Founded in 2011, CrowdStrike reinvented cybersecurity for the cloud and artificial intelligence (“AI”) era and transformed the way cybersecurity is delivered and experienced by customers.
−Removed: When we started CrowdStrike, cyberattackers had an asymmetric advantage over legacy cybersecurity products that could not keep pace with rapid changes in adversary tactics.
−Removed: We took a fundamentally different approach to solve this problem with the AI-native CrowdStrike Falcon cybersecurity platform – the first, true, cloud-native platform built with AI at the core, capable of harnessing vast amounts of security and enterprise data to deliver highly modular solutions through a single lightweight agent.
+Added: When we started CrowdStrike, cyberattackers had an asymmetric advantage over legacy cybersecurity products that could not keep pace with rapid changes in adversary tactics, a dynamic that has intensified as adversaries increasingly leverage automation, identity abuse, and AI to operate at machine speed.
+Added: We took a fundamentally different approach to solve this problem with the AI-native CrowdStrike Falcon cybersecurity platform, which serves as the operating system for cybersecurity.
+Added: CrowdStrike built the first, true, cloud-native platform with AI at the core, capable of harnessing vast amounts of security and enterprise data to drive real-time security decisions and response – stopping breaches at scale through a single lightweight sensor.
The CrowdStrike Falcon platform is designed to be the definitive platform for cybersecurity consolidation, purpose-built to stop breaches.
−Removed: The platform’s single, lightweight agent collects and integrates data from across the enterprise, including endpoints, cloud workloads, identities, and third-party sources.
+Added: The platform’s single, lightweight sensor collects and integrates data from across the enterprise, including endpoints, cloud workloads, identities, and third-party sources.
+Added: This data is ingested once and reused across multiple security functions, forming the foundation for detection, investigation, and response across the platform.
We use this to train our AI to detect and prevent threats and drive workflow automation to give security teams machine speed advantage to stop adversaries.
By consolidating and replacing legacy point products and fragmented platforms across key areas of security and IT, the Falcon platform delivers a unified, modern approach that increases capabilities, reduces complexity, and lowers costs – all while stopping breaches.
−Removed: We believe our approach has defined a new category called the Security Cloud, which has the power to transform the cybersecurity industry the same way the cloud has transformed the customer relationship management, human resources, and service management industries.
−Removed: Using cloud-scale AI, our Security Cloud enriches and correlates trillions of cybersecurity events per week with indicators of attack, threat intelligence, and enterprise data (including data from across endpoints, workloads, identities, DevOps, IT assets, and configurations) to create actionable data, identify shifts in adversary tactics, and automatically prevent threats in real-time across our customer base.
−Removed: The more data that is fed into our Falcon platform, the more intelligent our Security Cloud becomes, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
+Added: We believe our approach has defined a new category called the AI Security Cloud, which has the power to transform the cybersecurity industry the same way the cloud has transformed the customer relationship management, human resources, and service management industries.
+Added: Using cloud-scale AI, our AI Security Cloud enriches and correlates trillions of cybersecurity events per week with indicators of attack, threat intelligence, and enterprise data (including data from across endpoints, workloads, identities, DevOps, IT assets, configurations and AI interactions).
+Added: This data is continuously curated, labeled, and validated through real-world security operations, including managed detection and response, threat intelligence, and incident response activities, creating high-fidelity intelligence grounded in real adversary behavior and outcomes – cyber Reinforced Learning from Human Feedback (“RLHF”) at scale.
+Added: This intelligence is used to train and refine our AI models, enabling the Falcon platform to provide real-time context on adversary behavior, inform security decisions, and automatically prevent threats across our customer base.
+Added: The more data that is fed into our Falcon platform, the more intelligent the AI Security Cloud becomes, the stronger our ability to anticipate and counter evolving adversary tradecraft, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
The Architectural Purpose Behind the Platform
Our Falcon platform was purpose-built in the cloud to harness the power of data and AI to deliver the next generation of automated protection and provide threat hunters with the intelligence required to stop sophisticated attacks, including malware-free and fileless attacks.
−Removed: This approach has made CrowdStrike an industry leader in protection across endpoints, cloud workloads, identity and data (capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices) and enables us to rapidly scale this best in class protection across new and emerging areas of enterprise risk.
−Removed: Today, we offer 29 cloud modules on our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate endpoint and cloud workload security, managed security services, security and vulnerability management, IT operations management, identity protection, next-generation security information and event management (“SIEM”) and log management, threat intelligence services, data protection, SaaS security posture management, Security Orchestration, Automation and Response (“SOAR”) and AI powered workflow automation, and securing generative AI workloads.
+Added: This approach has made CrowdStrike an industry leader in protection across endpoints, cloud workloads, identity data, and AI systems, delivering consistent security execution across hybrid and cloud environments, and allowing us to rapidly extend this best-in-class protection across new and emerging areas of enterprise risk.
+Added: Today, we offer 33 cloud modules on our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate endpoint and cloud workload security, managed security services, security and vulnerability management, IT operations management, identity protection, next-generation security information and event management (“SIEM”) and log management, threat intelligence services, data protection, SaaS security posture management, Security Orchestration, Automation and Response (“SOAR”) and AI powered workflow automation, and security for generative AI and AI-driven systems through AI detection and response.
Our Falcon platform is composed of tightly integrated, proprietary technologies that enable us to deliver superior protection and performance, while reducing complexity for our customers.
