CrowdStrike
A cloud-native cybersecurity company providing endpoint protection, threat intelligence, identity security, and cyberattack response services.
Last updated August 21, 2026
Overview
CrowdStrike is a United States cybersecurity technology company headquartered in Austin, Texas. It develops cloud-delivered security products and services for enterprises, governments, and other organizations. The company is best known for Falcon, a security platform designed to protect endpoints, workloads, identities, cloud environments, applications, and data through a common cloud architecture. The company was founded in 2011 by George Kurtz, Dmitri Alperovitch, and Gregg Marston. Kurtz had previously been associated with the cybersecurity industry, while Alperovitch brought expertise in threat intelligence and state-sponsored cyber activity. Gregg Marston served as an early finance executive. CrowdStrike initially differentiated itself from traditional antivirus vendors by emphasizing a cloud-managed platform, behavioral detection, large-scale telemetry, threat intelligence, and rapid incident response rather than relying primarily on locally maintained signature databases. CrowdStrike launched Falcon in June 2013. The platform provided endpoint security through a lightweight sensor connected to CrowdStrike's cloud infrastructure. This architecture allowed the company to aggregate security signals from many customers, identify emerging attack patterns, and deliver detection and response capabilities centrally. CrowdStrike also expanded into incident response and investigations through CrowdStrike Services, which was led from 2012 by Shawn Henry, a former Federal Bureau of Investigation official. The company gained public visibility through investigations of sophisticated intrusions and alleged state-sponsored campaigns. Its researchers reported on activity attributed to Russian, Chinese, North Korean, and other threat actors. CrowdStrike contributed analysis relating to the 2014 Sony Pictures attack, Chinese espionage groups, the Democratic National Committee intrusion, and attacks involving Ukrainian military software. These investigations helped establish the company as both a security-products vendor and a provider of cyber threat intelligence. Some of its public conclusions, including aspects of its reporting on Ukrainian artillery losses, were challenged by Ukrainian officials and other researchers, although subsequent reporting supplied additional evidence that the relevant application had been targeted by actors associated with Fancy Bear. CrowdStrike expanded its product portfolio through organic development and acquisitions. Its offerings came to include endpoint detection and response, managed detection and response, threat hunting, identity protection, cloud security, external attack-surface management, log management, security operations, and generative artificial-intelligence assistance. Acquisitions such as Preempt Security, Humio, SecureCircle, Reposify, Bionic, Flow Security, and Adaptive Shield broadened the platform's identity, observability, cloud-security, and application-security capabilities. Products and services such as Charlotte AI, Falcon Foundry, CrowdStream, and Falcon Flex further extended the platform's automation, integration, application-development, and subscription-management functions. CrowdStrike completed its initial public offering on the Nasdaq in June 2019 under the ticker CRWD. It later became a member of the S&P 500 index in 2024. The company has operated in a competitive market alongside endpoint-security, cloud-security, identity, and security-information vendors. Its positioning centers on a unified, cloud-native security platform, broad telemetry, automated detection, threat intelligence, and the ability to combine software with managed services and expert response. On July 19, 2024, a faulty configuration update for the Falcon Sensor on Microsoft Windows systems caused widespread computer crashes and recovery problems. CrowdStrike said the incident was not a cyberattack and acknowledged that a defective update was responsible. The disruption affected airlines, healthca…
History
CrowdStrike was established in 2011 by George Kurtz, Dmitri Alperovitch, and Gregg Marston. The founders built the company around a cloud-based approach to cybersecurity, treating endpoint telemetry and threat intelligence as centrally managed data rather than as isolated information stored on individual devices. In 2012, the company added CrowdStrike Services under the leadership of Shawn Henry, a former FBI official, to provide incident response and investigative expertise. Falcon, the company's first major product, launched in June 2013. Its lightweight endpoint sensor connected customer devices to CrowdStrike's cloud, enabling centralized detection, behavioral analysis, threat hunting, and response. The model was designed to support rapid updates and continuous analysis of attacks across a broad customer base. CrowdStrike subsequently became involved in investigations of prominent cyber incidents and published research on groups linked to Russia, China, North Korea, and other countries. In 2014, CrowdStrike research was associated with public actions against Chinese military hackers accused of economic cyber espionage. The company also reported on Energetic Bear, a group linked to Russia's Federal Security Service, and analyzed the Sony Pictures intrusion, which it connected to North Korean activity. It later identified the Chinese group Putter Panda, also known as PLA Unit 61486. In 2015, CrowdStrike disclosed VENOM, a vulnerability in QEMU virtualization software, and reported suspected Chinese cyber operations against technology and pharmaceutical organizations despite a public U.S.