CrowdStrike Falcon Aims to See Inside the AI Factory

CrowdStrike Falcon Aims to See Inside the AI Factory

Analyst(s): Fernando Montenegro
Publication Date: June 8, 2026

CrowdStrike is expanding Falcon’s visibility into AI infrastructure through a new integration with NVIDIA DOCA Argus. The move reflects a broader shift toward securing agentic AI environments at the data, storage, and infrastructure layers as autonomous AI systems create new operational and security risks.

What is Covered in This Article:

  • CrowdStrike is integrating NVIDIA DOCA Argus telemetry into Falcon Next-Gen SIEM to improve visibility across AI factory environments.
  • NVIDIA Vera BlueField-4 STX introduces in-silicon security capabilities designed to monitor and govern agentic AI workloads.
  • The integration allows CrowdStrike to correlate infrastructure telemetry with endpoint, identity, cloud, and third-party security data already available within Falcon.
  • CrowdStrike is among several cybersecurity vendors building on NVIDIA’s DOCA telemetry layer, highlighting the emergence of AI factory security as a broad platform competition.
  • The announcement highlights growing competition among cybersecurity vendors to establish visibility and control within AI factory environments.

The News: CrowdStrike announced plans to integrate NVIDIA DOCA Argus telemetry into Falcon Next-Gen SIEM as part of an expanded collaboration with NVIDIA around AI factory security. The integration extends Falcon’s visibility into infrastructure-level activity generated by NVIDIA Vera BlueField-4 STX, allowing security teams to correlate agent behavior, data access patterns, network activity, and infrastructure telemetry with endpoint, identity, cloud, and third-party signals already unified within the Falcon platform.

The announcement follows NVIDIA’s introduction of Vera BlueField-4 STX, a storage processing platform designed for agentic AI environments. DOCA Vault, DOCA Argus, and DOCA Flow provide file access governance, agent activity visibility, and network isolation directly within BlueField-4 silicon, enabling organizations to enforce security controls and monitor activity within the AI data path.

CrowdStrike Falcon Aims to See Inside the AI Factory

Analyst Take: The perimeter has been expanding for years, from endpoints to cloud to identity. AI factories are pushing it further still, into infrastructure layers that most security architectures were never designed to see. CrowdStrike’s integration of NVIDIA DOCA Argus into Falcon Next-Gen SIEM is an early move into that territory, and it won’t be the last.

Infrastructure Telemetry Expands Falcon’s Visibility

DOCA Argus gives CrowdStrike visibility into agent behavior, data access patterns, and network interactions at the infrastructure layer, a layer that has historically generated little usable security signal. Combined with the endpoint, cloud, identity, and third-party telemetry already in Falcon, that creates a materially more complete picture of activity across AI environments.

Futurum’s 1H 2026 Cybersecurity Global Enterprise Decision Maker Survey found integration with existing tools ranked as the second-highest vendor selection factor at 29.3%. CrowdStrike’s ability to absorb and correlate these new signals is becoming a differentiating factor.

CrowdStrike Is Far Beyond Traditional Endpoint Security

CrowdStrike has spent the past several years aggressively expanding beyond its endpoint roots, building a platform that spans identity, cloud, data, and security operations. Its agentic SOC vision, central to Fal.Con 2025, positions Charlotte AI and the broader Falcon platform as the operational backbone for AI-driven security workflows.

The DOCA Argus integration fits that trajectory. AI factories represent a new environment that needs to be instrumented, and Falcon Next-Gen SIEM is the natural destination for that telemetry within CrowdStrike’s architecture. The question is less whether CrowdStrike should be doing this and more whether the infrastructure signals DOCA Argus generates will prove rich enough to materially improve detection and response outcomes in practice.

The Competitive Field Is Taking Shape

CrowdStrike is not alone in recognizing the opportunity. Palo Alto Networks, Cisco, Fortinet, Zscaler, and others are all building on the same DOCA telemetry layer, each emphasizing different outcomes. Palo Alto Networks is the most direct comparison, pairing its Cortex XSIAM integration with Prisma AIRS and hardware-level enforcement mechanisms on BlueField infrastructure, a broader governance posture than CrowdStrike’s visibility-and-correlation approach.

The more interesting question is how differentiation plays out when the underlying telemetry source is common to all of them. Collecting DOCA signals is quickly becoming table stakes. What separates vendors is how they operationalize those signals within their platforms, whether through detection fidelity, response automation, identity context, or integration depth with the broader security stack.

AI Factory Security Is Becoming A Platform Competition

NVIDIA is effectively creating a common telemetry layer through DOCA Argus while allowing ecosystem partners to build differentiated capabilities on top of it. That shifts competition away from simply collecting infrastructure signals and toward how vendors operationalize them within their existing platforms.