−Removed: Our Falcon platform consists of our easily deployed, intelligent lightweight agent, and our groundbreaking graph technology.
−Removed: Our single, lightweight-agent approach has changed how organizations experience cybersecurity, delivering protection without impacting the user, resources or productivity.
−Removed: With the lightweight agent installed on each endpoint and cloud workload, our Falcon platform automates detection and prevention capabilities in real time across our entire global customer base.
+Added: Our Falcon platform consists of our easily deployed, intelligent lightweight sensor, and our Enterprise Graph, which unifies our ground-breaking graph technologies into a single, connected intelligence layer.
+Added: Our single, lightweight-sensor approach has changed how organizations experience cybersecurity, delivering protection without impacting the user, resources or productivity.
+Added: With the lightweight sensor installed on each endpoint and cloud workload, our Falcon platform automates detection and prevention capabilities in real time across our entire global customer base.
This also enables our Falcon platform to intelligently ingest data once and stream high fidelity data back into the Security Cloud to be re-used for multiple use cases, continuously improve our Falcon platform’s AI algorithms and make its real-time decision-making faster and smarter to keep customers ahead of changing adversary tactics.
−Removed: Our graph technology correlates and contextualizes the vast data of our Security Cloud so we can collect data once and reuse it repeatedly to deliver solutions that solve our customers’ biggest problems.
+Added: Our Enterprise Graph correlates and contextualizes the vast data of our Security Cloud to transform raw signals into authoritative security context, enabling us to collect data once and reuse it repeatedly to support real-time detection, investigation, and response across the platform.
+Added: By creating a living, connected model of the enterprise, the Enterprise Graph makes signals immediately actionable by both AI-driven workflows and human analysts.
The highly advanced graph technologies underpinning the Falcon platform include:
4 unchanged sentences
• Our Asset Graph, which dynamically monitors and tracks the complex interactions among assets, providing a single holistic view of the risks those assets pose.
−Removed: Asset Graph provides graph visualizations of the relationships among all assets such as devices, users, accounts, applications, cloud workloads and operations technology (“OT”), along with the rich context necessary for proper security hygiene and proactive security posture management to reduce risk in their organizations — without impacting IT.
+Added: Asset Graph provides graph visualizations of the relationships among all assets such as devices, users, accounts, applications, cloud workloads and operations technology, along with the rich context necessary for proper security hygiene and proactive security posture management to reduce risk in their organizations - without impacting IT.
The Falcon platform was purpose-built with the foresight that the future of cybersecurity would need to be cloud-native and AI-driven.
10 unchanged sentences
These include:
−Removed: • The Increasing Sophistication and Disruption of Cybersecurity Threats :
+Added: • The Increasing Speed, Sophistication and Disruption of Cybersecurity Threats :
Adversary sophistication continues to increase as militaries and intelligence services of well-funded nation-states, technically advanced criminal organizations and hackers advance their tactics.
−Removed: In addition, the commoditization of technologies like generative AI make it easier for low-skilled adversaries to move faster and launch more sophisticated attacks.
+Added: In addition, the commoditization of technologies like generative AI makes it easier for low-skilled adversaries to move faster and launch more sophisticated attacks.
This includes non-malware based attacks like social engineering that exploit user identities and credentials.
4 unchanged sentences
At this stage in the threat lifecycle, the adversary is able to encrypt, destroy, or silently exfiltrate sensitive data.
−Removed: • An Expanded Attack Surface Driven By Hybrid and Remote Workforces :
+Added: • An Expanded Attack Surface Driven By Cloud, AI and Distributed Environments :
Organizations everywhere are embracing digital transformation and are becoming more distributed as they adopt the cloud, increase workforce mobility, and grow their number of connected devices.
3 unchanged sentences
Trained cybersecurity professionals are in high demand, and organizations continue to face a dire shortage of talent to fill much needed cybersecurity positions.
−Removed: As a result, existing cybersecurity teams are often overwhelmed by the velocity of cyberattacks.
−Removed: Adversaries exploit this vacuum by continuing to accelerate their sophisticated attacks.
+Added: As a result, existing cybersecurity teams are often overwhelmed by the velocity of cyberattacks and the operational burden created by fragmented tools, siloed data, and high volumes of low-fidelity alerts that require manual investigation and correlation across multiple systems.
+Added: Adversaries exploit this complexity by accelerating attacks, while AI-enabled techniques compress response windows, increasing the need for automation and AI-driven security execution to keep pace.
• The Need to Reduce Complexity and Simplify Security Operations :
7 unchanged sentences
On-premise products are siloed, lack integration, and have limited ability to collect, process, and analyze vast amounts of data—attributes that are required to be effective in today’s increasingly dynamic threat landscape.
−Removed: Meanwhile, these solutions often require more agents on the endpoint as new capabilities are patchworked together, which can have a dramatic negative impact on user performance.
+Added: Meanwhile, these solutions often require more sensors on the endpoint as new capabilities are patchworked together, which can have a dramatic negative impact on user performance.
Many on-premise vendors have tried to solve this problem by simply extending on-premise products to the cloud.
12 unchanged sentences
These attacks involve malware built for the specific purpose of performing malicious activities, stealing data, or destroying systems.
−Removed: Our 2024 Global Threat Report observed that over 70% of attacks comprise non-malware, hands-on-keyboard activity.
−Removed: Additionally, we found that eight out of 10 attacks involve compromised or stolen credentials, with these identity-based attacks easily able to bypass legacy approaches to protection.
