CrowdStrike Unveils Groundbreaking Managed Threat Hunting Solution at RSA 2025
April 28, 2025 – San Francisco, CA – In a major leap forward for cybersecurity, CrowdStrike Holdings Inc. (NASDAQ: CRWD) introduced its Falcon® Adversary OverWatch Next-Gen SIEM during the RSA 2025 conference. This pioneering solution marks the first instance of managed threat hunting extending to third-party data, significantly enhancing security visibility across various attack surfaces that have traditionally been overlooked.
1. Addressing the Evolving Threat Landscape
As cyber adversaries become increasingly sophisticated, they exploit vulnerabilities across a myriad of platforms. Threat groups such as FAMOUS CHOLLIMA and OPERATOR PANDA deploy tactics that allow them to infiltrate networks and move laterally with alarming speed. CrowdStrike's latest innovation aims to counter these threats by providing relentless, expert-led threat hunting that reaches beyond conventional endpoint and cloud environments.
Adam Meyers, head of counter adversary operations at CrowdStrike, emphasized the urgency of this advancement: “Today’s adversaries move incredibly fast and thrive on the complexity of modern environments. They exploit the sprawl of IT and security tools to gain an edge, while defenders are left struggling to stitch together disjointed data. With OverWatch now hunting across third-party data, we’re eliminating the blind spots that adversaries rely on.”
2. Key Features of Falcon Adversary OverWatch
CrowdStrike's Falcon Adversary OverWatch and Next-Gen SIEM introduce a suite of powerful features designed to transform Security Operations Centers (SOCs) and enhance threat detection:
1. Expert-Led Threat Hunting Across All Attack Surfaces
This feature integrates 24/7 threat hunting capabilities with first-party endpoint, identity, cloud, and third-party data through Falcon Next-Gen SIEM. By expanding coverage to unmanaged infrastructures, the solution exposes hidden threats that attackers often exploit.
2. Advanced User and Entity Behavior Analytics (UEBA) and Case Management
Leveraging advanced machine learning, Falcon Next-Gen SIEM analyzes user behavior to detect insider threats and stealthy adversaries. The system employs AI-driven risk scoring, entity resolution, and automated workflows, empowering security teams to minimize false positives, connect related activities, and investigate efficiently.
3. Unified Identity Security
Combining Falcon® Identity Protection with Falcon Next-Gen SIEM enables security teams to detect and prioritize identity-based threats in real-time. Additionally, the integration with Falcon Fusion SOAR automates critical Active Directory actions, such as disabling compromised accounts and enforcing Multi-Factor Authentication (MFA), thus ensuring rapid response capabilities.
4. CrowdStrike Pulse Services
To further assist customers in transforming their SOCs, CrowdStrike offers Pulse Services, which focus on reducing active risk through tailored solutions like ransomware readiness planning and cyber resiliency uplift. These modular, expert-led engagements enhance response times and fortify operational resilience.
3. Conclusion
CrowdStrike’s Falcon Adversary OverWatch Next-Gen SIEM sets a new benchmark in the cybersecurity industry, tackling the challenges posed by modern adversaries and their tactics. With an emphasis on unified visibility and expert-led detection, this innovative solution is designed to offer organizations the early insights needed to prevent breaches across all attack surfaces.
For more information about CrowdStrike’s latest developments in SOC innovation, attendees at RSA 2025 can visit booth N-6144, read the company’s blog, or register for the virtual event titled "SOC in Fast-Forward: Powered by AI. Driven by Experts."
As cyber threats continue to evolve, CrowdStrike stands at the forefront of cybersecurity innovation, committed to its mission to stop breaches and protect enterprises from emerging risks.