Cyber News / Article / CrowdStrike Delivers the Next Evolution of the Agentic SOC

CrowdStrike Delivers the Next Evolution of the Agentic SOC
September 02, 2026
The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to theCrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real time.
CrowdStrike is delivering new innovations with the next evolution of the agentic SOC, in which analysts and AI agents work together in a unified system.
In the legacy SOC, evidence lives in disconnected systems. Automation is split across separate interfaces and execution logs. Analysts toggle between tools and manually stitch together context. Only a subset of detections receives real investigation while everything else piles up as a structural blind spot.
But most security teams struggle to achieve an agentic SOC transformation, for three key reasons. First, fragmented data prevents cross-domain investigations. When context lives in separate tools and isn't AI-ready, agents can't connect the dots across identity, cloud, endpoint, SaaS, and network. Second, isolated agents reach incorrect or late verdicts. Because they work in silos with sequential handoffs, they see only a partial picture, which reverts the work back to analysts. Third, ungoverned automation creates breach points. Agents act in your environment and connect to your systems; if you can't build, monitor, and control them, you can't see what's running, what it's connected to, or what it costs.
CrowdStrike takes a different path. The CrowdStrike Falcon® platform is not just where agents run. It is where the data is generated, enriched, investigated, orchestrated, and governed.
At Fal.Con, CrowdStrike is delivering the next evolution of the agentic SOC, a production operating model where expert agents and analysts stop breaches as one system. New capabilities in the Falcon platform include:
See it in action: Coordinated expert agents investigate every domain at once and converge on a single verdict
Let’s take a closer look at what’s new.
The Falcon platform starts from native telemetry and extends outward, delivering petabytes of cross-domain data refined by elite security experts in one unified foundation. Teams decide what is ingested and what is federated, and critical first-party data has no ingestion cost. The result is agents with a complete view of their environment that is AI-ready from the start.
Third-party data traditionally depends on pipelines customers build and maintain themselves, with no guarantee that data lands complete or usable. A single dropped field or schema change can break a detection without anyone noticing. In an agentic SOC, where agents act on data automatically, that risk compounds.
CrowdStrike is closing this gap with new capabilities that optimize how third-party data gets in, what happens to it in flight, and whether teams can trust it when it lands. These include:
Certified data pipelines(Public Preview). Teams will get pre-built, pre-tested data flows that CrowdStrike validates and maintains, starting with Zscaler and Palo Alto Networks. Sources go live in hours and arrive detection-ready, so coverage starts when a new source is connected. There is no pipeline overhead to carry, and only security-relevant data reaches the platform.
Detection in the pipeline(Public Preview). Detection normally waits until data is ingested and normalized. With this new capability, detection logic will run inside the pipeline itself. Because pipelines can execute at the edge, threats are caught in transit, which reduces MTTD.
Agents need intelligent coordination that summons the right expertise at the right time. CrowdStrike now delivers out-of-the-box multi-agent workflows that coordinate teams of expert agents to accomplish tasks. These agents reason over shared context unique to each organization and sharpen their accuracy over time. These coordinated workflows span critical security operations, from investigations to digital risk protection.
New capabilities include:
Agentic investigations with shared context(Public Preview). When detections warrant an investigation, an orchestrator agent summons specialist agents, built and used every day byCrowdStrike Falcon® Completemanaged detection and response. These agents work across every associated domain and data source in parallel. They build on each other's findings through shared context and converge on a single verdict. From there, they drive the next step: clearing queues, or escalating with pre-assembled context for human review. Coverage no longer depends on who is available.
Watch the demo:
CrowdStrike's agents are shaped by two loops that compound over time. The first loop is global. Our agents are informed by millions of real detections from around the world and get sharper with every incident the Falcon Complete team stops.
Complementing that is a second, local loop. The same shared context layer that agents reason over during an investigation is where their learning accumulates. Every decision, correction, and resolution in a customer's environment is collected there, unique to that organization and accessible to all of their CrowdStrike agents. This improves agents’ accuracy over time.
With access to global expertise defeating adversaries anywhere, and local knowledge to operate fluently in a specific environment, CrowdStrike's agents continually improve accuracy and earn the trust to run at scale.
Building agents is one thing; operating them at scale is another.Charlotte Agentic SOARnow lets teams build and govern automation, both rule-based and agentic, in a single place with expanded flexibility.
New capabilities include:
The agentic SOC is the operating model that connects the data, detection, investigation, orchestration, and response capabilities already deployed across the Falcon platform. Agentic investigations, delivered through CrowdStrike Falcon® Next-Gen SIEM and powered by Charlotte AI, run on existing Falcon telemetry with no new sensors required. They draw on signals from CrowdStrike Falcon® Next-Gen Identity Security and CrowdStrike Falcon® Cloud Security alongside endpoint data.
Each layer makes the next stronger. Better data produces faster, more accurate investigations, which in turn permit more informed workflow decisions. Governed workflows turn intelligence into accountable action.
The value of AI in security is enabling every investigation to begin with the right data, reason across the full attack, and produce an outcome defenders can trust. Only CrowdStrike brings together native and third-party data, agents built by the experts who stop breaches every day, a context layer that learns each environment, and governed orchestration in one platform. The agentic SOC from CrowdStrike is the operating model modern security demands.
Forward-Looking Statements
This blog may include discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.
Try CrowdStrike free today
Sign up now to receive the latest notifications and updates from CrowdStrike
Related articles
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
8 days ago
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
9 days ago
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
9 days ago
You might Also like

New InjectEave Attack Allows Hackers to Recover Audio Playing on Headphones from 30 Meters

Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code Execution