+Added: Our 2026 Global Threat Report observed that 82% of detections were malware-free.
Therefore, a malware-centric defensive approach will leave the organization vulnerable to attacks that do not leverage malware.
11 unchanged sentences
We believe that the cloud-native architecture of the Falcon platform and Security Cloud provides a sustainable advantage in addressing the needs of our customers as their businesses and the threat landscape continues to evolve.
−Removed: We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed, and multi-agent security products in a single solution.
+Added: We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed, and multi-sensor security products in a single solution.
We also allow thinly-stretched security organizations to automate previously manual tasks, freeing them to focus on their most important objectives.
−Removed: With the Falcon platform, organizations can transform how they combat threats, transforming from slow, manual, and reactionary to fast, automated, and predictive, while gaining visibility across the threat lifecycle.
+Added: With the Falcon platform, organizations can transform how they combat threats, evolving from slow, manual, and reactionary to fast, automated, and predictive, while gaining visibility across the threat lifecycle.
Key benefits of our approach and the CrowdStrike Falcon platform include:
2 unchanged sentences
As more high fidelity data is fed into our Security Cloud, our AI models continue to train and improve, increasing the overall efficacy of the Falcon platform.
−Removed: This unique data layer is powered and turned into action by three complementary graph databases (Threat Graph, Intel Graph, and Asset Graph) to put threats, adversaries, and assets into the context needed to make the rapid, informed decisions that stop breaches.
+Added: This unique data layer is powered and turned into action by the Enterprise Graph.
+Added: Enterprise Graph unifies our pioneering graph technologies (including Threat Graph, Intel Graph, and Asset Graph) into a living, connected model of the enterprise.
+Added: This makes signals instantly actionable by both AI agents and human analysts to put threats, adversaries, and assets into the context needed to make the rapid, informed decisions that stop breaches.
• Driving AI Innovation and Security :
1 unchanged sentence
The Falcon platform’s AI-native architecture uses advanced models and the power of the Security Cloud to detect and stop breaches, while innovations like Charlotte AI represent a significant advancement in agentic AI—delivering autonomous security decisions within customer-defined guardrails to triage detections, reduce noise, and accelerate response.
−Removed: Charlotte AI, powered by high-fidelity data and continual training, reduces routine investigation workloads, bridging critical skills gaps for stretched teams.
+Added: Charlotte AI, powered by high-fidelity data and continual training, reduces routine investigation workloads, bridging critical skills gaps for
+Added: stretched teams.
As AI continues to evolve, CrowdStrike is driving the next generation of AI-powered agentic cybersecurity—enabling AI to act independently while ensuring human oversight and control.
−Removed: Beyond delivering AI-driven protection, we also secure the AI systems organizations depend on, helping customers safeguard generative AI applications, protect sensitive data, and mitigate the risks posed by AI misconfigurations and vulnerabilities.
+Added: Beyond delivering AI-driven protection, we also secure the AI systems organizations depend on, helping customers safeguard generative AI applications and agents, protect sensitive data, and mitigate the risks posed by AI misconfigurations and vulnerabilities.
By advancing AI innovation and security, we empower organizations to stay ahead of adversaries, increase operational efficiency, and securely embrace the AI-driven future.
4 unchanged sentences
Our cloud-native platform gives customers a unified approach to address their most critical areas of risk seamlessly.
−Removed: We empower customers to rapidly deploy and scale industry leading technologies across Endpoint Security, Identity Protection, Cloud Security, Next-Gen SIEM and Modern Log Management, Data Protection, Exposure Management, IT Automation, ITSecOps and Risk, Threat Intelligence, and SaaS Security Posture Management from a single platform.
−Removed: • Reducing Agent Bloat :
−Removed: Our single intelligent lightweight agent enables frictionless deployment of our platform at scale, enabling customers to rapidly adopt our technology across any type of workload running on a variety of endpoints.
−Removed: The agent is non-intrusive to the end user, requires no reboots and continues to protect the endpoint and track activity even when offline.
−Removed: Through our single lightweight agent approach, customers can adopt multiple platform modules to address their critical areas of risk without burdening the endpoint with multiple agents.
−Removed: Legacy approaches often require multiple agents as they layer on new capabilities.
+Added: We empower customers to rapidly deploy and scale industry leading technologies across Endpoint and Workspace Security, Identity Protection, Cloud Security, Next-Gen SIEM and Modern Log Management, Data Protection, Exposure Management, IT Automation, ITSecOps and Risk, Threat Intelligence, and SaaS Security Posture Management from a single platform.
+Added: • Reducing Sensor Bloat :
+Added: Our single intelligent lightweight sensor enables frictionless deployment of our platform at scale, enabling customers to rapidly adopt our technology across any type of workload running on a variety of endpoints.
+Added: The sensor is non-intrusive to the end user, requires no reboots and continues to protect the endpoint and track activity even when offline.
+Added: Through our single lightweight sensor approach, customers can adopt multiple platform modules to address their critical areas of risk without burdening the endpoint with multiple sensors.
+Added: Legacy approaches often require multiple sensors as they layer on new capabilities.
This can severely impact user performance and create barriers to security.
1 unchanged sentence
Our cloud-native platform was built to rapidly scale industry leading protection across the entire enterprise, eliminating lengthy implementation periods and professional services engagements that next-gen and legacy competitors may require.
−Removed: Our single agent, collect once and re-use many times approach enables us to activate new modules in real time.