-China understanding concerning economic espionage. CrowdStrike attracted venture investment as its commercial presence grew. Google participated in its Series C financing in 2015. The company reported increasing private-market valuations during the following years and completed an initial public offering on Nasdaq in June 2019. Its public-company strategy involved expanding Falcon beyond conventional endpoint antivirus into detection and response, managed security, threat intelligence, identity protection, cloud security, log management, and security operations. The company broadened its capabilities through acquisitions. Payload Security added automated malware-analysis sandbox technology in 2017. Preempt Security, acquired in 2020, contributed identity and conditional-access capabilities. Humio, acquired in 2021, strengthened log management and security analytics. SecureCircle added a software-as-a-service security model, while Reposify expanded external attack-surface management. Bionic added application-security capabilities. Later transactions involving Flow Security and Adaptive Shield expanded the company's cloud-security portfolio. CrowdStrike continued to introduce platform extensions. Falcon Identity Threat Protection was launched in 2020 and later developed as a managed service. Cloud threat-hunting capabilities were added in 2022. CrowdStream, created with Cribl, addressed data integration and security telemetry workflows. Charlotte AI, introduced in 2023, applied generative AI to security analysis and response. Falcon Foundry, also introduced in 2023, provided a no-code environment for developing security applications and workflows. In December 2021, CrowdStrike moved its headquarters from Sunnyvale, California, to Austin, Texas. The company joined the S&P 500 in 2024. Its growth and platform breadth positioned it as a major provider in endpoint security and adjacent cybersecurity markets. The most consequential operational event in CrowdStrike's history occurred on July 19, 2024. A faulty configuration update distributed through Falcon Sensor caused Windows computers around the world to crash or enter recovery problems. Airlines, hospitals, banks, broadcasters, government bodies, and other organizations were affected. CrowdStrike determined that the incident resulted from a software-update defect rather than malicious activity. It supplied remediation tools and guidance, issued public apologies, and announced changes to validation, deployment, and customer-control processes. The outage led to questions about concentration risk, update governance, testing practices, and the resilience of critical information-technology infrastructure. Delta Air Lines, which experienced prolonged operational disruption, sued CrowdStrike. CrowdStrike filed its own action seeking to establish contractual limits on liability and argued that Delta's technology architecture and recovery decisions contributed to the length of the disruption. The litigation and the incident continued to shape discussion of cybersecurity vendor accountability and the risks of highly centralized security platforms.
- 2024S&P 500 inclusion and global outage
CrowdStrike joined the S&P 500 and later experienced a worldwide outage caused by a defective Falcon configuration update.
- 2023Charlotte AI and Falcon Foundry introduced
CrowdStrike expanded Falcon with a generative-AI security analyst and a no-code security application platform.
- 2021Humio acquired
The acquisition expanded CrowdStrike's log-management and security analytics capabilities.
- 2021Headquarters moved to Austin
CrowdStrike relocated its headquarters from Sunnyvale to Austin, Texas.
- 2020Identity protection expansion
Falcon Identity Threat Protection was introduced.
- 2019Initial public offering
CrowdStrike listed on Nasdaq under the symbol CRWD.
- 2015VENOM vulnerability disclosed
CrowdStrike reported VENOM, a serious vulnerability affecting QEMU virtualization software.
- 2013Falcon launched
CrowdStrike launched Falcon as a cloud-connected endpoint security product.
- 2012CrowdStrike Services established
Shawn Henry joined to lead a services business focused on incident response and cyber investigations.
- 2011Company founded
George Kurtz, Dmitri Alperovitch, and Gregg Marston co-founded CrowdStrike.
Products and positioning
A premium, cloud-native cybersecurity platform for enterprise and public-sector customers, combining endpoint protection, threat intelligence, managed services, identity security, cloud security, and automated security operations.
Falcon platformCloud cybersecurity platform2013
Falcon is CrowdStrike's principal cloud-native security platform. It combines endpoint sensors, cloud analytics, threat intelligence, detection and response, threat hunting, identity protection, cloud security, and security operations. Its architecture is intended to provide a common data and control layer across devices, workloads, users, and cloud environments.
Falcon PreventEndpoint protection
Falcon Prevent provides next-generation antivirus and prevention controls for endpoints. It is designed to block malware and other malicious behavior using behavioral indicators, machine learning, exploit prevention, and cloud-delivered intelligence rather than relying solely on traditional signatures.
Falcon InsightEndpoint detection and response
Falcon Insight provides endpoint detection and response capabilities. Security teams can investigate activity, search telemetry, identify suspicious behavior, and contain threats across managed systems. It supports the broader Falcon approach of combining endpoint visibility with cloud analytics and intelligence.
