Alliances · CrowdStrike Center of Excellence

From licence to fully operational.

CrowdStrike Falcon is one of the most capable security platforms in the industry, but most environments run only a fraction of what they have licensed. Our CrowdStrike Center of Excellence is where that gap closes — modules implemented, tuned, and operated by engineers who run Falcon in production every day.

The practice

Engineers who run Falcon in production.

As a CrowdStrike partner we resell the platform, deliver professional services on it, and operate it every day, with engineers certified across the Next-Gen SIEM and Cloud specializations (CCSE, CCCS). The practice exists because platform outcomes track operator skill far more than module count — and in FY2026 CrowdStrike recognized that work with two partner awards.

FY2026
Canada Technical Champion of the Year

CrowdStrike Partner Award recognizing technical depth on the Falcon platform — the engineering side of the practice.

FY2026
Canada Sales MVP of the Year

CrowdStrike Partner Award recognizing performance across the year’s engagements.

Coverage

Modules we operationalize.

Endpoint & device security

Prevent, Device Control, FileVantage and Firewall Management brought to production-grade maturity.

Cloud security

CNAPP, container security, and cloud detection and response across AWS, Azure and GCP.

Identity security

Identity Threat Protection, SSPM and Privileged Access, closing the identity-to-detection gap.

Next-Gen SIEM

Essentials through Premium, tuned for signal over noise.

AI & agentic security

Charlotte AI adoption and AIDR coverage across your workforce and autonomous agents.

Program governance

Advisory, roadmap and stakeholder alignment behind every technical engagement.

People & enablement

Resident engineers, staff augmentation and role-based training that build lasting capability.

Managed operations

24x7 monitoring, tuning and hunting across every module above.

CSC-01of 12 · Onboarding & activation

Onboarding & Launch

Every licensed module live, and configured against your environment.

We stand up new Falcon deployments from day one: onboarding, Prevent and Insight configured against your environment rather than a generic template. Endpoint modules, forensics, data protection, exposure management, XIoT and Falcon for IT are each brought to a working baseline before handoff to steady-state operations, delivered across Essentials, Advanced and Premium tiers.

  • Essentials, Advanced & Premium tiers
  • Endpoint Security launch
  • Forensics & Data Protection activation
  • Exposure Management, XIoT & Falcon for IT
Read moreRead less

What's included

  • Falcon Launch for Platform Services: Essentials, Advanced, Premium
  • Falcon Platform Onboarding, Falcon Prevent and Insight
  • Falcon Platform Endpoint Security (Device Control, FileVantage, Firewall Management)
  • Falcon Forensics
  • Falcon Data Protection
  • Falcon Exposure Management
  • Falcon XIoT
  • Falcon for IT
  • Falcon Insight/Prevent detection analysis, remediation & normalization
CSC-02of 12 · Optimization & expansion

Add-On & Optimization

Take a working deployment to full maturity.

Once Falcon is live, the work shifts to depth: migrating CIDs, hardening policy, onboarding dashboards, and integrating Next-Gen SIEM with your existing intel workflows. This is where a functioning platform becomes a tuned one — improving coverage, reducing noise, and getting more out of what you already licensed.

  • CID migration & platform assurance
  • Endpoint, forensics & data protection hardening
  • Dashboard build-out
  • Next-Gen SIEM & intel integration
Read moreRead less

What's included

  • Falcon Platform CID Migration
  • Falcon Platform Onboarding, Prevent and Insight add-ons
  • Falcon Platform Endpoint Security hardening
  • Falcon Forensics and Falcon Data Protection expansion
  • Falcon Exposure Management and Falcon for IT
  • Falcon Dashboards
  • Falcon Assurance & Optimization
  • Falcon XIoT
  • Next-Gen SIEM add-on services
  • Counter Adversary Operations intel SIEM integration
CSC-03of 12 · Cloud workloads

Cloud Security

Cloud attack paths, found and closed.

We operationalize Falcon’s cloud stack end to end, from posture and container security through active detection and response, giving you one detection fabric across AWS, Azure and GCP instead of three disconnected tools.

  • CNAPP + container security
  • Proactive cloud posture management
  • Cloud detection & response (CDR)
Read moreRead less

What's included

  • Falcon Platform Services for Cloud: CNAPP with Containers
  • Falcon Platform Services for Cloud: Proactive Security
  • Falcon Platform Services for Cloud: Cloud Detection & Response with Containers
CSC-04of 12 · Identity attack surface

Identity Security

Close the identity path before it becomes lateral movement.

Identity is the attack path most environments leave open. We bring Falcon’s identity modules into your core detection workflow, from premium identity security through SaaS posture and privileged access, so identity threats are caught rather than only logged.

  • Next-Gen Identity Security, Premium & Standard
  • Identity Threat Protection
  • SaaS Security Posture Management
  • Privileged Access
Read moreRead less

What's included

  • Falcon Platform Services for Identity: Next-Gen Identity Security Premium
  • Falcon Platform Services for Identity: Next-Gen Identity Security
  • Falcon Identity Threat Protection
  • Falcon Shield (SSPM)
  • Falcon Privileged Access
CSC-05of 12 · Detection & analytics

Next-Gen SIEM

Signal over noise, at any scale.