+Added: Our single sensor, collect once and re-use many times approach enables us to activate new modules in real time.
• Elite Security Teams as a Force Multiplier :
6 unchanged sentences
Because our world-class team can see attacks across our entire customer base, their expertise is enhanced by their constant visibility into the threat landscape.
−Removed: Additionally, the insights of our OverWatch team can then be leveraged by the Falcon platform to further enhance its autonomous capabilities, creating a positive feedback loop for our customers.
+Added: Furthermore, these elite security teams (including Falcon Complete, Falcon Overwatch, and our Professional Services teams) are key ingredients into the development of our automation and AI systems.
+Added: New and increasingly sophisticated models are developed, benchmarked, and validated using data distilled from their operations.
+Added: As these models gain capabilities and efficacy, our elite teams become more efficient in dealing with existing threats, which in turn allows for more focus on emerging and novel threats, which further enhances their models and automation systems, creating a positive feedback loop and data flywheel for our customers.
• Alleviating the Skills Shortage through Automation :
CrowdStrike automates manual tasks to free security teams to focus on their most important job – stopping the breach.
−Removed: Our Falcon Fusion capability automates workflows to reduce the need to switch between different security tools and tasks, while our Falcon Insight XDR module provides a unified solution that enables security teams to rapidly and efficiently identify, hunt, and eliminate threats across multiple security domains using first and third party datasets.
+Added: Our Falcon Fusion capability automates workflows to reduce the need to switch between different security tools and tasks, while our Falcon Insight XDR and Falcon Next-Gen SIEM modules provide a unified solution that enables security teams to rapidly and efficiently identify, hunt, and eliminate threats across multiple security domains using first and third party datasets.
• Lower Total Cost of Ownership :
4 unchanged sentences
Endpoint and Cloud workloads, Identity Threat Protection and Data Protection.
−Removed: Approximately eighty percent of breaches today use stolen credentials and identities.
+Added: According to the CrowdStrike 2026 Global Threat Report, 82% of detections in 2025 were malware-free, reflecting a sustained shift toward hands-on-keyboard operations, abuse of legitimate tools, and credential-driven movement that are difficult to distinguish from normal use behavior.
Stopping these advanced attacks requires a holistic approach that delivers true end-to-end protection across workloads, identities, and data.
CrowdStrike is able to natively enforce protection at the device layer, the identity layer, and the data layer, extending our bold vision for security by driving modern Defense in Depth to the enterprise.
−Removed: By delivering these powerful capabilities through a unified platform with a single agent, CrowdStrike is able to connect the endpoint and workload to user identity, and the data that is being used and accessed.
+Added: By delivering these powerful capabilities through a unified platform with a single sensor, CrowdStrike is able to connect the endpoint and workload to user identity, and the data that is being used and accessed.
Customers can see the full health and state of endpoints and workloads, in context with the identity that is using and accessing them, aligned with where data is being created, who is using it, where it flows and how it is protected.
6 unchanged sentences
Our Falcon platform is composed of two tightly integrated proprietary technologies:
−Removed: our lightweight agent and our Security Cloud.
−Removed: Our cloud-delivered modules integrate seamlessly within the Falcon platform to provide customers with a unified set of cloud-delivered technologies across Endpoint Security, Identity Protection, Cloud Security, Next-Gen SIEM and Modern Log Management, Data Protection, Exposure Management, IT Automation, ITSecOps and Risk, Threat Intelligence, and SaaS Security Posture Management.
+Added: our lightweight sensor and our Security Cloud.
+Added: Our cloud-delivered modules integrate seamlessly within the Falcon platform to provide customers with a unified set of cloud-delivered technologies across Endpoint and Workspace Security, Identity Protection, Cloud Security, Next-Gen SIEM and Modern Log Management, Data Protection, Exposure Management, IT Automation, ITSecOps and Risk, Threat Intelligence, and SaaS Security Posture Management.
The Falcon platform also encompasses recently acquired technologies where integration may be ongoing.
−Removed: We can rapidly and cost effectively develop and deliver additional cloud modules on our Falcon platform without the need for additional agents, and are expanding options for our new customers to test modules on a trial basis as well as offering in-application trials for existing customers.
+Added: We can rapidly and cost effectively develop and deliver additional cloud modules on our Falcon platform without the need for additional sensors, and are expanding options for our new customers to test modules on a trial basis as well as offering in-application trials for existing customers.
Our expanding set of open APIs and the Foundry app development platform allow customers and partners to build their own capabilities on top of the Falcon platform.
2 unchanged sentences
Unified Security Across Major Categories
−Removed: Our cloud-native Falcon platform integrates seamlessly with our single lightweight agent to deliver robust functionality across key areas of cybersecurity and IT operations.
−Removed: The Falcon platform delivers 29 cloud modules, enabling customers to address their most critical areas of risk with speed, confidence, and visibility through one unified platform.
+Added: Our cloud-native Falcon platform integrates seamlessly with our single lightweight sensor to deliver robust functionality across key areas of cybersecurity and IT operations.
+Added: The Falcon platform delivered 32 cloud modules as of January 31, 2026 and currently delivers 33 cloud modules, enabling customers to address their most critical areas of risk with speed, confidence, and visibility through one unified platform.
Key areas of focus include:
10 unchanged sentences
Real-time insights and guided actions empower customers to address vulnerabilities before they can be exploited.
