CrowdStrike Expands QuiltWorks to Strengthen Falcon SIEM as AI-Security Control Plane


SIEM
Security information and event management software that collects and analyzes security data from across an organization to support detection, investigation and response.
Telemetry pipeline
A system for moving, filtering and normalizing security data from different tools so it can be analyzed or routed to other platforms.
Agentic remediation
The use of AI agents or automated workflows to recommend, initiate or complete security fixes, often with human approval controls.
Exposure window
The period between when a vulnerability or risky condition is discovered and when it is mitigated enough to reduce the likelihood of exploitation.
CrowdStrike
news
CrowdStrike Expands Project QuiltWorks Across the Tech Ecosystem, Uniting More Data Sources to Secure Frontier AI Risk
“Project QuiltWorks now ingests real-time partner data from Abnormal AI, Artemis Security, AttackIQ, ExtraHop, HackerOne, Horizon3, Netskope, Picus Security, Rubrik, SafeBreach, Terra Security and Zscaler into Falcon Next-Gen SIEM.”
CrowdStrike Investor Relations
news
CrowdStrike Expands Project QuiltWorks Across the Tech Ecosystem, Uniting More Data Sources to Secure Frontier AI Risk
“The investor-relations release verifies the date, partner list, SIEM ingestion language and CrowdStrike’s framing around broader telemetry, attack-path analysis and vulnerability prioritization.”
CrowdStrike
news
CrowdStrike Launches Falcon IQ to Operationalize Project QuiltWorks at Machine Speed
“Falcon IQ ties Project QuiltWorks to NVIDIA Nemotron, Charlotte AI AgentWorks, more than 50 agents and workflows for assessment, prioritization and remediation automation.”
CrowdStrike Investor Relations
CrowdStrike Brings the Falcon Platform to Snowflake, Unifying Security and Data at Enterprise Scale
CrowdStrike
CrowdStrike Brings CLEAR's Verified Human Identity into the Falcon Platform
StreetInsider / Business Wire
CrowdStrike Expands Project QuiltWorks Across the Tech Ecosystem, Uniting More Data Sources to Secure Frontier AI Risk
Real-time telemetry
CrowdStrike says QuiltWorks now ingests real-time data from partners including Abnormal AI, HackerOne, Netskope, Rubrik and Zscaler into Falcon Next-Gen SIEM.
Agent workflows
Falcon IQ adds an agent layer tied to QuiltWorks, with CrowdStrike citing more than 50 agents for assessment, prioritization and remediation.
SIEM control plane
The expansion positions Falcon Next-Gen SIEM as a hub for correlating telemetry, vulnerability context, identity signals and remediation workflows.
CrowdStrike said Monday that Project QuiltWorks now ingests real-time data from more security partners into Falcon Next-Gen SIEM, positioning the platform as a central control plane for detecting, prioritizing and remediating AI-era security risks.1
The expansion brings telemetry from Abnormal AI, Artemis Security, AttackIQ, ExtraHop, HackerOne, Horizon3, Netskope, Picus Security, Rubrik, SafeBreach, Terra Security and Zscaler into Falcon Next-Gen SIEM, according to the company’s August 31 announcement.1 CrowdStrike’s investor-relations release framed the move around broader telemetry ingestion, attack-path analysis and vulnerability prioritization, rather than a conventional partner marketplace update.2
The announcement matters because CrowdStrike is trying to make Falcon Next-Gen SIEM the layer where disparate signals — vulnerability reports, validation data, network telemetry, SaaS and cloud activity, backup and recovery context, offensive testing results and threat intelligence — can be normalized and acted on. The company said Falcon Onum supports real-time data pipelines, filtering and in-pipeline analysis before information reaches downstream detection and response workflows.1
That reflects a broader enterprise-security shift: SIEMs are being recast from passive repositories for logs and alerts into operational systems that orchestrate AI-assisted response. For CrowdStrike, QuiltWorks is the data-fabric element of that strategy, while Falcon IQ and Charlotte AI provide the agentic workflow layer for analysis, prioritization and remediation.3
The partner list spans several categories of security telemetry. Abnormal AI contributes email and messaging-security context; HackerOne adds vulnerability and bug bounty findings; Netskope and Zscaler provide cloud, web and zero-trust access telemetry; Rubrik brings resilience and recovery context; and AttackIQ, Horizon3, Picus Security, SafeBreach and Terra Security contribute validation and exposure data from offensive testing and security-control assessment workflows.1
The value CrowdStrike is claiming is not simply that more vendors can send data into Falcon. The company says QuiltWorks uses partner feeds to enrich Falcon Next-Gen SIEM with more context for attack paths, vulnerability prioritization and remediation decisions.2 In practice, that means a vulnerability finding could be evaluated against runtime telemetry, exploitability signals, identity and access context, network exposure and control-validation results before a security team decides what to fix first.
