
CrowdStrike, a global leader in cybersecurity, announced its groundbreaking Threat AI system at Fal.Con 2025, marking a significant leap into the agentic era of threat intelligence. Integrated into the CrowdStrike Falcon platform, Threat AI automates complex workflows, enabling rapid threat detection and response while empowering analysts to focus on high-impact investigations.
CrowdStrike launches Threat AI, the first agentic threat intelligence system.
Automates malware analysis and proactive threat hunting with AI agents.
Features Malware Analysis and Hunt Agents for faster, actionable insights.
Includes a Chrome extension for real-time adversary intelligence access.
Tracks over 265 sophisticated threat groups, enhancing cybersecurity defenses.
Part of the Agentic Security Workforce, streamlining enterprise threat response.
CrowdStrike’s Threat AI, unveiled at Fal.Con 2025, introduces the industry’s first agentic threat intelligence system, designed to counter AI-accelerated cyberattacks. “Adversaries are weaponizing AI to accelerate every stage of attacks – what once took months can now happen in seconds, collapsing the defender’s window of response,” said Adam Meyers, head of Counter Adversary Operations at CrowdStrike. “Threat AI is the intelligence arm of CrowdStrike’s vision to equip every security analyst with mission-ready agents that eliminate high-friction tasks better suited for machines, ushering in a new era of threat intelligence.” By automating time-intensive tasks, Threat AI allows analysts to prioritize strategic investigations, enhancing enterprise cybersecurity.
Threat AI includes two initial agents: the Malware Analysis Agent and the Hunt Agent. The Malware Analysis Agent automates complex workflows like reversing and classifying malware, delivering instant attribution and generating YARA rules in seconds. The Hunt Agent proactively scans environments for emerging threats, providing clear, actionable insights. These agents, embedded in CrowdStrike’s Threat Intelligence & Hunting modules, leverage insights from tracking over 265 nation-state, eCrime, and hacktivist groups, ensuring rapid and precise threat response.
The Malware Analysis and Hunt Agents are the first in a series of planned Threat AI agents, with future additions to include triage, correlation, and exposure mapping. These agents are orchestrated to work collaboratively, enhancing each other’s outputs for comprehensive threat mitigation. This approach strengthens CrowdStrike’s Agentic Security Workforce, a vision to integrate AI-driven agents into frontline defense, keeping human analysts in command while automating routine tasks.
CrowdStrike also introduced a Chrome extension that integrates its adversary intelligence directly into analysts’ browsers. This tool provides immediate context during external research, speeding up investigations and response times. By embedding real-time insights into existing workflows, the extension enhances efficiency and decision-making for cybersecurity teams.
With adversaries leveraging AI to execute attacks at unprecedented speeds, Threat AI positions CrowdStrike as a leader in next-generation cybersecurity. The system’s ability to automate complex workflows and deliver actionable recommendations addresses the shrinking response windows faced by defenders. As part of the Falcon platform, Threat AI ensures rapid deployment and scalability, empowering enterprises to stay ahead of sophisticated threats.
CrowdStrike, a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data.
Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.
Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value.