This year's theme: “Secure the AI Revolution”
Our biggest announcements yet.
One booth you shouldn't skip.
Vijilan is unveiling ThreatHunt™ and ThreatContain™ — our biggest announcement of the show — revealing Praxis AI™, our AI SOC platform, and launching NextDefend™, managed CrowdStrike Falcon® Next-Gen SIEM. Fal.Con 2026 is about securing the AI revolution — this booth is where that's an operating service, not a slide. Plus giveaways genuinely worth stopping for.
30 minutes · at the booth or nearby · with the engineers who run the service — no slideware.
Vijilan Security is a Silver Sponsor at CrowdStrike Fal.Con 2026, August 31 – September 3, 2026, at Mandalay Bay in Las Vegas. At the show, Vijilan is unveiling ThreatHunt™ and ThreatContain™ (proactive hunting plus automated containment — its biggest announcement), revealing Praxis AI™, its AI SOC platform, and launching NextDefend™, fully managed CrowdStrike Falcon® Next-Gen SIEM backed by a 24/7 Global SOC. The show's theme is “Secure the AI Revolution,” and Vijilan's announcements center on exactly that: AI-era SOC operations that act, not alert. Free 30-minute booth meetings can be booked on this page, and the same calendar works for virtual meetings for anyone not attending.
What we are taking home.
Our read on the Fal.Con 2026 keynote, written from the floor. George Kurtz opened by arguing that the traditional threat model no longer holds: frontier AI capability has spread well past nation states, attacks now move at machine speed, and the AI agents every enterprise is racing to adopt are themselves a surface that has to be defended.
- Falcon IQCrowdStrike's agentic AI security platform, built with NVIDIA and powered by Charlotte AI AgentWorks. It ships with prebuilt agents that automate assessment, prioritization and response, and lets partners build custom agents on the platform.
- Falcon GuardianAnnounced as generally available.
- SafeMind, Blue Solano and Red TempestNew autonomous defense capabilities, extending AI-driven protection across the attack lifecycle.
- Falcon on Google CloudThe Falcon platform is now available on Google Cloud.
- Falcon Next-Gen SIEM (Project QuiltWorks)Real-time telemetry ingest from across the stack, third-party tools included, positioning it as the aggregation layer for AI-era security operations.
- NVIDIA, Intel and OpenAIDeepened alliances, with NVIDIA founder and CEO Jensen Huang joining George Kurtz on stage.
Reported from the Fal.Con 2026 mainstage. Product names and availability are CrowdStrike's; see CrowdStrike's own announcements for the authoritative detail.
Three consequences if you run on Falcon.
Your AI environment is in scope now, whether you planned for it or not.
Models, prompts, agents and the pipelines feeding them are an attack surface EDR and XDR structurally cannot evaluate. Prompt injection, jailbreaks, agent behavior drift and shadow AI do not look like malware. That is the gap Falcon AIDR covers, and the one most teams have no baseline for.
Run a 60-day AI risk assessmentA SIEM that ingests everything moves the bottleneck to the pipeline.
Once the platform will take telemetry from your whole stack, the limiting factor becomes pipeline engineering: third-party sources parsed to the CrowdStrike Parsing Standard so they are queryable and correlatable, and shaped at the edge so ingest cost stays predictable. That is the half Vijilan engineers, on Falcon Onum or Cribl Stream.
See how we engineer the pipelineMachine speed still needs someone accountable.
Automation is what removes latency. It is not what removes responsibility. Praxis AI™ correlates, triages and contains in seconds across every connected source, and a Vijilan analyst owns the decision at every layer, detection through response. Machine speed where speed wins, human judgment where it matters.
See NextDefend OperateThreatHunt™ & ThreatContain™
The SOC that acts gets its biggest upgrade yet — hunting that finds what tools miss, and containment that disables accounts, isolates hosts, and blocks IPs before an incident becomes a headline.
Revealed live on the show floor at Fal.Con 2026.
Be there when it drops
Vijilan's AI SOC platform. The expertise of our 24/7 SOC — at machine speed.
Revealed with live demos at Fal.Con 2026.
Be there for the unveiling
Falcon® Next-Gen SIEMNextDefend™ — get the full value from your Falcon Next-Gen SIEM investment.
Most customers ingest only Falcon endpoint telemetry, leaving identity, cloud, SaaS, and network blind spots wide open.
Where a SIEM was deployed but underutilized (IBM Cost of a Data Breach Report), visibility gaps cost real money.
Hiring Next-Gen SIEM specialists, parser engineers, and detection content authors on the open market is slow and expensive.
Three service tiers · independent — combine, escalate, or stand alone
NextDefend™ Deploy
Stand up Falcon Next-Gen SIEM correctly the first time: solution architecture, data ingest, parser development, baseline detection content, validated handover.
NextDefend™ Sustain
Parser maintenance, detection content evolution, custom rule authoring, dashboard iteration, ingest tuning.
