The cybersecurity industry is rapidly evolving from static automation to intelligent, autonomous agents that can reason and act like human experts. Leading this shift, CrowdStrike has expanded its Agentic Security Workforce, introducing new mission-ready AI agents that extend the capabilities of the Falcon platform. Unlike automation trained on rigid playbooks, these agents are trained on the collective knowledge and decisions of elite analysts from the CrowdStrike Falcon Complete SOC. This approach enables the agents to bring true intelligence to common platform tasks, accelerating security outcomes and freeing human analysts to focus on strategic decisions.
CrowdStrike expanded its Agentic Security Workforce with new AI agents.
Agents are trained on expert human judgment, not static playbooks.
New agents automate Falcon platform tasks like app creation and data onboarding.
Charlotte AI AgentWorks allows for building custom, no-code agents.
Charlotte Agentic SOAR orchestrates CrowdStrike and third-party agents.
The goal is to create a fully connected, agentic Security Operations Center (SOC).
A key differentiator for CrowdStrike's agents is their training data. They learn from millions of real-world decisions made by operators in the Falcon Complete SOC, inheriting expert human judgment. This allows them to reason over massive datasets and take autonomous action as an elite analyst would. George Kurtz, CEO and founder of CrowdStrike, emphasized this distinction, stating, “playbooks train automation, people train intelligence. CrowdStrike’s agents learn from the world’s best SOC operators, giving them the judgment to act autonomously and the discipline to stay under defender command.”
The expansion includes several new and updated agents integrated directly into Falcon platform modules. The Foundry App Creation Agent allows analysts to build and deploy custom security applications using natural language, accelerating the path from idea to execution. The Data Onboarding Agent streamlines the process of ingesting and validating data into Falcon Next-Gen SIEM. The updated Exposure Prioritization Agent, powered by ExPRT.AI, now includes authenticated scanning and provides risk-based patching recommendations.
To manage this growing workforce, CrowdStrike introduced Charlotte AI AgentWorks and Charlotte Agentic SOAR. AgentWorks empowers organizations to build their own no-code, custom agents tailored to specific needs. Charlotte Agentic SOAR acts as the central orchestration layer, enabling analysts to command a unified team of CrowdStrike, custom, and third-party agents. This creates a coordinated defense system where agents can reason over shared context and execute complex, multi-step workflows autonomously.
CrowdStrike's expansion of its Agentic Security Workforce represents a significant leap toward the future of autonomous security operations. By grounding AI intelligence in real-world human expertise and providing the tools to orchestrate a diverse agentic ecosystem, CrowdStrike is empowering defenders to operate at machine speed and scale. This shifts the SOC from a reactive model to a proactive, intelligent, and coordinated defense capable of outmaneuvering modern, AI-accelerated threats.
CrowdStrike, a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data.
Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.
Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value.