most recently as Executive Assistant Director of the FBI’s Criminal, Cyber, Response and Services Branch.
8 unchanged sentences
in Criminal Justice from Virginia Commonwealth University.
+Added: Michael Sentonas - President
+Added: Sentonas has served as our President since March 2023.
+Added: Prior to being appointed President, Mr.
+Added: Sentonas served as our Chief Technology Officer since February 2020, and as our Vice President, Technology Strategy from May 2016 to February 2020.
+Added: Immediately prior to joining us, Mr.
+Added: Sentonas served at McAfee Corp.
+Added: from March 2004 to April 2016 in various positions, and finally as Chief Technology Officer – Security Connected from November 2013 to April 2016.
+Added: Sentonas is a board member of the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities, and a member of the Forbes Technology Counsel, an organization for senior technology executives.
+Added: He is an active public speaker on security issues and advises government and business communities on global and local cyber security threats.
+Added: Sentonas holds a bachelor’s degree in computer science from Edith Cowan University, Western Australia.
Corporate Information
1 unchanged sentence
9th Street, Suite 1400, Austin, Texas 78701 and our telephone number is (888) 512-8906.
+Added: We are a holding company and all of our business operations are conducted through our subsidiaries, including CrowdStrike, Inc.
Our website address is www.crowdstrike.com.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.