NextDefend™ Operate
Everything in Deploy + Sustain, plus 24/7 Vijilan SOC monitoring and threat hunting on third-party Next-Gen SIEM data — working in tandem with Falcon Complete, never duplicating it.
Where Falcon Complete ends, NextDefend Operate begins — we own third-party detection content, cross-source hunting, and parser engineering; CrowdStrike owns native Falcon platform operations.
Take the whole set with you.
Scanned the QR on a handout? Drop your email below and we’ll send all four documents straight to your inbox — attached, so you can read them on the flight home without hunting for wifi.
- Vijilan at Fal.Con 2026 — the NextDefend lifecycle
- NextDefend Deploy — one-time onboarding
- NextDefend Sustain — annual engineering retainer
- NextDefend Operate — fully managed
Four PDFs, about 0.9 MB in total. No pricing, no gated portal — just the material we hand out at the booth.
Fal.Con 2026: the full research report
Scale, agenda, keynotes, the partner and CPSP angle, the analyst criticism, and what to prioritize if you are going. Sourced and dated. No form.
A CISO on call,
backed by a SOC that acts.
Detection and response are only half the job. ThreatGovern™ brings the other half — security strategy, program governance, risk, compliance readiness and executive incident command — and connects it straight to Vijilan’s 24/7 SOC. Strategy that isn’t slideware, because the same team can operate it.
Strategy & governance
Multi-year roadmap, program build, KPIs and board-ready reporting.
Risk & compliance
A living risk register plus readiness for ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR, NIST CSF and CMMC 2.0.
Incident command
An executive incident commander during a breach — backed by the SOC that contains and remediates.
Most advisors hand you a plan. Vijilan can also run it.
White-label for MSPs, MSSPs & vCISOs — or direct for enterprises. Flexible engagements: fractional, interim or project-based.
The third-party half of the platform.
Falcon sees what the agent sees. Vijilan engineers everything either side of it: ingest, parsing, detection content and remediation that reaches past the endpoint, so the SIEM sees the whole environment rather than only what CrowdStrike already protects.
Falcon Guardian
The AI attack surface: models, prompts, agents, and the pipelines feeding them. Prompt injection, jailbreaks, agent behavior drift and shadow AI are things EDR and XDR structurally cannot evaluate. We onboard it, tune it, and watch it around the clock.
Falcon Onum
Telemetry shaped, filtered and routed at the edge before it lands, parsed to the CrowdStrike Parsing Standard. This is where ingest cost is won or lost, and the engineering for it is scarce.
Cribl Stream
Plenty of environments already route through Cribl. We work with the pipeline you have, or migrate you onto the native path: fluent in both, with no rip-and-replace as the opening move.
Third-party telemetry parsed to the CrowdStrike Parsing Standard via Falcon Onum and Cribl Stream, shaped at the edge, and priced to stay predictable.
We extend Falcon Complete. We do not replace it.
OverWatch hunts the endpoint. ThreatHunt covers identity, cloud control planes, network and SaaS.
Falcon Complete responds on the endpoint. Operate extends containment and remediation into the rest of the environment.
Falcon Complete and OverWatch stop at the endpoint. Operate and ThreatHunt™ carry the same standard across everything else.
Built for the people running the SOC math.
MSSPs & MSPs
Augment your SOC, modernize your SIEM practice, white-label options, no minimums.
Mid-market enterprises
Enterprise-grade managed detection, response, and remediation without building the team yourself.
Come talk to the people who actually run this stuff — not booth staffers with a script.
Worth the walk.
The Pink Floyd Drawing
Win a We Are Rewind portable cassette player — Pink Floyd Limited Edition ($199 value): aluminum-chassis Bluetooth 5.1 cassette player with The Dark Side of the Moon 50th-anniversary remastered cassette and a numbered authenticity card. Stop by, catch a demo, enter the drawing — winner announced at the show.
Analog music. Because your SIEM already gives you enough digital noise.
No purchase necessary. Must be present at Fal.Con to enter. Official drawing terms available at the booth.
The Next-Gen SIEM DIY Survival Kit
Thinking about deploying Next-Gen SIEM yourself? We packed everything you'll need:
- Coffee — for the 2 a.m. parser rewrites.
- Aspirin — for everything after that.
- One million dollars — year-one staffing and tooling, give or take.
- And one final item we can only hand you in person.
Or skip the kit and let NextDefend do it for you. Either way — the box is yours.
Handed out at the booth, while supplies lasted.
The Video Booklet
A video brochure preloaded with Vijilan's solution portfolio for MSSPs and mid-market enterprises. Watch our 3-minute overview, then plug it into your laptop and load your own family photos and videos.
The rare conference handout your household won't throw away.
Entries happen in person at the booth — and booked meetings skip the line. Grab a 30-minute slot →
Get on our calendar before the show fills it.
30-minute meetings at the booth or nearby — bring your Next-Gen SIEM questions, leave with a straight answer.
