Introduction
CrowdStrike was founded in 2011 by George Kurtz, a former chief technology officer at McAfee, and Dmitri Alperovitch, a threat-intelligence researcher who had led work tracking state-sponsored hacking groups. The company built its business around a simple premise for the time: endpoint protection did not need heavy, signature-based agents installed on every machine. Instead, a lightweight sensor could stream telemetry to the cloud, where machine-learning models and human analysts could detect malicious behavior in near real time. That architecture became the Falcon platform, and it is the foundation of everything CrowdStrike has built since. The company went public on Nasdaq in June 2019 under the ticker CRWD and is headquartered in Austin, Texas, after relocating from Sunnyvale, California.
Neither founder was new to the security industry. Kurtz had previously founded Foundstone, a vulnerability-management vendor McAfee acquired in 2004, after which he served as McAfee's worldwide chief technology officer; Alperovitch had led McAfee's threat research team. That background shaped CrowdStrike's early emphasis on threat intelligence alongside endpoint telemetry, embodied in Threat Graph, a graph database the company built to correlate security events across its entire customer base and surface patterns that would be invisible within any single organization's data. CrowdStrike gained significant public visibility in 2016 when the Democratic National Committee hired it to investigate a breach of its network; CrowdStrike publicly attributed the intrusion to two Russian state-sponsored groups it tracks as Fancy Bear and Cozy Bear, an early, high-profile example of a private security vendor's threat-intelligence findings becoming central to a major geopolitical story, well before the company's 2019 IPO.
Falcon started as an endpoint detection and response (EDR) tool but has expanded into a broader security operations platform. It now spans cloud workload protection, identity threat detection, next-generation SIEM (built on the Falcon LogScale data platform), exposure management, and managed threat hunting through CrowdStrike's Falcon OverWatch and Falcon Complete services. The common thread across these modules is a shared sensor and a shared data layer: CrowdStrike markets this as the ability to add capabilities without deploying new agents, which has been central to its cross-sell strategy and its consistently high net retention rates as a public company. In 2023 and 2024, CrowdStrike layered a generative AI assistant, Charlotte AI, on top of this data layer, letting security teams ask natural-language questions about detections and get triage recommendations instead of manually pivoting through raw telemetry. Beyond the sensor and self-service modules, CrowdStrike also sells Falcon Complete, a fully managed detection-and-response service in which CrowdStrike's own analysts monitor and remediate threats on a customer's behalf, and Falcon OverWatch, a proactive threat-hunting service layered on top of the same telemetry; both have become a meaningful part of the business as many customers, particularly outside the largest enterprises, prefer to outsource continuous monitoring rather than staff it internally.
CrowdStrike's growth has made it one of the most closely watched companies in enterprise security, but the event that most defined its public reputation in recent years was not a product launch. On July 19, 2024, a routine content configuration update to the Falcon sensor for Windows contained an undetected defect. When systems ingested the update, a mismatch between input values expected by CrowdStrike's Content Validator and what was actually delivered triggered an out-of-bounds memory read, which Windows could not recover from gracefully. The result was widespread blue-screen crashes on Windows machines running the affected sensor version, disrupting airlines, hospitals, banks, and retailers across multiple continents within the same morning. CrowdStrike reverted the faulty update within roughly 78 minutes of its release, but because the defective content had already reached machines that were online during that window, remediation required manual intervention on many affected endpoints.
What happened next is a useful case study in how a security vendor handles a self-inflicted outage. CrowdStrike published a preliminary Post Incident Review within days, followed by a detailed public Root Cause Analysis in early August 2024 that named the specific software defect, the testing gaps that allowed it to ship, and the process changes the company committed to — including staggered rollouts of Rapid Response Content, expanded validation checks, and independent third-party code review of the Falcon sensor. The incident did not involve a malicious actor or a breach of CrowdStrike's systems; it was an operational failure in software deployment practices at a company whose core product runs with elevated privileges on millions of endpoints. That distinction matters for how the incident is understood, but it does not diminish its scale: multiple independent estimates placed the direct and indirect cost to affected businesses in the billions of dollars, and it remains one of the most disruptive IT outages caused by a single vendor update in the industry's history.
For readers trying to understand where AI fits into modern security operations, CrowdStrike is a reference point in two distinct ways. First, Falcon is a genuine example of machine-learning models operating at production scale to classify behavior across a very large, heterogeneous fleet of endpoints — the kind of workload that would be impractical for purely rules-based detection. Second, and less flattering, the July 2024 incident is a concrete illustration of the operational risk that comes with concentrating security enforcement in a small number of vendors whose updates push automatically to production systems worldwide. Both facts are true at once, and CrowdStrike's own public documentation of the outage is unusually detailed for a cybersecurity vendor, which is part of why it remains a frequently cited case in later industry discussions about change-management practices for security tooling.
What the company does
Falcon platform: cloud-native EDR/XDR, identity threat protection, next-gen SIEM, exposure management, and the Charlotte AI assistant for SOC triage.
Who it serves
Enterprises and public-sector organizations securing endpoints, cloud workloads, and identities.
Company background
Founded 2011.George Kurtz, Dmitri Alperovitch United States
Product and AI capabilities
Falcon platform: cloud-native EDR/XDR, identity threat protection, next-gen SIEM, exposure management, and the Charlotte AI assistant for SOC triage.
Key developments
Public company (NASDAQ: CRWD). July 19, 2024 global outage and subsequent Root Cause Analysis are verified via CrowdStrike's own published incident reports.
Why it matters
CrowdStrike is both a benchmark for AI-assisted endpoint defense at scale and, following the July 2024 outage, a widely documented case study in the operational risk of vendor-pushed security content.
Sector context
See Brel’s Cybersecurity sector hub for related profiles.
Sources and references
Official: https://www.crowdstrike.com/en-us/about-us/