Call a Specialist Today! 020 3893 1921 Free Delivery! Free Delivery!

CrowdStrike Falcon Overwatch
See and stop hidden advanced attacks

Falcon OverWatch: Managed Threat Hunting

Falcon OverWatch is a human threat detection engine that operates as an extension of your team, hunting relentlessly to see and stop the most sophisticated hidden threats

Stopping the Mega Breach

Falcon OverWatch is CrowdStrike’s managed threat hunting service, built on the CrowdStrike Falcon platform. OverWatch provides deep and continuous human analysis, 24/7, to relentlessly hunt for anomalous or novel attacker tradecraft that is designed to evade standard security technologies.

OverWatch is comprised of an elite team of cross-disciplinary specialists who harness the massive power of the CrowdStrike Threat Graph, enriched with CrowdStrike threat intelligence, to continuously hunt, investigate and advise on sophisticated threat activity in customer environments. Armed with cloud-scale telemetry and detailed tradecraft on more than 130 adversary groups, OverWatch provides unparalleled ability to see and stop the most advanced threats.

Key Benefits of Choosing Falcon Overwatch


OverWatch hunts relentlessly to detect and disrupt the stealthiest sophisticated threats: the 1% of the 1% of threats that go undetected.


OverWatch delivers the best results by leveraging cloud-scale data, custom tools and up-to-the-minute threat intelligence and augmenting this with insights from skilled analysts to hunt with unprecedented speed and scale.


OverWatch delivers results for organizations of all sizes, operating as a seamless extension of your team - minimizing overhead, complexity and cost.


  • Cloud-scale data. Scalable and effective threat hunting requires access to vast amounts of data and the ability to mine that data in real time for signs of intrusions. CrowdStrike’s rich telemetry creates the foundation for OverWatch threat hunting.

  • Trillions of events per day. CrowdStrike’s lightweight Falcon sensor delivers continuous telemetry covering hundreds of event types from millions of endpoints. All of this is collected and catalogued by the Falcon platform, providing comprehensive visibility into activity across the CrowdStrike install base.
Powered by the Falcon Platform


  • Context. The proprietary CrowdStrike Threat Graph contextualizes events and reveals relationships between data points in real time.

  • Threat Intelligence. CrowdStrike threat intelligence provides up-to-the-minute intel on the tradecraft of more than 140 adversary groups, as well as intimate working knowledge of the tactics, techniques and procedures (TTPs) in use in the wild.

  • Proprietary Tools. All of this is underpinned by OverWatch’s proprietary tools and processes, which ensure every hunt is optimized for maximum efficiency.


  • Human analysis. Threat hunting involves taking enriched data and applying complex statistical methods, examining outliers, and frequency analysis. It involves using intuition and experience to form and test hypotheses about where and how a determined attacker might conceal their operations.

  • 200+ years of combined diverse expertise. OverWatch employs elite experts from a wide range of backgrounds, including government, law enforcement, commercial enterprise, the intelligence community and defense.

  • Continuous vigilance 24/7/365. When a sophisticated intrusion occurs, time is critical. Your adversaries do not sleep and are not restricted by time zones or geography - neither should your threat hunting team.
Layers of Expertise


  • Connect the dots. Before you can take action against an adversary, you first need to fully understand the threat. As soon as a hands-on-keyboard intrusion is discovered, OverWatch begins to comprehensively reconstruct the attack.

  • Ask the right questions. Experience helps OverWatch quickly zero in on how the intruder gained access and how far the intrusion has spread.

  • Get answers in seconds. CrowdStrike’s proprietary Threat Graph provides OverWatch analysts with the answers to these questions in near real time.


  • One team, one fight. CrowdStrike pioneered the idea of creating a seamless union between the technology, our experts and your team, closing the gap between detection and response.

  • Frictionless communication. OverWatch operates as a native component of the Falcon platform and a force multiplier for your team, delivering timely threat information within your single cloud-native console.