−Removed: Managed Services Subscription :
−Removed: Falcon Complete Next-Gen Managed Detection and Response (“MDR”) delivers a comprehensive managed security service subscription that combines 24/7 expert monitoring, investigation, response, and remediation to stop breaches across the entire attack lifecycle.
+Added: Managed Detection and Response (“MDR”) :
+Added: Falcon Complete Next-Gen MDR delivers a comprehensive managed security service subscription that combines 24/7 expert monitoring, investigation, response, and remediation to stop breaches across the entire attack lifecycle.
Delivered by CrowdStrike’s team of security experts and powered by the AI-native Falcon platform, it combines industry-leading endpoint protection and extends managed protection across cloud security, identity protection, asset visibility, and Next-Gen SIEM, with 24/7 managed threat hunting from Falcon Adversary OverWatch for a full-stack MDR service.
7 unchanged sentences
Next-Generation SIEM and Log Management :
−Removed: CrowdStrike’s Next-Gen SIEM and log management solutions deliver AI-driven detection, investigation, and response capabilities, alongside high-performance log management for any data source.
+Added: CrowdStrike’s Next-Gen SIEM and log management solutions deliver AI-driven detection, advanced data pipelining, centralized case management, investigation, and response capabilities, alongside high-performance log management for any data source.
This comprehensive approach enhances security operations and enables organizations to respond to threats with speed and precision.
Generative AI :
−Removed: Innovations like Charlotte AI leverage generative AI and natural language processing to automate time-intensive tasks, enabling security analysts to work more efficiently.
+Added: Innovations like Charlotte AI leverage generative AI and agentic reasoning to automate time-intensive tasks, enabling security analysts to work more efficiently.
Charlotte AI transforms hours of routine investigation into minutes, addressing critical skills gaps and enhancing operational efficiency.
Powered by the Falcon platform’s unique data advantage, Charlotte continues to evolve, delivering time savings and workflow automation to meet the demands of modern security operations.
+Added: Securing AI :
+Added: The Falcon platform provides comprehensive security from emerging threats and new attack surfaces for organizations implementing their own generative AI services and applications.
+Added: AI Detection and Response (“AIDR”) provides visibility and governance into how employees use AI and how AI agents operate by mapping relationships between users, prompts, models, agents, and Model Context Protocol (“MCP”) servers, and enforcing policy across these relationships.
+Added: Unstructured data is analyzed for malicious actions such as prompt injection, and sensitive data can be automatically redacted to keep AI interactions safe and compliant.
IT Automation :
10 unchanged sentences
Bringing CrowdStrike to the Market
−Removed: We primarily sell the Falcon platform through our direct sales team that leverages our network of channel partners to maximize effectiveness and scale.
+Added: We primarily sell the Falcon platform through our sales and partner teams that leverage our network of channel partners to maximize effectiveness and scale.
We have a low friction land-and-expand sales strategy.
2 unchanged sentences
Given the limitations of existing legacy and other endpoint security products, many organizations are replacing their existing legacy and other endpoint security products with our Falcon platform.
−Removed: We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Prevent that is easily downloaded from our website and AWS Marketplace.
+Added: We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Go that is easily downloaded from our website, the AWS Marketplace, the Google Marketplace, and the Microsoft Marketplace.
+Added: We also increasingly work with Managed Service Providers (“MSPs”), and Managed Security Service Providers (“MSSPs”), who operate the Falcon platform on a customer’s behalf, acting as an outsourced security team to manage risk, products, and outcomes for customers.
• Further Penetrating Existing Customers.
Our growth will depend in part on our ability to continue to expand our relationships with our customers by deploying on additional endpoints in their environment and cross-selling more cloud modules.
−Removed: When customers deploy our lightweight agent, they can easily add additional cloud modules.
+Added: When customers deploy our lightweight sensor, they can easily add additional cloud modules.
We also offer in-application trial usage of additional modules to cross-sell to existing customers.
5 unchanged sentences
For example, Falcon Discover includes use cases outside of security, such as application license management, AWS spend analysis, and asset inventory.
−Removed: Because our lightweight agent collects diverse endpoint data once for repeated use, we can expand our addressable market by rapidly adding new cloud modules that leverage this data.
+Added: Because our lightweight sensor collects diverse endpoint data once for repeated use, we can expand our addressable market by rapidly adding new cloud modules that leverage this data.
We intend to continue to develop new cloud modules for broader endpoint use cases.
23 unchanged sentences
We plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us.
+Added: We also endeavor to work with more partners, new partner types, new technology companies, and new service providers to help more customer segments and new customers realize novel outcomes from the Falcon Platform.
We have designed an innovative architecture from the ground up to overcome the limitations of existing security products and deliver cloud-based solutions.
5 unchanged sentences
As customer adoption grows, the network effect of each additional endpoint added to the Falcon platform will amplify the breadth and depth of our dataset and intelligence.
−Removed: Falcon Agent.
−Removed: We designed an intelligent lightweight agent that is installed on each endpoint or cloud workload.
−Removed: This agent incorporates identification and prevention of known and unknown malware and fileless attacks using machine learning, AI, exploit blocking, and advanced behavioral techniques, to protect workloads across all endpoints while capturing and recording high fidelity endpoint data.
−Removed: Our agent is capable of acting autonomously and continues to collect data and protect workloads running on endpoints even when offline.
−Removed: The agent recommences transmitting data to our Falcon platform when the connection to the cloud has been re-established.
−Removed: Our lightweight agent is built to support Windows, Mac, and Linux operating systems.
