CrowdStrike headquarters in Silicon Valley
– Getty Images

CrowdStrike issued a double whammy of releases in time for this week's RSA 2026 event, with new wares focusing on AI agents and Microsoft endpoints.

The firm’s flagship Falcon platform includes updates to secure AI agents with endpoint detection and response (EDR) features. An EDR runtime feature claims to capture the network connections, commands, scripts, and file activity of each application running on the endpoint, including those of the agentic sort.

In addition, a shadow AI tool automates discovery of agents and AI applications running across endpoints qne development tools to seek out unauthorized and compromised software. The feature also scans large language model (LLM) runtimes as well as model context protocol (MCP) servers, linking them to asset context and privilege exposure to prioritize risk to critical systemw and assess the potential blast radius in a compromise situation.

Finally, Falcom prompt-layer protection is extended to desktop AI tools, including household names such as ChatGPT, Gemini, Claude, DeepSeek, and Microsoft Copilot.

Cloud and Microsoft defense

Beyond the endpoint, CrowdStrike’s RSA-timed release touted similar features for cloud and software-as-a-service (SaaS) environments, with agent discovery and governance for platforms like Copilot and ChatGPT Enterprise focused on permissions, data access, and activity. In the cloud layer, Falcon adds controls for containerized AI workloads and pipelines, including runtime inspection and data flow tracking for services using interfaces like the OpenAI API.

CrowdStrike also announced a new hyperscaler tie up at RSA, launching a Microsoft integration with its security information and event management (SIEM) wares. Specifically, Falcon Next-Gen SIEM now ingests and correlates telemetry data from Microsoft Defender for Endpoint, eschewing the use of additional sensors for Defender users looking to move from legacy SIEM to the cloud.

This comes with native integration of Falcon Onum, the real-time security data control plane inherited from last year’s Onum acquisition. CrowdStrike claimed the integration eliminates onboarding friction by delivering up to five-times faster streaming, 70% faster incident response, and 40% less ingestion overhead through real-time, in-pipeline detection, and intelligent filtering.

SIEM updates also include a federated search function across distributed data stores; onboarding of external indicators of compromise (IOCs); and a query translation agent that converts legacy SIEM queries, such as Splunk searches, into CrowdStrike Query Language (CQL). This agentic piece was touted as accelerating cloud migration, preserving analyst workflows, and eliminating retraining friction.

“AI agents are fundamentally changing how technology operates and how it must be secured,” CrowdStrike President Michael Sentonas explained. “Security built for static applications can’t keep up with autonomous systems. Organizations need real-time visibility and control over AI behavior wherever it runs. CrowdStrike is that new standard.”

“It is great to see Microsoft Defender telemetry being leveraged within Falcon Next-Gen SIEM,” added Rob Lefferts, corporate VP for threat protection at Microsoft. “Defender operates at a global scale, and integrations like this reinforce the importance of an open ecosystem where leading platforms interoperate to help customers improve security outcomes.”