Falcon OverWatch: Proactive Managed Threat Hunting

Falcon OverWatchTM is a human threat detection engine that operates as an extension of your team, hunting relentlessly to see and stop the most sophisticated hidden threats
Download Data Sheet


Why Choose Falcon OverWatch

  • Ability to See and Stop Hidden Advanced Attacks

    Ability to See and Stop Hidden Advanced Attacks

    The OverWatch team hunts relentlessly to see and stop the stealthiest sophisticated threats: the 1% of 1% of threats that blend in silently and lead to a breach if they remain undetected.

  • Maximum Effectiveness and Efficiency

    Maximum Effectiveness and Efficiency

    OverWatch delivers the best results by augmenting skilled analysts with the most advanced technology. Our elite human experts use cloud-scale data, custom tools and up-to-the-minute threat intelligence to hunt with unprecedented speed and scale.

  • Seamless Extension of Your Team

    Seamless Extension of Your Team

    As a core component of the CrowdStrike Falcon® platform, OverWatch delivers results for organizations of all sizes, operating as a seamless extension of your team — minimizing overhead, complexity and cost.

Technical Features

People, Process and Technology Are All Key to Stopping Breaches

24 x 7 Human Expertise

24 x 7 Human Expertise

  • Attacker mentality. Effective threat hunting requires the ability and expertise to think like an attacker.
  • Cross-disciplinary expertise. OverWatch employs elite experts from a wide range of backgrounds, including government, law enforcement, commercial enterprise, the intelligence community and defense.
  • 24/7/365 availability. When a sophisticated intrusion occurs, time is critical. Your adversaries do not sleep and are not restricted by time zones or geography — and neither should your threat hunting team.
  • Continuous vigilance. OverWatch’s continuous, proactive operations deliver results every minute of every day.
  • Finely-tuned response. OverWatch identifies and responds to hundreds of potential breaches per week. Each threat handled helps team members fine-tune their skills and processes, ensuring they are always sharp and effective.

Insights from the 2019 OverWatch Mid-year Report

Cloud-scale Security Telemetry

Cloud-scale Security Telemetry

  • Tools for the hunt. Threat hunting requires more than just expert hunters — those hunters need the right tools. Scalable and effective threat hunting requires access to vast amounts of data and also the ability to mine that data in real time for signs of intrusions.
  • Real-time visibility. OverWatch takes advantage of the cloud-scale telemetry of the proprietary CrowdStrike Threat Graph® to get broad, deep visibility, delivered in real time.
  • Massive data. Threat Graph ingests trillions of events each week, giving Falcon OverWatch an extensive, global real-time view of threat activity, as it happens.

Learn More About CrowdStrike Threat Graph

Up-to-the-minute Threat Intelligence

Up-to-the-minute Threat Intelligence

  • Threat context. You can’t detect a threat you don’t understand.
  • CrowdStrike threat intelligence. This intel empowers OverWatch with detailed, always-current knowledge of tradecraft from more than 130 adversaries.
  • Current TTPs. This intimate knowledge of the latest TTPs (tactics, techniques, and procedures) in use today ensures that OverWatch is able to hunt effectively and efficiently.

Learn More About CrowdStrike Threat Intelligence

Seamless Part of the Falcon Platform

Seamless Part of the Falcon Platform

  • One team, one fight. OverWatch operates as an extension of the Falcon platform and your team, delivering timely threat information via the single cloud-native console.
  • Alerts augmented with context. OverWatch analysts deliver alerts that are augmented with contextual details and global insights to help organizations understand threats and act faster.

Explore the Falcon Platform

Technical Center

For technical information on Falcon OverWatch, please visit the CrowdStrike Tech Center.

  • Technical Center
  • Technical Center
  • Technical Center
Getting Started with Falcon OverWatch

Product Validation

Customers Trust CrowdStrike

Third-Party Validation

Since 2016, CrowdStrike has demonstrated a strong commitment to continuous industry collaboration, scrutiny, and testing. Time and time again, CrowdStrike has been independently certified to replace legacy solutions.

  • Forrester Total Economic Impact

    Falcon OverWatch helps organizations reduce risks and improve efficiencies, resulting in 316% ROI.

    Read the Report

  • SANS Review of OverWatch

    SANS experts review how Falcon OverWatch responds in real time to sophisticated threats including credential theft, lateral movement and defense evasion.

    Read the Report

Visit our third-party evaluations page to see how CrowdStrike performed against the industry’s most rigorous tests and trials.

Falcon OverWatch Offerings

Choose the one that meets your requirements:

  • OverWatch Standard

    OverWatch Standard

    See and stop hidden advanced attacks and reduce dwell time with 24 x 7 proactive human threat hunting.

    See Below

  • OverWatch Elite

    OverWatch Elite

    Falcon OverWatch Elite expands the basic OverWatch offering by adding an assigned OverWatch threat analyst to consult on root causes, assist with analysis, perform weekly health checks and provide proactive configuration recommendations and customized quarterly briefings.

    Learn More

OverWatch Standard
OverWatch Elite
Cross-disciplinary human experts tooltip checkcheck
Continuous vigilance tooltip checkcheck
Cloud-scale telemetry tooltip checkcheck
Intelligence-driven tooltip checkcheck
Seamless integration with the Falcon platform tooltip checkcheck
Alerts augmented with context tooltip checkcheck
Email notifications tooltip checkcheck
Assigned threat analyst tooltip check
Personalized onboarding tooltip check
Hunting and investigation coaching tooltip check
Recurring environmental checkups tooltip check
Proactive tuning tooltip check
Tailored threat reports and briefings tooltip check
Response advice, advanced investigation and context support tooltip check
Proactive, closed-loop communications tooltip check

Get Answers to Commonly Asked Questions

Falcon OverWatch FAQ

Purchase Falcon OverWatch as a Part of a Bundle

CrowdStrike Falcon bundles are specifically tailored to meet a wide range of endpoint security needs.

Explore the Bundles