The more realistic near-term outcome is less about head-to-head platform battles and more about which vendors can translate raw DOCA signals into workflows that security teams actually use. Working directly with infrastructure telemetry requires expertise and tooling integration that most enterprises will look to their security vendors to provide. That makes operational depth, not telemetry access, the real differentiator.

What to Watch:

  • Will infrastructure telemetry become a required layer of AI security? Most enterprises today rely on endpoint, cloud, and network monitoring. Whether AI factory infrastructure generates signals rich enough to justify a new monitoring layer remains unproven.
  • Can CrowdStrike turn DOCA signals into better detections? Ingesting telemetry is the easy part. The harder question is whether Falcon can convert infrastructure-level signals into higher-confidence detections that meaningfully reduce response times.
  • Will NVIDIA’s 1,000x detection speed claim hold in production? The benchmark compares against existing agentless runtime approaches. STX-based platforms aren’t expected until the second half of 2026, so real-world validation is still ahead.
  • How will enterprises compare vendors building on the same telemetry layer? With DOCA Argus available across the ecosystem, differentiation will come down to detection fidelity, response automation, and governance depth rather than data access.
  • Will security vendors become the primary interface for AI factory telemetry? Vendors that surface actionable insights within familiar operational workflows are better positioned than those expecting enterprises to work directly with raw infrastructure signals.

See the complete announcement on CrowdStrike’s integration of NVIDIA DOCA Argus telemetry into Falcon Next-Gen SIEM on the CrowdStrike website.

Declaration of generative AI and AI-assisted technologies in the writing process: This content has been generated with the support of artificial intelligence technologies. Due to the fast pace of content creation and the continuous evolution of data and information, The Futurum Group and its analysts strive to ensure the accuracy and factual integrity of the information presented. However, the opinions and interpretations expressed in this content reflect those of the individual author/analyst. The Futurum Group makes no guarantees regarding the completeness, accuracy, or reliability of any information contained herein. Readers are encouraged to verify facts independently and consult relevant sources for further clarification.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights From Futurum:

Do AI Factories Signal a New Mandate for Certified Security? — Report Summary

CrowdStrike Deepens Agentic SOC Strategy Across AI Workflows

CrowdStrike Fal.Con 2025: A Vision and a Path to the Human-Led Agentic SOC

Author Information

Fernando Montenegro

Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.

Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.

Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

Related Insights
Fortinet's AI Controls Join the Field. Can Integration Set Them Apart?
July 21, 2026

Fortinet’s AI Controls Join the Field. Can Integration Set Them Apart?

Fernando Montenegro, VP at Futurum, examines why FortiEndpoint's consolidated AI controls are a real buyer win, while platform and SASE integration, not the individual features, will decide whether Fortinet stands...
SCSK Security Launches Prisma Browser to Enhance Cloud Security
July 21, 2026

SCSK Security Launches Prisma Browser to Enhance Cloud Security

SCSK Security Corporation launches Prisma Browser Deployment Support Service, enabling enterprises to implement cloud access control and data protection through standard web browsers, positioning itself to capture meaningful channel partner...
CMMC Pause Signals Compliance Risks for Defense Contractors
July 17, 2026

CMMC Pause Signals Compliance Risks for Defense Contractors

The DoD's CMMC Phase 2 pause has not suspended core federal data protection obligations for Defense Industrial Base contractors. Magna5 urges DIB firms to use this window to close NIST...
Why Ignoring Security in AI Deployments Could Cost You More Than You Think
July 16, 2026

Why Ignoring Security in AI Deployments Could Cost You More Than You Think

Organizations deploying AI without robust security risk data breaches, regulatory failure, and reputational damage—Concentrix shows why integrating security from the start costs less than treating it as an afterthought....
Is F5's New Fleet Management the Key to Cyber Resilience in the AI Era?
July 16, 2026

Is F5’s New Fleet Management the Key to Cyber Resilience in the AI Era?

F5 launched F5 Insight for ADSP v1.2 with advanced fleet management workflows designed to streamline BIG-IP patching and software updates, directly addressing the compression of vulnerability response timelines in the...
Can Anthropic's GRAM 'Off Switch' Make Dual-Use AI Safer Without Killing Utility?
July 10, 2026

Can Anthropic’s GRAM ‘Off Switch’ Make Dual-Use AI Safer Without Killing Utility?

Anthropic and AE Studio introduced GRAM, enabling selective removal of sensitive AI capabilities without retraining, potentially addressing privacy and security concerns for organizations adopting generative AI....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.