CrowdStrike · Charlotte Agentic SOAR

AI-directed endpoint containment

Charlotte AI, within a configured agentic workflow, can determine whether network containment of a Falcon-managed endpoint is justified and, depending on workflow configuration, either submit the containment for human approval or execute it automatically. The documented action places the endpoint into network containment/isolation; the precise network communications that remain available during containment are not established by the attached public evidence. CrowdStrike's specific containment example is a dated (August 2025) simulation; the attribution of this mechanism to Charlotte Agentic SOAR by name is supported in substance but not explicitly stated by CrowdStrike.

Recorded characteristics

Function
AI-directed network containment of a Falcon-managed endpoint. In CrowdStrike's 4 August 2025 article "AI vs AI: The Cybersecurity Arms Race" (explicitly described as a simulation), a Charlotte AI Agentic Workflow is activated "using CrowdStrike Falcon® Fusion SOAR", which "invokes a foundational model to guide the analyst through triage, judgment, and subsequent containment". CrowdStrike states "we can instruct the model to determine if network containment is justified"; "Charlotte AI may recommend network isolation"; and the workflow "executes conditional response actions", e.g. "isolate the affected endpoint". Containment is described as executed "either through predefined policy or human-approved action". Containment scope: the documented action places the affected endpoint into network containment/isolation. The precise network communications that remain available during containment are not established by the public evidence currently attached to this record. Boundary: this record covers AI-directed network containment of a Falcon-managed endpoint only. Excluded (outside this record): disabling user credentials (which appears in the same example sentence), file quarantine, file deletion, process termination, IOC blocking, firewall modification, Real-Time Response execution, remediation scripts and automatic release from containment.
Data access
Charlotte AI reasons over Falcon platform telemetry and detection context (in the simulation, a Falcon Insight XDR alert and process tree, triage analysis, asset context and analyst-defined thresholds) to decide whether containment is justified. Not claimed: access beyond the Falcon platform data the workflow is configured to use.
Actions
Can take actions
External actions
Yes
Human confirmation
Conditional
Permission basis
Not established
Administrative control
CrowdStrike: security teams "configure which actions get automated - and under what conditions - using Charlotte Agentic SOAR (in workflows) and Charlotte AI AgentWorks (in the case of agents). Actions can be set to execute autonomously or require human approval." Agentic SOAR: "Set the autonomy level for every workflow, from human-in-the-loop approval to fully autonomous execution. Every agent action and workflow execution is logged and auditable." Governance controls listed by CrowdStrike include role-based access controls, execution traces, audit logs, agent version history and rollback, credit caps and configurable approval workflows "that require human sign-off before specified actions execute". Workflow creation or prior administrative configuration is not runtime human confirmation.
Default state
Disabled
Availability
Current first-party statement: "Charlotte AI does not take automated response actions by default." Response automation must be configured through Charlotte Agentic SOAR (workflows) or AgentWorks (agents); "By default, Charlotte AI's prebuilt agents are limited to generating information, summaries, and recommendations. Any actions that affect an organization's environment require explicit configuration and approval by an authorized member of the security team." The availability of Charlotte AI itself is distinct from the default state of this action authority, which is disabled until configured.
Licensing
Licensing for Charlotte Agentic SOAR and automated containment is not publicly established in the sources reviewed. CrowdStrike separately describes an opt-in free Charlotte AI access tier with monthly AI credits; this does not establish entitlement to automated response actions.
External model or provider
CrowdStrike states workflows can be built "with a growing selection of LLMs from Open AI, Anthropic and NVIDIA, or bring your own"; the specific model used for containment decisions is not established.
Limitations and uncertainty
Evidence basis: the specific containment mechanism is established only by CrowdStrike's 4 August 2025 article, which describes a simulation ("For this simulation, prevention capabilities in the Falcon platform were intentionally disabled"). The simulated scenario is not evidence that every production deployment performs autonomous containment. Product-boundary qualification: the article directly establishes AI reasoning within a Charlotte AI Agentic Workflow leading to conditional endpoint containment through Falcon Fusion SOAR; current CrowdStrike documentation states that automated Charlotte AI response actions are configured through Charlotte Agentic SOAR and may execute autonomously or require human approval; current public documentation does not explicitly connect the historical containment example to Charlotte Agentic SOAR by name. The current product attribution is therefore supported in substance by first-party evidence but is not explicitly stated by CrowdStrike; this is part of the reason for partially_verified. Human confirmation recorded as conditional: the documented architecture supports both runtime human approval/rejection ("reviewing and approving, or rejecting, each recommendation before action is taken") and automatic execution under configured workflow policy ("can also be configured to automatically execute actions"). Permission basis recorded as not_established: the public evidence does not establish the runtime identity or credential under which the containment action executes; a passing reference to "role-based permissions" among governance controls does not establish it. The precise network communications that remain available during containment are not established by the public evidence currently attached to this record; detailed containment documentation is behind a customer login. Not publicly established: execution identity; per-action approval enforcement point; release-from-containment behaviour; rate or scope limits on automated containment; failure and recovery behaviour. Monitoring limitation: no currently identified public, monitorable CrowdStrike page directly documents the endpoint-containment mechanism; the monitors track the current product boundary, response-autonomy model, approval model and default behaviour rather than the containment action itself. The dated article is evidence only and is not monitored.

Evidence