−Removed: The agent is hardened against attacks and uses a combination of kernel and user-mode modules to collect and transmit high fidelity endpoint events as they take place on a system.
+Added: Falcon Sensor.
+Added: We designed an intelligent lightweight sensor that is installed on each endpoint or cloud workload.
+Added: This sensor incorporates identification and prevention of known and unknown malware and fileless attacks using machine learning, AI, exploit blocking, and advanced behavioral techniques, to protect workloads across all endpoints while capturing and recording high fidelity endpoint data.
+Added: Our sensor is capable of acting autonomously and continues to collect data and protect workloads running on endpoints even when offline.
+Added: The sensor recommences transmitting data to our Falcon platform when the connection to the cloud has been re-established.
+Added: Our lightweight sensor is built to support Windows, Mac, and Linux operating systems.
+Added: The sensor is hardened against attacks and uses a combination of kernel and user-mode modules to collect and transmit high fidelity endpoint events as they take place on a system.
It correlates these events using a local situational model on the endpoint, analyzes via agent-based AI models and is capable of taking a variety of preventative and responsive actions on the endpoint, either automatically or via human control.
−Removed: Events are streamed by the agent to the cloud in real time in order to be further analyzed in the Threat Graph, where additional correlation and AI algorithms can be applied.
−Removed: The agent is also capable of being remotely reconfigured in real time based on analytics in our cloud platform to collect and analyze different events or take other actions as risk and threat postures change.
+Added: Events are streamed by the sensor to the cloud in real time in order to be further analyzed in the Threat Graph, where additional correlation and AI algorithms can be applied.
+Added: The sensor is also capable of being remotely reconfigured in real time based on analytics in our cloud platform to collect and analyze different events or take other actions as risk and threat postures change.
Threat Graph.
12 unchanged sentences
High Fidelity Data and Smart Filtering.
−Removed: The presence of a local graph model in our agent enables it to track the state of the machine in real time, perform rapid machine learning and behavioral analysis, and provide efficient event streaming to the cloud.
−Removed: We call this “smart filtering.” This allows us to keep performance overhead on the endpoint to a minimum, dramatically reduce the bandwidth required for agent-cloud communication, efficiently process large volumes of data, and separate signals from noise.
−Removed: The Falcon agent collects and analyzes unfiltered data with local machine learning and behavioral algorithms on the endpoint but only streams high fidelity endpoint events to the cloud to just send what is necessary for detection, prevention and investigation of attacks.
+Added: The presence of a local graph model in our sensor enables it to track the state of the machine in real time, perform rapid machine learning and behavioral analysis, and provide efficient event streaming to the cloud.
+Added: We call this “smart filtering.” This allows us to keep performance overhead on the endpoint to a minimum, dramatically reduce the bandwidth required for sensor-cloud communication, efficiently process large volumes of data, and separate signals from noise.
+Added: The Falcon sensor collects and analyzes unfiltered data with local machine learning and behavioral algorithms on the endpoint but only streams high fidelity endpoint events to the cloud to just send what is necessary for detection, prevention and investigation of attacks.
This smart filtering architecture allows us to reduce network load for our customers.
20 unchanged sentences
• Incident Response, Forensics, and Recovery Services.
−Removed: Our incident response services typically begin by deploying our lightweight agent to a customer’s endpoints or cloud workloads to provide visibility in order to determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done.
+Added: Our incident response services typically begin by deploying our lightweight sensor to a customer’s endpoints or cloud workloads to provide visibility in order to determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done.
In addition to enriching the response team’s understanding of the attack, the full suite of Falcon platform’s next-gen prevention capabilities, cloud security, exposure management, and identity protection offerings can also be leveraged to help to slow down and prevent an active attacker from moving at-will throughout a compromised customer’s environment, increasing the risk and potential damage to the customer.
We also provide customized surgical recovery services by providing the tools and staffing to eject attackers out of the network, lock down credentials from further use, remediate impacted systems and ensure adversaries stay out.
−Removed: In addition to providing valuable breach remediation to our customers, our incident response services also act as a strong lead generation engine for our Falcon platform and cloud modules.
+Added: In addition to providing valuable breach remediation to our customers, our incident response services also act as a strong lead generation engine for our Falcon platform, cloud, identity, Next-Gen SIEM, and many other modules.
After experiencing the benefits of our platform firsthand, many of our incident response customers become subscription customers.
−Removed: • Technical Assessment and Strategic Advisory Services .
−Removed: Our proactive security services include technical assessment services designed to help organizations understand their cyber maturity levels.
−Removed: These services include both endpoint and cloud workload compromise assessments, cybersecurity maturity assessments, security program in-depth assessments, service organization control assessments, IT hygiene assessments, and active directory security assessments.
−Removed: We also advise customers on readiness and preparation through the execution of table-top exercises, live fire exercises, red team/blue team assessments, and advanced adversary emulation exercises.
−Removed: We have also added AI red-teaming to help organizations understand where these models can have risk, where they can be exploited and where to take corrective security actions.
+Added: • Consulting Services.
+Added: Our proactive consulting security services include technical assessment and strategic advisory services designed to help organizations understand their cyber maturity levels.
+Added: These services include endpoint, identity, and cloud workload compromise assessments, cybersecurity maturity assessments, security program in-depth assessments, service organization control assessments, IT hygiene assessments, and active directory security assessments.
+Added: We advise customers on readiness and preparation through the execution of table-top exercises, live fire exercises, red team/blue team assessments, and advanced adversary emulation exercises.