  • Actionable insights. You get results, including alerts with deep context and targeted recommendations for response, beginning day one, without any new infrastructure, communications channels or processes.
Layers of Expertise


  • Continuous improvement. Threat hunting is not a one-time activity; it’s a process that demands continuous improvement and sharpening of your tools in order to deal with evolving adversary TTPs.

  • Always sharp. OverWatch’s continuous, proactive operation delivers results every minute of every day. Each threat they handle enables OverWatch hunters to continuously fine tune their skills and processes, ensuring they are always sharp, effective and ready for the next new threat.

Falcon Overwatch Offerings

Choose the one that meets your requirements:

betterprotection icon

Falcon Overwatch

See and stop hidden advanced attacks and reduce dwell time with 24 x 7 proactive human threat hunting.

Falcon Overwatch Elite

Falcon OverWatch Elite expands the basic OverWatch offering by introducing an assigned threat response analyst to help your organization both understand the threats that are most likely to target it and how best to prepare and respond to them.


Falcon Overwatch

Falcon Overwatch Elite

CrowdStrike's lightweight agent streams deep telemetry into the Security Cloud in near real time giving OverWatch immediate visibility to emerging threats.
Included Component Included Component
Global Threat Visibility
The CrowdStrike Security Cloud ingests, indexes and enriches trillions of events per day, giving OverWatch the broadest view of threat activity as it is happening, all over the world.
Included Component Included Component
Immunity by Community
Through millions of endpoints globally distributed, the CrowdStrike OverWatch team can see emerging threats immediately, and disrupt them globally.
Included Component Included Component
Specialized Data, Tools and Processes
The OverWatch team leverages a proprietary threat hunting methodology 'SEARCH' to effectively stop breaches.
Included Component Included Component
Hypothesis Driven Threat Hunting
OverWatch performs threat hunting using intuition and experience to form and test hypotheses about where and how a determined attacker might conceal their operations.
Included Component Included Component
Continuous Vigilance
The OverWatch team conducts 24/7/365 threat hunting, because attackers are not constrained by geography or time zones.
Included Component Included Component
Cross Disciplinary Expertise
Human threat hunters possess diverse backgrounds and skill sets, for broad and deep expertise.
Included Component Included Component
Intelligence-LED Threat Hunting
CrowdStrike threat intelligence empowers the OverWatch team with intimate knowledge of the latest TTPs, ensuring that the team knows what it should be looking for today and tomorrow.
Included Component Included Component
Alerts Augmented with Context
OverWatch analysts deliver alerts that are augmented with contextual details and global insights to help organizations understand and act faster.
Included Component Included Component
Email Threat Notifications
Your team receives tailored email summaries of critical threats uncovered by OverWatch threat hunters.
Included Component Included Component
Quarterly Threat Hunting Reports
Receive quarterly reports on the threat landscape and what OverWatch has seen in the wild.
Included Component Included Component
Personalized Onboarding
Collaboration with your OverWatch analyst begins on day one.
  Included Component
Response Advice, Advanced Investigation and Contextual Support
Your OverWatch Elite analyst is available for targeted advice on incident response and to provide deeper context on threats observed by OverWatch in your environment.
  Included Component
Two-Way Communications via Slack and Email
Get on-demand access to expertise via multiple channels.
  Included Component
Proactive Closed-Loop Communications
OverWatch Elite analysts perform proactive 24/7 outreach for critical, active threats that are not addressed within the first 60 minutes.
  Included Component
Threat Hunting and Investigation Coaching
OverWatch Elite provides tailored coaching for your team on best practices for threat hunting and investigations in the Falcon console.
  Included Component
Tailored Threat Reports and Briefings
Meet with your Overwatch Elite analyst and other OverWatch experts to review your security posture and gain hunting insights relevant to your industry.
  Included Component
Overwatch Elite Global Insights
OverWatch analysts deliver contextual details and global insights through exclusive quarterly briefings to help organizations understand and act faster.
  Included Component


Download the CrowdStrike Falcon Overwatch Datasheet (.PDF)

It appears you don't have a PDF plugin for this browser. No biggie... you can click here to download the PDF file.