CrowdStrike gives AI agents an identity provider, parallel SOC investigations and package blocking
CrowdStrike Holdings Inc. today announced three additions to its Falcon platform: an identity provider built for artificial intelligence agents, a rebuilt investigation layer that runs multiple Charlotte AI agents across security domains at once, and a feature that blocks malicious open-source packages on the endpoint before their embedded code can run.
All three were detailed at the company’s Fal.Con 2026 conference in Las Vegas this week. The identity product, the CrowdStrike Agentic Identity Provider or Agentic IdP, fills a gap in Continuous Identity, the real-time authorization model CrowdStrike detailed at Identiverse in June and built on technology from its $740 million acquisition of SGNL Inc. Continuous Identity decides whether an agent should be allowed to do something at a given moment. Agentic IdP handles the step before that, establishing what the agent is in the first place.
Companies currently stand in for agent identity using service accounts, application programming interface keys and workload identities. None of those were designed for software that takes autonomous action on a person’s behalf and delegates work to sub-agents.
CrowdStrike’s position is that an identity provider is the system of record every later security decision rests on, and that agents show up without the logins, passwords and manual onboarding that give human accounts their authority.
“Continuous Identity modernized identity security for the agentic era, but you cannot continuously authorize an identity you were never able to establish, and traditional identity providers break the moment an agent acts on its own,” said Scott Kriz, general manager of Continuous Identity at CrowdStrike. “Agentic IdP is the identity provider for AI agents.”
Registration runs through Falcon Guardian, the agent discovery and enforcement product CrowdStrike launched earlier at the conference. Guardian finds agents across the enterprise and Agentic IdP registers each one as it comes online, under a single directory.
Each agent is issued a cryptographically verifiable identity that CrowdStrike said cannot be spoofed or shared, and only agents holding one are eligible for authorization. Access decisions then fall to Continuous Identity.
Credentials are not handed to the agent. Agentic IdP brokers tokens scoped to the minimum access required for a given task and for the minimum time, an approach meant to eliminate standing privilege. Every action an agent takes is bound to the human or workload it is acting for, so activity traces back to an accountable party.
The second announcement rebuilds how investigations run. Charlotte AI now dispatches agents to endpoint, identity, software-as-a-service, cloud and network in parallel rather than one after another, working a single investigation across all of them at once. CrowdStrike said the change turns work that took hours into minutes.
CrowdStrike’s argument for the change is that first-generation AI tools for the security operations center send one agent per alert and work through them in sequence, which returns a fragment from a single domain rather than a verdict.
“AI agents in the SOC are table stakes. Agents working together across every domain, on the same investigation, that’s the new standard,” said Michael Sentonas, president of CrowdStrike. “CrowdStrike’s architecture and expert validation make this possible, and confidently answer the question every CISO is asking: how do I trust what my agents found, and how do I know it’s right?”
Holding the agents together is a shared context layer, which CrowdStrike described as persistent memory spanning every agent, investigation and tenant. It sits on Enterprise Graph, the data layer CrowdStrike introduced at last year’s Fal.Con. What one agent establishes, the rest can use, which removes handoffs between them.
The company said the platform generates close to four trillion events a day across those five domains, and that decisions made by its analysts during managed detection and response and incident response engagements are fed back into the agents.
Investigations now take in attacks on enterprise AI systems as well, including model abuse, prompt injection and data exfiltration through AI assistants. Agents return a verdict with staged response actions and show the reasoning behind it rather than a bare conclusion.
Two supporting pieces arrived with it. Certified Data Pipelines, built on Falcon Onum streaming technology, filter noise at ingestion and run detection in the stream before data lands, which CrowdStrike said cuts storage costs by up to 50% while connecting third-party sources into Falcon Next-Gen SIEM.
Charlotte Agentic SOAR now houses Charlotte AI AgentWorks and Falcon Foundry in one workspace, where teams build no-code agents on a model of their choosing and set an autonomy level for each workflow, from human approval through to fully autonomous execution. Bidirectional Model Context Protocol support connects outside agents into Falcon and CrowdStrike’s own agents out to external tools.
The third announcement, Real-Time Supply Chain Attack Protection, points the Falcon sensor at a different problem. Coding agents now assemble applications from packages pulled off public registries faster than anyone can review what arrives, and a poisoned package runs its code the moment it installs.
The feature intercepts package manager transactions at the command line, covering npm install and pip install across npm and PyPI on Windows, macOS and Linux. The block lands before any embedded install script runs. Coverage extends to any endpoint where agentic applications run rather than developer workstations alone.
Security teams can set granular controls over what code reaches their machines, including a minimum package age requirement. That control screens out freshly published typosquats and recently hijacked releases, a category that accounts for a large share of package compromises.
When a package is flagged, Falcon runs a lookback across every endpoint and triggers remediation through Charlotte Agentic SOAR. A global inventory records every package installed across the fleet, so teams can locate affected machines once a compromise becomes public rather than reconstructing the list by hand.
The scale of the problem shows up in CrowdStrike’s own threat research. The company’s 2026 Threat Hunting Report, published in August, found that North Korea-linked adversary STARDUST CHOLLIMA poisoned 131 trusted AI framework packages, while eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day.
“Attackers know that compromising one trusted package can give them a path into thousands of organizations. That makes the software supply chain one of the most powerful attack surfaces in the AI era,” Sentonas said. “The endpoint is where malicious code executes, and only CrowdStrike turns it into the control point that stops the attack.”
CrowdStrike said standalone scanners, proxies and browser-based tools flag compromises days after a poisoned package has landed, by which point the code has already run. Legacy endpoint tools were built to catch executables, the packages that assemble AI software.
None of the three announcements carried a general availability date.
Taken together, they extend the argument CrowdStrike has made all week, that the endpoint and the identity layer are where agent activity can actually be caught, and that the investigation on top of them has to move as fast as the attack. Falcon Guardian, the Falcon IQ agent fleet and a set of security-specific frontier models developed with Nvidia Corp. all arrived earlier in the conference.
Photo: Robert Hof/SiliconANGLE
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.