+Added: We also offer AI red-teaming and other AI security services to help organizations understand where these emerging models introduce cyber risk, where they can be exploited, and where to take corrective security actions.
All of these services are designed to evaluate our customers’ security profile so they can identify areas of vulnerability, secure their network, and improve their response if their defenses are breached.
−Removed: Our services also align to executive and board level cybersecurity training and awareness, including by helping public companies more confidently comply with public disclosure requirements relating to assessing, identifying and managing material cybersecurity risks, and reporting material cyber incidents.
−Removed: Our programs are designed to help organizations effectively achieve cybersecurity risk reduction objectives and to maximize investments.
−Removed: • NextGen SIEM Professional Services.
−Removed: Our NG-SIEM professional services offer a comprehensive suite of deployment packages and ongoing support options designed to help organizations seamlessly implement and optimize the Falcon NG-SIEM platform.
−Removed: Our Essentials, Advanced, and Premium Deployment Packages provide standardized implementations that prioritize data ingestion aligned with critical use cases from the MITRE ATT&CK framework, ensuring maximum impact in detecting and responding to threats.
−Removed: For customers requiring deeper, hands-on expertise, we offer Resident Engineer Services in flexible durations of 3, 6, or 12 months supporting both NG-SIEM as well as LogScale.
−Removed: These experts embed directly with customer teams to provide tailored guidance, ongoing optimization, and support for evolving security needs.
+Added: Our services also align to executive and board level cybersecurity priorities and are designed to help organizations effectively achieve cybersecurity risk reduction objectives and to maximize investments.
+Added: • Platform Professional Services.
+Added: Our platform deployment and operational services are designed to help customers maximize the value of their investment in the CrowdStrike Falcon platform and transform their Security Operations Centers.
+Added: These services provide seamless deployment of Falcon modules across endpoint, cloud, identity, Next-Gen SIEM and virtually every other module ensuring rapid time-to-value and alignment to CrowdStrike’s recommended security configurations to prevent breaches.
+Added: For customers requiring deeper, hands-on expertise, we offer Resident Services with experts embedded directly with customer teams to provide tailored guidance, ongoing optimization, and support for evolving security needs.
Our services are designed to accelerate time-to-value, enhance security posture, and ensure the long-term success of SIEM deployments within any organization.
−Removed: • Platform Deployment and Operational Services.
−Removed: Our deployment and operational services are designed to help customers maximize the value of their investment in the CrowdStrike Falcon platform.
−Removed: These services provide seamless deployment of Falcon modules across endpoint, cloud, identity, Next-Gen SIEM and many other modules ensuring rapid time-to-value and alignment to CrowdStrike’s recommended security configurations to prevent breaches.
−Removed: Our integration services focus on enabling customers to align Falcon modules with their existing security ecosystems, leveraging our APIs and Falcon Fusion SOAR automation for improved operational efficiency.
Additionally, our operational services provide tailored guidance and best practices to optimize platform performance, streamline workflows, and address specific cybersecurity challenges.
3 unchanged sentences
CrowdStrike University is an online learning management system that organizes all CrowdStrike e-learning, instructor-led training and certification preparation courses in one place, providing a personalized learning experience for individuals who have an active training subscription.
−Removed: CrowdStrike currently offers proctored exam certifications through industry leading training partner Pearson Vue for its CrowdStrike Certified Falcon Administrator, CrowdStrike Certified Falcon Responder, CrowdStrike Certified Falcon Hunter, CrowdStrike Certified Cloud Specialist, and CrowdStrike Certified Identity Specialist programs.
−Removed: We provide comprehensive training and certification programs to empower customers and partners with the knowledge and skills needed to maximize the value of CrowdStrike technologies and strengthen their cybersecurity expertise.
−Removed: CrowdStrike University provides a centralized, online platform for accessing a wide range of training options including on-demand e-learning, instructor-led training, and certification preparation.
−Removed: Our offerings are designed to accommodate varying levels of proficiency from foundational concepts to advanced skills in threat detection, incident response, cloud security, intelligence and other proactive security operations aligned to the Falcon platform.
−Removed: Our CrowdStrike Certified Falcon Administrator, Responder, Hunter, Cloud Specialist, and Identity Specialist certifications validate the skillsets of our customers and partners to ensure they are properly equipped to operate the Falcon platform.
+Added: CrowdStrike currently offers proctored exam certifications through industry leading training partner Pearson Vue for our CrowdStrike Certified Falcon Administrator, Falcon Responder, Falcon Hunter, Cloud Specialist, Identity Specialist, and Next-Gen SIEM Engineer programs.
+Added: Our offerings are designed to accommodate varying levels of proficiency from foundational concepts to advanced skills in threat detection, incident response, cloud security,
+Added: intelligence and other proactive security operations aligned to the Falcon platform.
Our training offerings provide a structured learning path to accelerate CrowdStrike adoption, drive operational success, and equip professionals with validated expertise in modern cybersecurity practices.
Some of the world’s largest enterprises, government organizations, and high-profile brands trust us to protect their business.
−Removed: As of January 31, 2025, we are trusted by more than 74,000 organizations, including our end customers and those of our Managed Security Service Providers (“MSSP”), worldwide.
+Added: As of January 31, 2026, we are trusted by more than 88,000 organizations, including our end customers and those of our Managed Security Service Providers (“MSSPs”), worldwide.