Prefer email? info@vijilan.com · +1 (954) 334-9988
Not making it to Vegas? The same calendar books virtual meetings before, during, or after the show.
Show coverage and the Praxis AI™ reveal, posted from the floor by KayVon Nejad, Founder & CEO:
Quick answers before Vegas.
What is Vijilan announcing at Fal.Con 2026?
Three things. The biggest announcement of the show is the unveiling of ThreatHunt™ and ThreatContain™ — proactive threat hunting plus automated containment that disables accounts, isolates hosts, and blocks IPs. Vijilan is also revealing Praxis AI™, its AI SOC platform, and launching NextDefend™, fully managed CrowdStrike Falcon Next-Gen SIEM backed by a 24/7 Global SOC.
When and where can I find Vijilan at Fal.Con 2026?
Fal.Con 2026 runs August 31 – September 3, 2026 at the Mandalay Bay Resort in Las Vegas, under the theme "Secure the AI Revolution." Vijilan Security is a Silver Sponsor on the expo floor; the booth number will be published here as soon as CrowdStrike assigns it.
How do I book a meeting with Vijilan at the show?
Pick a slot on the booking calendar on this page, or send the short form and the team will confirm within one business day. Meetings are 30 minutes, at the booth or nearby, with the engineers who run the service — no slideware. You can also email info@vijilan.com or call +1 (954) 334-9988.
What is NextDefend?
NextDefend™ is Vijilan’s managed CrowdStrike Falcon Next-Gen SIEM service: professional-services onboarding, managed Next-Gen SIEM engineering, and 24/7 Global SOC operations that hunt and remediate across endpoint, identity, cloud, network, and SaaS. It is built for mid-market and large enterprises and the MSSPs that serve them.
What are the booth giveaways?
Three things worth the walk: a drawing for a We Are Rewind cassette player with a Pink Floyd Dark Side of the Moon 50th-anniversary cassette, a Cyber Security Survival Kit video box, and a video booklet preloaded with Vijilan’s solution overview. Entries happen in person at the booth.
Can Vijilan help us implement Falcon Guardian (AIDR)?
Yes. Vijilan onboards and operates CrowdStrike Falcon® Guardian, announced at Fal.Con 2026 as the evolution of Falcon AIDR (AI Detection and Response), which secures the AI attack surface: models, prompts, agents, and the pipelines feeding them, covering prompt injection, jailbreaks, agent behavior drift and shadow AI. It sits alongside endpoint, identity, cloud, network and SaaS in the same 24/7 SOC, and it is the coverage domain that answers this year’s “Secure the AI Revolution” theme most directly.
Does Vijilan work with Falcon Onum and Cribl Stream?
Both. Falcon Onum is the platform-native data control plane, where third-party telemetry is shaped, filtered and routed at the edge before it lands, and that is where ingest cost is won or lost. Many estates already run Cribl Stream and Vijilan is equally fluent there: we work with the pipeline you have, or migrate you onto the native path. Either way, third-party sources are parsed to the CrowdStrike Parsing Standard so they are queryable and correlatable in Falcon Next-Gen SIEM.
Does Vijilan replace Falcon Complete?
No. Vijilan works alongside the Falcon Complete team. Falcon Complete responds on the endpoint; NextDefend™ Operate extends containment and remediation into the rest of the environment. The same split applies to hunting: Falcon Adversary OverWatch hunts the endpoint, while ThreatHunt™ covers identity, cloud control planes, network and SaaS. Falcon Complete and OverWatch stop at the endpoint; Operate and ThreatHunt carry the same standard across everything else.
We own Falcon Next-Gen SIEM but have not operationalized it. Can Vijilan run it for us?
That is exactly what NextDefend™ does. Deploy stands the tenant up correctly: solution architecture, third-party ingest and parsing, detection content mapped to MITRE ATT&CK, and a validated handover. Sustain keeps it current as the estate changes, with reserved engineering hours and ongoing detection tuning. Operate is the 24/7 SOC, included in every engagement, with Tier 1 to 3 analysts, threat hunting and remediation across every connected source rather than the endpoint alone.
I’m not attending Fal.Con — can I still get a meeting?
Yes. The same calendar works for virtual meetings before, during, or after the show. Book a slot and note in the form that you won’t be in Las Vegas — everything announced at the booth can be demoed remotely.
Something else on your mind? Bring it to a 30-minute meeting →
CrowdStrike®, Falcon®, and Fal.Con are trademarks of CrowdStrike, Inc. Vijilan is an authorized CrowdStrike partner; this page and event presence are Vijilan's own and are not sponsored or endorsed by CrowdStrike. The cassette player giveaway is a third-party product; Vijilan is not affiliated with We Are Rewind or Pink Floyd. NextDefend™, Praxis AI™, ThreatHunt™, ThreatContain™, and ThreatGovern™ are trademarks of Vijilan Security.