Skip to main content
40d 23:53:22Fal.Con 2026 — our biggest reveals of the year.See the announcements
Solutions · supporting products & add-ons

The full catalog,
behind the flagships.

Every flagship is backed by channel-exclusive supporting products, and a system of outcome-named capabilities that say what they do, not which vendor module powers them.

Supporting managed services

Four products.
Channel-exclusive.

Included inside the flagship tiers, and available standalone where it makes sense for the partner.

Managed SIEM · no data caps

ThreatLog™

Managed SIEM powered by CrowdStrike Falcon Next-Gen SIEM. No data caps, ever. Included inside every flagship tier, and available as a standalone managed service.

Threat intelligence · CrowdStrike OEM

ThreatIntel™

CrowdStrike-OEM threat intelligence that enriches detection and hunting across the portfolio. Every finding is cross-referenced against global adversary intelligence.

Posture assessment · land motion

ThreatAssess™

A full-platform posture assessment that surfaces gaps and builds the case for ThreatRespond™ or ThreatDefend™. Bundled as a 60-day trial inside ThreatDefend™ Advanced.

On-prem collection · Cribl Stream

ThreatSensor™

A virtual appliance powered by Cribl Stream for on-prem log collection: 400+ source types, air-gap ready. ThreatRespond™ + ThreatSensor™ onboarding takes about an hour.

The Threat[verb] system

Outcome names,
not vendor jargon.

Externally, capabilities are named by what they do. The underlying technology stays internal; partners and clients see the outcome.

ThreatGuard™Endpoint detection & response
ThreatMap™Asset discovery & shadow IT
ThreatScan™Scanless vulnerability assessment
ThreatID™Identity threat detection & response
ThreatExpose™Exposure management (ThreatDefend)
ThreatOverWatch™Elite global threat hunting (Premium)
ThreatContainActive containment (Advanced+)
ThreatHuntSOC proactive threat hunting
ThreatSurface™Attack surface visibility
ThreatWatch™Dark web credential monitoring
ThreatBrowse™Browser security
ThreatAI™AI detection & response (ThreatDefend)
// ThreatRespond add-ons are agent-agnostic · Falcon-dependent capabilities belong to ThreatDefend
We're online · book a SOC walkthrough today

Compose the coverage
each client needs.

Start with a flagship, layer the supporting products that fit. We’ll map it to your book of business; no SKU dumps, no upsell games.