Platform  /  Charlotte AI

CrowdStrike® Charlotte AI

Powering the next evolution of the SOC


Unite intelligent automation with human cyber expertise to accelerate detection, investigation and response.

 

Experience the power of Charlotte AI

Charlotte AI Detection Triage

1:54 minute watch

Charlotte AI Detection Triage

Reduce noise and prioritize high-risk attacks faster

Charlotte AI Agentic Response

2:12 minute watch

Charlotte AI Agentic Response

Save time by asking and answering expert-level questions

Conversational AI

2:48 minute watch

Conversational AI

Get fast, actionable answers to pressing questions

Charlotte AI transcends “ask-and-respond” copilots, delivering autonomous reasoning and action on first- and third-party data

test

Detect

Triage detections in seconds, filter false positives, and escalate only what matters.


Respond

Insert and activate AI reasoning directly within automated playbooks.


Investigate

Exponentially increases analyst productivity by automatically asking and answering investigative questions.

Extend the power of agentic AI to cybersecurity services

 

Falcon® Complete Next-Gen MDR with Charlotte AI utilizes the triage decisions of CrowdStrike’s elite analysts to accelerate investigations – creating a powerful, one-of-a-kind feedback loop that supercharges human and AI performance.

Charlotte AI
Charlotte AI is trained on the millions of breaches we’ve stopped and insights from our elite threat hunters and SOC analysts. As Charlotte gets smarter, so does our platform—and so do the experts who use it.

No fiction, just function

 

In a world of AI hype, keep it real with Charlotte AI.

Real outcomes

40hrs+

Time Saved

40hrs+

Average savings per week by automating detection triage with agentic AI1

75%

Faster Answers

75%

Faster answers to questions about your environment2

57%

Faster Query Writing

57%

Faster query writing, amplifying analysts of all skill levels3

Real use cases

Cut through noise and reclaim hours

 

Triage in seconds with front-line precision. Slash alert fatigue and reclaim hours from manual analysis. Built on the playbooks of Falcon Complete™ MDR, Charlotte AI Detection Triage filters false positives — escalating only what matters. Stay focused, stay fast, and stay in control of what’s automated, and when.

Charlotte AI product screenshot
Charlotte AI product screenshot

Boost analyst performance with frontline insights

 

Charlotte AI accelerates investigations by thinking like a seasoned analyst, asking and answering critical questions . Get fast context with AI-generated summaries, dynamic incident graphs, and insights that map out the who, what, and how — so decisions happen faster, and with confidence.

Find real attacks fast and prioritize what matters

 

LLM-powered conversations meet real-time security insight. Query your Falcon® data in plain language — from decoded commands to adversary profiles. Charlotte AI turns complex analysis into simple answers, shareable across your team with reusable promptbooks.

Charlotte AI product screenshot
Charlotte AI product screenshot

Activate autonomous reasoning to speed up response

 

Automate what slows you down with Agentic Workflows in CrowdStrike Falcon® Fusion SOAR. Go beyond traditional SOAR with AI intelligence that adapts on the fly and eliminates lags from human-activated tasks.

Respond with bounded autonomy

 

Charlotte AI runs with bounded autonomy, keeping you informed at every step. Every action is traceable, auditable, and governed by role-based access — so you can move fast without ever losing oversight or exposing your team and data.

Charlotte AI platform screenshot

Real customer stories

Emy Dunfee, Director, Information Technology Security

Emy Dunfee, Director, Information Technology Security

“CrowdStrike’s approach to Charlotte has been very realistic and very useful, efficient. They’ve really approached it from a, this is how you can really support your staff, help with attrition, help with knowledge gaps, and those are the real world problems that we’re trying to solve.”

David Levin, CISO

David Levin, CISO

“AI also helps prioritize which alerts are likely urgent. Our analysts then spend their time on the highest-risk issues rather than sifting through noise. It’s a massive boost in efficiency. Ultimately, AI helps us detect threats more accurately and respond faster.”

DJ Goldsworthy, VP Sec Ops

DJ Goldsworthy, VP Sec Ops

“Our adversaries are coming at us with AI PhDs. We need AI at the same level, and Charlotte AI will help us identify and secure vulnerabilities in real time as our environment evolves."

Charlotte Image

Proven AI leadership

cybersecurity award 2024

Best AI Security Solution

Award

Best AI Security Solution

SE Labs EDR

Best AI Security Co-Pilot

Award

Best AI Security Co-Pilot

AI excellence award 2025

Best Cybersecurity AI

Award

Best Cybersecurity AI

Charlotte AI FAQs


Product overview and pricing

 

Charlotte AI is a generative,  agentic AI assistant  for users of  the CrowdStrike Falcon®​​ platform. It uses industry-leading AI technologies to enable users to query Falcon platform data using plain-language questions, and to help accelerate detection triaging, investigations and workflow automation.

Charlotte AI powers detection triage and agentic investigations within the Falcon platform. It automatically analyzes new endpoint detections, helping to reduce response time. By generating detailed documentation and priority scoring, Charlotte AI empowers admins to act on critical detections. Humans  remain in control of how Charlotte AI detection triage is used.

No. You can access Charlotte AI using your existing CrowdStrike Falcon®  agent.

Charlotte AI is available for purchase to all Falcon platform users leveraging US-1, US-2 and EU platform regions.

 

Data and underlying models

 

Yes. Charlotte AI is able to obtain and surface data from supported CrowdStrike APIs and modules (such as Falcon Discover, which has connectors to 3rd party data sources).

Charlotte AI’s underlying models are trained and tuned on Falcon platform documentation, APIs of the Falcon platform, and CrowdStrike’s high-fidelity security telemetry.  

Charlotte AI is continuously trained on detection triage data and the latest investigation guidance from CrowdStrike Falcon® Complete MDR’s world-class security experts. This ensures it keeps up with evolving adversary techniques and provides highly reliable assessments.

Charlotte AI’s underlying architecture leverages a diverse set of cutting-edge LLMs and other AI technologies — including third party models and first party AI technologies. Charlotte AI’s architecture gives CrowdStrike the flexibility and adaptability to adjust the models applied across workflows based on ongoing performance testing, to continuously optimize Charlotte AI’s performance.

 

Responsibility, privacy, and safety controls

 

As an extension of the Falcon platform, Charlotte AI operates within each user’s role-based access policies.

Yes. Every answer provided by Charlotte AI is inspectable and traceable. To see the underlying sources of data for each answer, click on the “see response details” toggle included in the upper right corner of each answer.

Furthermore, the “Charlotte AI Auditor” role allows administrators to designate users in their environment who can see all questions submitted to Charlotte AI, to ensure usage is consistent with their organization’s policy.

When configuring Agentic Workflows, users define what data is available to the individual LLMs and what actions the resulting workflows are authorized to take on their behalf.

1 Calculated by multiplying the average number of alerts triaged by Charlotte AI by a 5-minute triage time per alert as estimated by the Falcon Complete team. Individual results may vary based on factors such as total alert volume.
2 Results based on a survey of Charlotte AI early adopters. Individual results may vary. 4 Accuracy rating is a measure of Charlotte AI triage decisions that match the expert decisions from the CrowdStrike Falcon Complete Next-Gen MDR team.
3 The time savings of more than 10 minutes per investigation is an estimate based on Agentic Response’s ability to automate tasks that would otherwise require more than 10 minutes of manual effort by a human analyst. This should not be interpreted as a guarantee that this will lead to a 10 minute reduction in the total investigation time or mean time to respond (MTTR)