top of page

CrowdStrike Invests in Above Security to Bring AI-Driven Insider Risk Investigations to Falcon

  • 6 days ago
  • 2 min read

Above Security’s integration with CrowdStrike Falcon aims to replace fragmented insider threat alerts with automated, investigation-ready cases.


CrowdStrike is placing a strategic bet on agentic AI for insider risk management.


At Black Hat USA 2026, Above Security announced an investment from the CrowdStrike Falcon Fund alongside a new integration with the CrowdStrike Falcon platform. The partnership is designed to help organizations investigate potentially dangerous employee, contractor, and machine activity without relying solely on static policies or teams of specialized analysts.


Above operates an AI-native managed insider threat platform built around continuously running investigative agents. These agents analyze activity across user identities, enterprise applications, data transfers, and business workflows. Instead of generating another isolated security alert, the platform assembles a case containing a behavioral timeline, supporting context, risk reasoning, and recommended response actions.


The CrowdStrike integration gives those agents access to endpoint, identity, and third-party telemetry collected through Falcon Next-Gen SIEM. Above can correlate that data into completed insider risk investigations and send the resulting cases back into Falcon, allowing security teams to review and act on findings within their existing operational environment.

The arrangement reflects a broader effort across cybersecurity to use AI agents for investigative work that traditionally required significant manual analysis. Insider risk is particularly challenging because suspicious behavior does not always involve malware or an obviously compromised account. Employees may access sensitive information legitimately before moving, copying, or exposing it in ways that violate company policy or create business risk.


"The Falcon Fund invests in companies developing innovative technologies that solve meaningful cybersecurity challenges,” said Michael Sentonas, President of CrowdStrike. “Above has built a compelling agentic approach to insider risk management. We're excited to open another path to legacy SIEM transformation and support the team as they continue to innovate and bring new capabilities to organizations around the world."


For Above, the partnership provides both technical distribution through Falcon and access to CrowdStrike’s global customer base.


“CrowdStrike's investment validates the principle Above was built on: the next generation of insider risk won't be built on policies – it will be built on investigation,” said Aviv Nahum, Co-founder and CEO of Above Security. “By combining Above's AI investigative agents with CrowdStrike's platform and go-to-market reach, we’re helping organizations operationalize insider risk management at scale.”


The investment follows Above’s participation in the CrowdStrike Cybersecurity Startup Accelerator, where it was selected from nearly 1,000 applicants and finished as runner-up at RSAC 2026. It also comes after a separate $50 million funding round backed by Ballistic Ventures, Merlin Ventures, and Norwest.


The challenge now is proving that autonomous investigations can deliver reliable context without overwhelming analysts with machine-generated conclusions. If Above and CrowdStrike succeed, insider risk could become less of a specialized security program and more of a built-in outcome of the modern security operations platform.

bottom of page