Lahat ng vendor

Vendor lineage

CrowdStrike

Built on the argument that you should hunt the attacker rather than the malware - then proved, in one morning, what a lightweight agent everywhere really means.

CrowdStrike was incorporated on 7 November 2011 by George Kurtz, Dmitri Alperovitch and Gregg Marston. Kurtz had been chief technology officer at McAfee, having sold it his previous company, Foundstone, in 2004. He resigned, spent a spell as an entrepreneur in residence at Warburg Pincus, and left with a $26M cheque from them to build the thing he thought McAfee could not.

The founding argument was specific rather than promotional. Signature-based antivirus asks 'have I seen this file before', which is answerable only about attacks that have already happened somewhere else, and the scanning it requires is heavy enough that users disable it. Alperovitch had attributed the 2009 Operation Aurora intrusions to Chinese actors while at McAfee, and the lesson both founders took was that the interesting question is not which malware is present but which adversary is operating - and adversaries reuse behaviour even when they change their tools.

So Falcon, shipped in 2013, inverted the model: a deliberately light agent that streams telemetry to a cloud where behaviour is correlated across every customer at once. One organisation seeing something odd becomes every organisation knowing about it. That is a genuinely different product from an on-premises scanner, and it is why the company grew as fast as it did.

The investigations made the name. Sony Pictures in 2014, the Democratic National Committee intrusions in 2015 and 2016 - work that put a private company in the middle of a national political argument, which is a position security vendors had not previously occupied.

Then, on 19 July 2024 at 04:09 UTC, a faulty configuration update to the Falcon sensor crashed an estimated 8.5 million Windows machines and left them unable to restart. Airlines, hospitals, banks, broadcasters and payment terminals stopped. It is generally described as the largest IT outage in history, with damage estimated near $10B, and it produced duelling lawsuits between CrowdStrike and Delta Air Lines.

The uncomfortable part is that the outage was not a failure of the architecture so much as its logical conclusion. A lightweight agent with kernel access on millions of machines, updated centrally and rapidly, is exactly what made the detection model work - and exactly what made one bad file global before anyone could intervene. Every property that made the product good made the failure big. That trade is worth understanding before deploying anything shaped the same way, which is most of modern security.

Founding stories

2011

CrowdStrike

Sunnyvale, California · Founders: George Kurtz, Dmitri Alperovitch, Gregg Marston

Incorporated on 7 November. Kurtz had been chief technology officer at McAfee, which had bought his previous company Foundstone; Alperovitch had run threat research there. The founding claim was that the industry was asking the wrong question - identifying malicious files rather than identifying the people sending them - and that an adversary who changes their tools is still recognisable by how they work.

The timeline

  1. Founded

    By two McAfee executives and a co-founder from Foundstone, on the argument that attribution and behaviour matter more than file signatures.

  2. Falcon ships

    A deliberately light sensor that streams telemetry to a cloud where behaviour is correlated across every customer at once, rather than a heavy agent making local decisions from a local database.

  3. Sony Pictures

    The investigation that made the name, followed by the Democratic National Committee intrusions in 2015 and 2016.

  4. NASDAQ listing

    Listed in June at roughly $14B and rose more than 70% on the first day.

  5. Humio becomes LogScale

    The log platform acquired in 2021 became the foundation for a SIEM product, putting the company into direct competition with the incumbents - including Splunk, which appears elsewhere on this timeline and was itself acquired by Cisco two years later.

  6. 19 July, and the S&P 500

    A faulty sensor configuration update took an estimated 8.5 million Windows machines offline in a morning. The company joined the S&P 500 the same year. Analyst assessments since have treated the event as a serious trust problem that did not alter the product's technical standing - which is a distinction worth holding on to, because the two are genuinely separable.

    The outage is discussed on its own terms in the entry above; this timeline records it and the analyst reading rather than repeating that argument.

  7. Seventh consecutive Gartner EPP leadership

    Named a Leader for the seventh time running, having been positioned furthest right for completeness of vision in three consecutive evaluations.

Flagship products and solutions

  • Falcon sensorOne lightweight agent carrying every module, with no on-premises infrastructure behind it. The single-agent architecture is the platform decision everything else depends on - and the reason a bad update reaches everywhere at once.
  • Falcon InsightThe endpoint detection and response component, and the part most often measured against competitors in independent evaluations.
  • Falcon OverWatch and Falcon CompleteManaged threat hunting and managed detection and response - human analysts working the same telemetry, sold as a service. The acknowledgement that automated detection has a ceiling.
  • Falcon Identity ProtectionCoverage of the identity attack path from initial access through privilege escalation to lateral movement, reported above $520M of annual recurring revenue and growing faster than the platform as a whole.
  • Falcon Next-Gen SIEMBuilt on LogScale, the platform acquired as Humio, and positioned explicitly as a replacement for the incumbent SIEMs rather than a complement to them.
  • Charlotte AINatural-language querying over Falcon telemetry, extended into agentic triage and response - the analyst assistant becoming an analyst substitute for the first tier of work.
  • Falcon Data ReplicatorExport of raw telemetry into a customer's own systems, which is worth noting beside the SIEM product: the platform sells you its analysis and will also hand you the data to analyse elsewhere.

Key innovations

  • The cloud as the correlation pointDetection quality improves with the number of sensors reporting, because behaviour that looks unremarkable at one customer is recognisable across thousands. That makes the install base an asset rather than a liability, and it is why the model is difficult to enter late.
  • Adversary tracking as a productNaming and profiling groups - their tooling, their timing, their habits - turns intelligence into something a customer can act on before an incident rather than after one. It also put a commercial company into public attribution, which had previously been the business of governments.
  • Consolidation onto one agentThirty-odd modules delivered by a single sensor addresses a real operational problem, since every additional agent on an endpoint costs performance, compatibility and administration. The trade is concentration: one agent is one dependency, and July 2024 is what that costs on a bad day.
  • Selling the analysts as well as the softwareOverWatch and Complete exist because most organisations cannot staff a security operations centre around the clock. Packaging expertise as a subscription is now normal, and this company did much to make it so.

Main markets

Reported at more than 400 million protected endpoints across upwards of 30,000 customers, sold from small-business tiers through to enterprise agreements measured in six figures a year. Flexible licensing - buying platform credits rather than individual modules - reached $1.69B of annual recurring revenue, which is a demand signal about how customers want to consolidate.

Its competitors are now in three different categories at once: dedicated endpoint vendors, the platform security suites, and Microsoft, which ships a competing product with the operating system. The SIEM move added a fourth front against incumbents with decades of installed base.

Analyst standing

  • A Leader in Gartner's endpoint protection Magic Quadrant for seven consecutive evaluations, positioned furthest right for completeness of vision in the last three, and a Leader in the first Magic Quadrant for cyberthreat intelligence technologies.
  • In SIEM it is placed as a Visionary rather than a Leader, which is the honest reading of a newer entrant against long-established platforms, and worth stating rather than rounding up.
  • The 2024 outage is treated in analyst coverage as a trust event rather than a capability one: significant customer concern, no change in the assessment of the product. Whether that separation holds is a commercial question rather than a technical one.
From the company