CrowdStrike is expanding its Agentic SOC with coordinated, multi-agent investigations that simultaneously analyze endpoint, identity, SaaS, cloud, and network activity.
The approach is meant to replace more sequential AI-driven investigations with specialized agents that share context, work toward a common verdict, and help analysts evaluate threats faster as attacks move across multiple environments at machine speed.
CrowdStrike brings coordinated AI agents to the SOC
CrowdStrike’s approach uses specialized agents to investigate endpoint, identity, SaaS, cloud, and network activity simultaneously.
“In the first generation, the AI stock tools still approach this problem rather sequentially,” said Bartley Richardson, Chief AI and Autonomous Systems Officer, CrowdStrike. “Think about it in the flow of how a human would do it.”
“They investigate one domain, and the next, and the next. So CrowdStrike is bringing coordinated, multi-agent investigations into the SOC. And these are specialized agents that investigate endpoints, identity, SaaS, cloud, network, all at the same time,” Richardson continued.
Multi-agent investigations share context across security domains
The key distinction Richardson made is that the agents share context and work toward a common verdict rather than producing isolated findings that analysts must reconcile.
This is intended to make investigations both faster and easier for human analysts to evaluate.
“Agents working together on the same investigation, with the same context, towards the same verdict, in a very coordinated and parallel way. And that coordination matters, said Richardson. “This agent investigates one domain, trying to identify evidence within that domain. A coordinated group of agents can understand how that evidence connects across the entire stack.”
Analysts can now receive a verdict and can evaluate and trust rather than reviewing a set of findings they have to reconcile manually.
“It’s not simply an acceleration in the actual investigation and the SOC process, but it’s an enablement and really, essentially, a human acceleration on the analyst side as well,” said Richardson.
A shared context layer also ensures that every agent shares a single memory of the environment, meaning that what one agent learns, they all learn.
CrowdStrike targets AI threats and higher-quality security data
The Agentic SOC will investigate threats associated with enterprise AI adoption, including prompt injection and model abuse.
It features certified data pipelines that filter out noise at ingestion, allowing agents to only process what matters, working faster and smarter.
“The coordinated investigations also extend to threats that exist because of enterprise AI adoptions that can include things like model abuse and prompt injection,” said Richardson.
“The higher fidelity your data goes into these swarms of agents, the better your outcomes are going to be,” Richardson explained. “And we’ve had a saying for a long time: bad data in, bad data out.”
Falcon data provides a foundation for agentic investigations
Richardson argues that coordinated AI investigations depend on a common data foundation, positioning CrowdStrike’s single-sensor and single-platform architectures as an advantage, as its agents can draw on broad contextual data.
“Coordinated investigations at this scale, at this magnitude, with this impact, require a common data foundation,” said Richardson. “That’s what CrowdStrike single sensors, single consoles, single platform, and architecture provide.”
Falcon generates nearly four trillion events per day, giving agents broad context across the environment to perform their actions.
Human analysts remain central to CrowdStrike’s AI strategy
CrowdStrike is positioning its Falcon data platform as the foundation for that coordination, arguing that multi-agent investigations require a common source of security context.
Falcon generates nearly four trillion events per day, giving agents broad visibility across the environments they analyze.
Richardson also stressed that human expertise remains part of the model. CrowdStrike’s incident response and detection analysts provide examples of how investigations should unfold, including which evidence matters, how separate signals connect, and which actions should follow.
For MSPs and MSSPs, the broader opportunity lies in operations. If coordinated agents can reduce the amount of manual correlation required across endpoint, identity, cloud, SaaS, and network data, security providers could potentially investigate more incidents without increasing analyst workload at the same rate.
That could become increasingly important as service providers take on more complex customer environments and AI-related threats such as prompt injection and model abuse.