We design, deploy and optimize Falcon Next-Gen SIEM across Essentials, Advanced and Premium tiers — onboarding telemetry, configuring detections and use cases, and aligning data to threat and incident workflows for faster investigations.

  • Log source & telemetry onboarding
  • Detection & use-case configuration
  • Essentials through Premium coverage
Read moreRead less

What's included

  • Falcon Platform Services for Next-Gen SIEM: Essentials, Advanced, Premium
  • Log source and telemetry onboarding
  • Detection engineering and use-case configuration
  • Alignment of data to threat and incident workflows
CSC-06of 12 · AI & agentic operations

AI & Agentic Security

The AI layer, secured and put to work.

We operationalize both sides of Falcon’s AI capability: securing how your workforce and AI agents interact with models, and deploying Charlotte AI so your own SOC works faster.

  • Charlotte AI Detection Triage & Response Agents
  • Charlotte AI AgentWorks
  • AIDR for Workforce
  • AIDR for Agents
Read moreRead less

What's included

  • Charlotte AI enablement, including the Detection Triage Agent, Response Agent, and Charlotte Agentic SOAR workflow automation
  • Charlotte AI AgentWorks configuration for custom, no-code security agent development
  • Falcon Platform Services AIDR for Workforce
  • Falcon Platform Services AIDR for Agents
CSC-07of 12 · Health & risk visibility

Platform Health & Risk Assessments

Know exactly where your platform stands.

Visibility into deployment health, coverage and risk exposure across endpoint, identity and cloud. We identify configuration gaps, misalignments and maturity blockers, then deliver a prioritized roadmap alongside dedicated program management and Onum data pipeline support.

  • Deployment health & coverage review
  • Configuration gap identification
  • Prioritized remediation roadmap
Read moreRead less

What's included

  • Falcon Platform Services Health Check
  • Falcon Platform Services Program Manager
  • Falcon Platform Services for Onum
CSC-08of 12 · Governance & roadmap

Advisory & Strategy Services

Strategic guidance, not just technical delivery.

Beyond implementation, we align stakeholders, identify capability gaps, and define program roadmaps that translate security goals into actionable execution — keeping platform adoption tied to business risk rather than module count.

  • Stakeholder alignment
  • Capability-gap identification
  • Roadmap & adoption planning
Read moreRead less

What's included

  • Falcon platform adoption roadmap development
  • Capability-gap and maturity-blocker identification
  • Executive and board-level Falcon program reporting
CSC-09of 12 · Embedded delivery

Resident Engineering & Staff Augmentation

Dedicated Falcon expertise, inside your environment.

For organizations that need sustained, hands-on capability, we embed resident engineers and augmented staff directly into your team, matched to the specialization your environment needs most — providing capacity and knowledge transfer without adding headcount.

  • Platform Engineer
  • Next-Gen SIEM Engineer
  • Self-Hosted LogScale Engineer
  • Platform Responder
Read moreRead less

Resident specializations

  • Platform Engineer
  • Next-Gen SIEM Engineer
  • Self-Hosted LogScale Engineer
  • Platform Responder

How it works

Residents are engaged under the CrowdStrike Resident Services general terms, with objectives agreed per specialization. Flexible staff augmentation models cover sustained platform capacity where a full resident engagement is more than you need.

CSC-10of 12 · Capability building

Training & Enablement

Give your team the skills to operate Falcon with confidence.

Technology without trained operators loses value fast. We deliver role-based technical training and workshops so your internal team can run day-to-day operations independently, with us available for the work that needs deeper expertise.

  • Role-based technical training
  • Threat hunting workshops
  • Knowledge transfer in every engagement
Read moreRead less

What's included

  • Role-based Falcon platform training by module
  • Threat hunting and detection engineering workshops
  • Response playbook development workshops
CSC-11of 12 · 24x7 operations

Managed CoE / MSSP

Falcon, operated around the clock.

Our Managed CrowdStrike Center of Excellence runs your Falcon platform as a co-managed or fully managed service: monitoring, tuning, hunting and reporting every day, not just at renewal.

  • 24x7 monitoring & detection triage
  • Continuous policy tuning
  • Proactive threat hunting
Read moreRead less

What's included

  • 24x7 monitoring, detection triage and response across EDR, Identity, Cloud and Next-Gen SIEM
  • Ongoing policy administration, detection tuning and false-positive reduction
  • Proactive threat hunting and adversary emulation validation
  • Exposure and vulnerability prioritization across the Falcon ecosystem
  • Governance of Charlotte AI agents and AIDR policies as part of daily operations
  • Continuous platform roadmap planning and module adoption strategy
CSC-12of 12 · Continuous advisory

CrowdStrike Pulse Services

Ongoing advisory, not a once-a-year checkup.

Pulse Services keep a named advisory relationship running between major engagements, tracking your risk posture, threat landscape changes, and program maturity continuously rather than resetting the conversation every twelve months.

  • Named advisory relationship
  • Continuous risk tracking
  • Regular cadence check-ins
Read moreRead less

How it connects

Pulse is the advisory cadence around the CrowdStrike platform work itself. Pulse tracks the risk and maturity picture; the rest of the Center of Excellence implements, tunes and operates the modules underneath it.

Alongside incident response

Pulse is frequently the standing relationship that follows an incident response engagement, keeping the risk picture current once the immediate work is closed.