Historically, we and our channel partners have primarily sold to large organizations, but have increasingly focused on selling to small and medium-sized businesses, particularly through our trial-to-pay model.
16 unchanged sentences
We partner with a diverse set of partners.
−Removed: We work with a wide array of go-to-market partners in our technology alliance partners to design go-to-market strategies that combine our platform with products or services provided by our technology alliance partners.
+Added: We work with a wide array of go-to-market partners in our technology alliance partners to design go-to-market strategies that combine our platform with products and/or services provided by our technology alliance partners.
These partner integrations deliver more secure solutions and an improved end user experience to their customers.
Our technology alliance partnerships focus on security analytics, network and infrastructure security, threat platforms and orchestration, and automation.
−Removed: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications.
−Removed: In addition, Falcon for AWS, available in the AWS Marketplace, allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
+Added: The CrowdStrike Store is an open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications.
+Added: Falcon for AWS, available in the AWS Marketplace, allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
+Added: In addition to AWS, we bring CrowdStrike to market through Google Marketplace, and starting fiscal year 2027, the Microsoft Marketplace.
+Added: We work with a vast network of resellers, distributors, MSSPs, MSPs, and global system integrators (“GSIs”) to deliver diverse customer experiences, tailored to the needs of the
+Added: Our best-in-class ecosystem helps us source new logos, expand within existing accounts, and maintain high renewal rates because we meet customers where they are and work with those they trust.
Research and Development
9 unchanged sentences
In addition, we engage security consulting firms to perform periodic vulnerability analysis of our solutions.
−Removed: Our research and development leadership team is located in Seattle, Washington and Sunnyvale, California.
−Removed: We also maintain research and development centers in Irvine, California, Minneapolis, Minnesota, Bucharest, Romania, Israel and India.
+Added: Our research and development leadership team is predominantly located in the United States.
+Added: We also maintain research and development centers internationally, including in Romania, Israel and India.
We employ subject matter experts in a number of jurisdictions around the world.
1 unchanged sentence
We primarily compete with established and emerging security product vendors.
−Removed: While the market for traditional endpoint and IT operations solutions has historically been intensely competitive, we believe that the architecture of our cloud-native, single agent platform fundamentally differentiates us compared to both next-gen and legacy competitors in the security industry.
+Added: While the market for traditional endpoint and IT operations solutions has historically been intensely competitive, we believe that the architecture of our cloud-native, single sensor platform fundamentally differentiates us compared to both next-gen and legacy competitors in the security industry.
Additionally, as we look to enter into adjacent markets and expand our total addressable market, we may face new competitors.
25 unchanged sentences
We intend to continue pursuing additional intellectual property protection to the extent we believe it would be beneficial and cost-effective.
−Removed: Despite our efforts to protect our intellectual property rights, they may not be respected in the future or may be invalidated, circumvented, or challenged.
+Added: Despite our efforts to protect our intellectual property rights, they may not be respected in the future, particularly in certain foreign jurisdictions where laws may not protect our proprietary rights as fully as in the United States, or may be invalidated, circumvented, or challenged.
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights.
11 unchanged sentences
We expect backlog will change from period to period for several reasons, including the timing and duration of customer agreements, varying billing cycles of subscription agreements, and the timing and duration of customer renewals.
−Removed: Because revenue for any period is a function of revenue recognized from deferred revenue under contracts in existence at the beginning of the period, as well as contract renewals and new customer contracts during the period, backlog at the beginning of any period is not necessarily indicative of future revenue performance.
+Added: Because revenue for any period is a function of revenue recognized from deferred revenue under contracts in
+Added: existence at the beginning of the period, as well as contract renewals and new customer contracts during the period, backlog at the beginning of any period is not necessarily indicative of future revenue performance.
We do not utilize backlog as a key management metric internally.
22 unchanged sentences
• Flexible working arrangements
−Removed: • Role and task diversity
+Added: • Roles and tasks designed for growth
• Professional development opportunities
24 unchanged sentences
Podbere 60 Chief Financial Officer
−Removed: Shawn Henry 62 Chief Security Officer
Michael Sentonas 52 President
22 unchanged sentences
from McGill University.
−Removed: Shawn Henry - Chief Security Officer
−Removed: Henry has served as our Chief Security Officer since March 2012.
−Removed: From March 2012 to October 2022, Mr.
−Removed: Henry also served as President of CrowdStrike Services.
−Removed: Henry previously worked for the FBI from 1987 through March 2012, including most recently as Executive Assistant Director of the FBI’s Criminal, Cyber, Response and Services Branch.
−Removed: Since June 2016, Mr.
−Removed: Henry has served as a faculty member specializing in cybersecurity for the National Association of Corporate Directors, an organization providing training and education for private and public company directors.
−Removed: Henry previously served as a cybersecurity and national security analyst for NBC News.
−Removed: Since November 2021, Mr.
−Removed: Henry has served as a director of ShoulderUp Technology Acquisition Corp., a blank check company that completed its initial public offering in
−Removed: November 2021.
−Removed: Henry also serves on the board of directors of CLEAR, a technology identity company, and served on the board of Global Cyber Alliance, a nonprofit organization dedicated to reducing cyber risk, from 2015 to December 2024.
−Removed: Additionally, Mr.
−Removed: Henry serves on the advisory boards of several organizations.
−Removed: Henry holds a B.B.A.
−Removed: from Hofstra University and an M.S.
−Removed: in criminal justice from Virginia Commonwealth University.
Michael Sentonas - President
20 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.