Skip to main content
ThreatHunt and ThreatContain revealed.See the announcements
Solutions · supporting products & add-ons

The full catalog,
behind the flagships.

Every flagship is backed by white-label supporting products, and a system of outcome-named capabilities that say what they do, not which vendor module powers them.

Supporting managed services

Four products.
Never around you.

Included inside the flagship tiers, and available standalone where it makes sense for the partner.

Managed SIEM · index-free

ThreatLog™

Managed SIEM powered by CrowdStrike Falcon Next-Gen SIEM. Index-free, built on Falcon LogScale. Included inside every flagship tier, and available as a standalone managed service.

Threat intelligence · CrowdStrike OEM

ThreatIntel™

CrowdStrike-OEM threat intelligence that enriches detection and hunting across the portfolio. Every finding is cross-referenced against global adversary intelligence.

Posture assessment · land motion

ThreatAssess™

A full-platform posture assessment that surfaces gaps and builds the case for ThreatRespond™ or ThreatDefend™. Bundled as a 60-day trial inside ThreatDefend™ Advanced.

On-prem collection · Cribl Stream

ThreatSensor™

A virtual appliance powered by Cribl Stream for on-prem log collection: 400+ source types, air-gap ready. ThreatRespond™ + ThreatSensor™ onboarding takes about an hour.

The Threat[verb] system

Outcome names,
not vendor jargon.

Externally, capabilities are named by what they do. The underlying technology stays internal; partners and clients see the outcome.

ThreatGuard™Endpoint detection & response
ThreatMap™Asset discovery & shadow IT
ThreatScan™Scanless vulnerability assessment
ThreatID™Identity threat detection & response
ThreatExpose™Exposure management (ThreatDefend)
ThreatOverWatch™Elite global threat hunting (Premium)
ThreatContainActive containment (Advanced+)
ThreatHuntSOC proactive threat hunting
ThreatSurface™Attack surface visibility
ThreatWatch™Dark web credential monitoring
ThreatBrowse™Browser security
ThreatAI™AI detection & response (ThreatDefend)
// ThreatRespond add-ons are agent-agnostic · Falcon-dependent capabilities belong to ThreatDefend
We're online · book a SOC walkthrough today

Compose the coverage
each client needs.

Start with a flagship, layer the supporting products that fit. We’ll map it to your book of business; no SKU dumps, no upsell games.