Skip to main content

AI Detection and Response · on CrowdStrike Falcon® Guardian

Your AI agents have access to everything. Who’s watching them?

ThreatAI Watch is Vijilan’s managed AI Detection and Response service. We find every AI agent in your estate, trace what each prompt actually did on the machine, and watch it 24/7, with a Vijilan analyst authorizing every consequential action.

Your agents. Our SOC.

The problem

The agents are already here

Coding assistants, desktop agents, browser copilots, MCP servers wired into internal tools. Most arrived with a developer’s IDE or a browser extension rather than through a procurement process, and each one can read files, run commands and use whatever credentials the person who installed it has.

CrowdStrike reports that its sensors detect more than 1,800 distinct AI applications on enterprise devices, nearly 160 million instances. (CrowdStrike, citing FY26 earnings, 23 March 2026.) And adversaries have noticed: CrowdStrike’s 2026 Global Threat Report found AI-enabled adversaries increased their activity 89% year over year, and that attackers injected malicious prompts into legitimate GenAI tools at more than 90 organizations. (CrowdStrike, 24 February 2026.)

The question your board is about to ask is simple. Which agents are running, what can they touch, and who notices when one does something it shouldn’t?

Capability

What ThreatAI Watch does

Find every agent, including the ones that are not running

Falcon Guardian inventories AI agents on the endpoint itself, so installed-but-idle agents appear alongside active ones. Tools that only watch network or gateway traffic see an agent only while it is talking.

Trace prompt to impact

Guardian lives in the Falcon sensor, so an investigation can follow a single session from the prompt to the processes, files and network activity it caused. That chain is how an analyst tells a misused agent from a busy one.

Govern what runs

Sanctioned and unsanctioned AI, defined once and enforced through policy: which agents may run, which AI destinations are allowed, and what sensitive data may not leave in a prompt.

Act, with a human deciding

When an agent is compromised or misused, the SOC acts under response rules you pre-authorize, such as isolating the host, blocking the agent or disabling the account, and owns the incident through to a written report.

When it is real

What happens when something is real

01

We investigate

Praxis AI™, Vijilan’s SOC platform, correlates the Guardian detection with endpoint, identity and SIEM context and assembles the agent’s session before an analyst opens it.

02

We decide

A Vijilan analyst determines whether the agent was prompt-injected, misused or behaving as intended, and what that warrants. Never autonomous-only.

03

We act

Host isolation. Agent blocked. Account disabled. Token revoked. The action itself, not a notification with a severity label.

04

We finish it

Investigation to conclusion, containment, remediation, and a report your CISO, auditor or works council can read.

How it is delivered

Delivered in three phases

01

Deploy

onboarding

Guardian policies built for Windows and macOS, agent discovery switched on, sanctioned and unsanctioned AI defined, privacy controls set before data flows, and the right two or three collectors for your use cases: coding assistants, MCP servers, AI gateways, Copilot Studio or your own AI applications. Ends with a readout and a tested handover to the SOC.

02

Sustain

maintenance and management

Optional

Detector tuning, false-positive reduction, new agent types reviewed as they appear, policy changes as adoption grows, and a quarterly AI governance review.

03

Operate

24/7 SOC

Always included

Follow-the-sun analysts on every Guardian and agentic detection, Agent Graph investigation, pre-authorized containment, and hunting for AI-agent techniques through ThreatHunt™.

Stakeholders

Built for the people who have to sign off

For the security team

One queue. Guardian detections arrive in the same SOC that already watches your endpoints, identities and SIEM, not a new console someone has to remember to check.

For engineering

Week one is observe-only. Enforcement starts on a named pilot group after a baseline, and only for rules you approve. Developers keep their tools.

For privacy and works councils

Access can be limited to metadata, meaning which agent, which destination, which detection, without exposing prompt content or model responses. We configure it before data flows and document it for your DPO.

Buying it

Two ways to add it

Add it to ThreatDefend™ or NextDefend™

Guardian is a module on the same Falcon sensor Vijilan already runs for you, and its telemetry lands as first-party data in Falcon Next-Gen SIEM. ThreatAI Watch adds the AI surface to a SOC that already knows your estate.

Or run it standalone

Already own CrowdStrike Falcon and run it yourselves? Vijilan operates the AI surface only, Deploy, Sustain and Operate for Guardian, and your team keeps everything else.

Requires CrowdStrike Falcon on the endpoints in scope. Don’t have it yet? ThreatDefend™ brings it

Questions

Common questions

What is Falcon Guardian?

CrowdStrike's AI Detection and Response product, launched 1 September 2026. It is built into the Falcon sensor and discovers AI agents, traces their activity and enforces AI policy.

Falcon Guardian, explained

Do we need CrowdStrike Falcon already?

Yes, on the endpoints in scope, because Guardian is a Falcon module rather than a standalone agent. If you do not have Falcon, ThreatDefend™ brings it and ThreatAI Watch adds on.

Which operating systems are covered?

Windows and macOS today. We will confirm exactly what is available on your fleet during scoping, including any differences between the two.

Will you read our employees’ prompts?

Only if you want us to. Access can be restricted to metadata, and prompt content can be excluded from logs by rule. We agree the configuration with you before anything is collected.

We already have an AI gateway. Is this redundant?

No. A gateway sees traffic that passes through it. It does not see a dormant agent, an agent calling a model directly, or what a prompt did on the machine afterwards. Keep the gateway, because Guardian has a collector for it and we will connect it.

Does AI make the containment decisions?

No. Praxis AI™ investigates and triages. A Vijilan analyst authorizes every consequential action.

How is it priced?

Per endpoint in scope, as an add-on or standalone, and quoted against your estate rather than published as a list rate. Start with the AI Agent Readout and we will price against what it finds.

Can we buy through our IT provider?

Yes. Vijilan works directly and through MSP, MSSP and VAR partners, and we never compete with our partners for their clients.

Find out what’s running before someone else does.

A named list of every AI agent on your pilot endpoints, what each one can reach, and what we’d watch first.

ISO/IEC 27001 Certified·SOC 2 Type II Audited·CrowdStrike Powered Service Provider (CPSP)

HIPAA, PCI and CMMC L2 evidence packs available on request.