Falcon OverWatchManaged threat hunting
Falcon OverWatch is a managed threat-hunting service in which CrowdStrike personnel monitor customer environments for adversary activity that may evade automated controls. The service adds human-led investigation and continuous hunting to the software platform.
Falcon Identity ProtectionIdentity security2020
Falcon Identity Protection is designed to detect and prevent identity-based attacks, including suspicious authentication behavior, credential abuse, and lateral movement. It extends protection beyond the endpoint by monitoring identity activity and access conditions.
Charlotte AIGenerative AI security assistant2023
Charlotte AI is a generative-AI capability integrated with CrowdStrike's security environment. It is intended to help analysts query security information, investigate detections, summarize threats, and support response workflows, with the goal of reducing manual work in security operations.
Falcon FoundrySecurity application platform2023
Falcon Foundry is a no-code application-development environment associated with the Falcon platform. It is designed to let organizations create tailored security workflows and applications using CrowdStrike data, controls, and platform services without building every integration from scratch.
Flagship businesses
- Falcon platform
- Falcon Prevent
- Falcon Insight
- Falcon OverWatch
- Falcon Identity Protection
- Charlotte AI
Brand decisions
- 2024Change software-update controls after the outageOther
A faulty Falcon configuration update caused a global technology disruption on July 19, 2024.
What changed. CrowdStrike issued remediation tools and guidance, apologized publicly, and announced changes intended to improve testing, validation, staged deployment, and customer control over updates.
Aftermath. The incident prompted lawsuits, regulatory and industry scrutiny, and broader debate about the resilience and concentration risks of widely deployed security software.
- 2019Become a public companyStrategy
CrowdStrike had expanded its cloud security platform and customer base and sought access to public capital markets.
What changed. The company completed an initial public offering on Nasdaq under the ticker CRWD.
Aftermath. The listing increased the company's visibility and supported its development as a large publicly traded cybersecurity vendor.
- 2013Launch a cloud-connected endpoint platformProduct launch
Traditional antivirus products were commonly managed around local agents and signature updates. CrowdStrike sought to build a platform centered on cloud analytics, behavioral detection, and shared threat intelligence.
What changed. The company introduced Falcon as its first major product, using a lightweight endpoint sensor connected to cloud services.
Aftermath. Falcon became the foundation for CrowdStrike's expansion into detection and response, threat intelligence, identity, cloud security, and managed services.
Leadership
| Name | Title | Tenure |
|---|---|---|
| George Kurtz | Co-founder and Chief Executive Officer | 2011– |
| Shawn Henry | Former leader of CrowdStrike Servicesformer | 2012– |
| Dmitri Alperovitch | Co-founder and former Chief Technology Officerformer | 2011– |
| Gregg Marston | Co-founder and former Chief Financial Officerformer | 2011– |
Controversies
- 2024Faulty Falcon update and worldwide outageControversy
On July 19, 2024, a defective configuration update for Falcon Sensor on Microsoft Windows caused widespread system crashes and recovery failures. The incident disrupted airlines, healthcare, finance, media, government, and other services. CrowdStrike said the event was not a cyberattack, acknowledged responsibility for the faulty update, issued apologies and recovery guidance, and announced changes to its software validation and deployment processes.
Recent events
- 2024CrowdStrike joins the S&P 500
CrowdStrike was added to the S&P 500 index in June 2024.
Other - 2023CrowdStrike introduces Charlotte AI
CrowdStrike launched Charlotte AI as a generative-AI security analyst intended to assist with threat triage, investigation, and response within the Falcon environment.
Product launch - 2021CrowdStrike expands through Humio acquisition
CrowdStrike acquired Humio, a Danish log-management company, strengthening its security analytics and observability capabilities.
M&A - 2021CrowdStrike moves headquarters to Austin
The company relocated its headquarters from Sunnyvale, California, to Austin, Texas.
Other - 2020CrowdStrike launches Falcon Identity Threat Protection
The company introduced a Falcon capability focused on protecting user identities and detecting identity-based attacks.
Product launch - 2019CrowdStrike completes its Nasdaq initial public offering
CrowdStrike became a publicly traded company on Nasdaq under the ticker CRWD.
Other - 2017CrowdStrike analysis contributes to public discussion of the DNC intrusion
CrowdStrike, together with other security organizations, analyzed the Democratic National Committee intrusion and attributed the activity with high confidence to groups associated with Russian intelligence services.
Other - 2016CrowdStrike reports on Russian-linked cyber activity in Ukraine
CrowdStrike published research attributing attacks involving a Ukrainian artillery application to the Russian-linked group Fancy Bear. Ukrainian officials and other organizations disputed parts of the report, while later reporting found evidence that the application had been targeted.
Other
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/crowdstrike · Editorial policy · How profiles are compiled