That differs from queue-based vulnerability management, where scanners and bug reports often generate large backlogs that analysts must triage manually. CrowdStrike’s pitch is that Falcon can use broader real-time telemetry to identify which exposures are most likely to be exploited and which remediation actions should come first.1
CrowdStrike separately announced Falcon IQ, which it described as the mechanism for operationalizing Project QuiltWorks “at machine speed.”3 Falcon IQ uses NVIDIA Nemotron and Charlotte AI AgentWorks, and CrowdStrike said it includes more than 50 agents for assessment, prioritization and remediation workflows.3
The Falcon IQ announcement shows how QuiltWorks data is intended to be used. Partner telemetry is not collected only for search or alerting; CrowdStrike says Falcon IQ correlates it with customer telemetry and threat intelligence, then applies partner playbooks and agent workflows to help validate vulnerabilities, prioritize fixes and automate remediation tasks.3
A syndicated Business Wire version of the Falcon IQ release described workflows for vulnerability validation and prioritization, runtime remediation, automated playbooks and customer-facing progress dashboards.7 Those capabilities show CrowdStrike is trying to close the loop between finding an exposure, determining whether it is exploitable in a specific environment and starting the work needed to reduce risk.
CrowdStrike’s QuiltWorks expansion also fits into a larger data strategy around Falcon Next-Gen SIEM. In a related August 31 announcement, the company said it was bringing the Falcon platform to Snowflake, allowing Falcon Next-Gen SIEM to correlate Snowflake data and support federated search across enterprise datasets.4 The same announcement described Falcon Onum as a way to route security telemetry across destinations, reinforcing CrowdStrike’s focus on data movement and normalization as core SIEM functions.4
That architecture matters for enterprise AI security because many relevant risk signals sit outside traditional endpoint telemetry. AI systems may touch code repositories, SaaS applications, identity systems, cloud storage, data warehouses, collaboration tools and third-party APIs. A SIEM that cannot ingest and correlate those signals in near real time may struggle to identify the practical blast radius of a newly discovered vulnerability or misconfiguration.
CrowdStrike is also extending Falcon’s control-plane role into identity and workflow decisions. In another August 31 announcement, the company said it would bring CLEAR’s verified-human identity capability into Falcon, allowing identity-verification results to inform allow, investigate or block decisions through Falcon Next-Gen SIEM and Charlotte Agentic SOAR.5 While separate from QuiltWorks, the CLEAR integration points in the same strategic direction: Falcon is being positioned as the place where telemetry, identity context and automated response intersect.
The operational test for QuiltWorks is whether these integrations can reduce exposure windows — the time between discovery of a weakness and meaningful mitigation. Security teams already have abundant data; the harder problem is determining which findings are urgent, which are exploitable, which affect critical assets and which can be safely deferred.
CrowdStrike’s announcement claims Falcon Onum pipelines can ingest, filter and analyze partner data in real time, while Falcon IQ can correlate that information with telemetry and threat intelligence.6 If effective, that could help teams move from static severity scores toward context-specific prioritization based on exploitability, attack paths and business impact.
The challenge is execution. More telemetry can improve decisions, but it can also increase noise if data models, asset context and remediation workflows are not tightly integrated. Agentic remediation also raises governance questions: enterprises will need controls over which actions agents can take automatically, which require analyst approval and how results are audited.
For now, CrowdStrike’s QuiltWorks expansion is a concrete example of how major security vendors are reworking SIEMs for AI-speed operations. The announcement is less about adding more logos to an ecosystem than about whether a SIEM can become the system that continuously absorbs external security signals, ranks exposures and coordinates remediation before attackers exploit the gap.
Comments