AI agents execute attack actions on multiple systems at machine speed. Therefore, research must advance at the same pace. To that end, CrowdStrike has announced the next evolution of agent-based SOC with the first coordinated, multi-agent investigations that simultaneously span endpoint, identity, SaaS, cloud and network, reducing what previously took hours to a matter of minutes, with insights defenders can trust.
“We are already seeing AI agents carry out attacks on multiple systems at the same time,” says Michael Sentonas, president of CrowdStrike. «AI agents in the SOC are essential. Agents collaborating in all domains, in the same investigation: that is the new standard. “CrowdStrike’s architecture and expert validation make this possible and confidently answers the question every CISO asks: How can I trust what my agents have found and how do I know it is correct?” he explains.
First-generation AI SOC tools send individual agents to investigate alerts sequentially. However, AI attacks don’t work like that. They leverage credentials, engage in social engineering, and operate multiple services in parallel at machine speed. An agent investigating a single domain simply provides a piece of the puzzle, not a conclusion. When providers add agents to fragmented data stacks, every connectivity gap becomes an investigation gap. So by the time the pieces are assembled, the security breach has already occurred.
Unified data. Agents trained by experts
Only CrowdStrike offers a single-sensor, single-console, and platform architecture that generates nearly four trillion events per day across endpoints, identities, SaaS, cloud, and network. CrowdStrike’s elite analysts empower agents with expert decisions in every MDR and IR intervention, making agents more effective with every thwarted attack.
Building on this, Charlotte AI deploys domain agents in parallel, all operating on a new shared context layer, a persistent memory common to all agents, investigations, and clients. What one agent learns, everyone knows, eliminating hand-offs and allowing agents to work together on the same investigation across domains. Agents investigate in the style of elite analysts, weighing evidence and converging on a single reliable hypothesis, backed by visible reasoning and justification. Analysts no longer have to piece together isolated findings. The agents do it, at the speed of a machine under an approach based on:
Coordinated investigations with multiple agents. The investigations cover all areas simultaneously, including threats directed at companies’ AI systems: misuse of models, prompt injection and exfiltration through AI assistants. Agents deliver a reliable verdict with step-by-step response measures. Analysts stop performing routine tasks and start making decisions.
Shared context layer. Built on the Enterprise Graph, the AI-ready data layer that unifies telemetry across the enterprise, the shared context layer makes coordinated investigations possible. Each agent shares the same memory of the environment. What one learns, everyone knows. The more research that is carried out, the more accurate future research will be.
Certified data channels. Based on Falcon Onum’s real-time data pipeline technology, these pipelines filter out noise at the time of ingestion, so agents only process what’s relevant, allowing them to work faster and more accurately. Detection takes place within the channel, so threats are detected in real time before data reaches its destination. Certified by Falcon Complete, no security-relevant data is lost when connecting any third-party source directly to the Falcon Next-Gen SIEM, reducing data storage costs by up to 50%.
Each agent shares the same memory of the environment. What one learns, everyone knows
Automation workspace with unified management. Charlotte Agentic SOAR brings together Charlotte AI AgentWorks and Falcon Foundry into a single workspace, allowing teams to build and manage code-free agents based on the model of their choice, along with custom applications and workflows on top of Falcon data. Customers set the level of autonomy for each workflow, from human-involved approval to fully autonomous execution. Two-way MCP connects any third-party agent to Falcon and any CrowdStrike agent—whether custom or Agentic Security Workforce—to external tools, bringing together all agents, models, and tools in a single workspace, from creation to response.
