List of Crowdstrike Falcon Overwatch Customers
Austin, 78701, TX,
United States
Since 2010, our global team of researchers has been studying Crowdstrike Falcon Overwatch customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased Crowdstrike Falcon Overwatch for Threat Modeling from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using Crowdstrike Falcon Overwatch for Threat Modeling include: Metropolitan Transportation Authority (MTA), a United States based Transportation organisation with 70000 employees and revenues of $21.30 billion, Tabcorp, a Australia based Leisure and Hospitality organisation with 5000 employees and revenues of $1.72 billion, CoreWeave, a United States based Professional Services organisation with 900 employees and revenues of $10.0 million, Greatwaves Netherlands, a Netherlands based Communications organisation with 10 employees and revenues of $2.0 million and many others.
Contact us if you need a completed and verified list of companies using Crowdstrike Falcon Overwatch, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The Crowdstrike Falcon Overwatch customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
CoreWeave | Professional Services | 900 | $10M | United States | CrowdStrike | Crowdstrike Falcon Overwatch | Threat Modeling | 2022 | n/a |
In 2022, CoreWeave deployed the CrowdStrike Falcon platform, including CrowdStrike Falcon OverWatch, to augment security operations. The deployment used CrowdStrike Falcon OverWatch as a Threat Modeling application to protect cloud workloads and endpoints across CoreWeave's high performance GPU cloud in the United States.
The implementation centered on CrowdStrike Falcon OverWatch managed threat hunting and the Falcon platform's detection and investigation capabilities. Functional capabilities implemented included continuous telemetry collection from endpoints and cloud workloads, automated detection and alerting, triage and investigation workflows, and active threat hunting by the OverWatch service to reduce noise and accelerate incident validation.
Operational responsibility focused on the security operations center and incident response functions, with OverWatch operating as an augment to existing SOC workflows rather than a named systems integration. The deployment is documented in CrowdStrike’s customer story and explicitly cites outcomes including a 100x reduction in false positives and hundreds of hours saved annually, demonstrating measurable improvements in detection fidelity and investigation efficiency for CoreWeave.
|
|
|
Greatwaves Netherlands | Communications | 10 | $2M | Netherlands | CrowdStrike | Crowdstrike Falcon Overwatch | Threat Modeling | 2017 | n/a |
In 2017, Greatwaves Netherlands deployed Crowdstrike Falcon Overwatch as a Threat Modeling application. The implementation was focused on the company’s network operations and ISP service stack and was tied directly to monitoring of every router, switch and firewall across its nationwide service footprint.
Crowdstrike Falcon Overwatch was configured to provide threat modeling and hunting support, ingest telemetry and signal correlation, and enable analyst-driven investigation workflows consistent with Threat Modeling capabilities. Operationally the deployment was integrated with Cronitor, which monitors network devices and triggers webhook-driven automations for provisioning and incident response, creating an automated pipeline from device telemetry to security analysis.
Governance and process changes centralized incident response and provisioning ownership in network operations, using webhook orchestration to standardize triage and remediation workflows. The combined Crowdstrike Falcon Overwatch and Cronitor configuration enabled nationwide scaling, proactive support automation and reduced on-site management overhead for Greatwaves Netherlands.
|
|
|
Metropolitan Transportation Authority (MTA) | Transportation | 70000 | $21.3B | United States | CrowdStrike | Crowdstrike Falcon Overwatch | Threat Modeling | 2019 | n/a |
In 2019 Metropolitan Transportation Authority implemented Crowdstrike Falcon Overwatch as a central capability for Threat Modeling and proactive threat hunting within its cybersecurity operations. Crowdstrike Falcon Overwatch was positioned as the enterprise EDR and threat hunting service used to surface behavioral detections and feed threat intelligence enrichment workflows aligned to the MITRE ATT&CK framework.
The implementation emphasized EDR detection configuration, threat intel enrichment, and investigation workflows, with specific use of Crowdstrike Falcon Overwatch for proactive hunting and mapping of detections to ATT&CK techniques. Configuration work included automated detection tuning, development of correlation rules and enrichment pipelines, and scripting for control automation using Python and PowerShell to codify mitigations and guardrails.
Integrations and operational coverage extended across the SOC stack, the GNOSC and CyberComm operations, and enterprise incident response teams, integrating Crowdstrike Falcon Overwatch with Splunk ES, Exabeam UBA and Fusion SIEM, Splunk SOAR, Carbon Black EDR artefacts, IBM QRadar, LogRhythm, FireEye Web MPS, and Nitro SIEM for unified telemetry. The deployment also linked to vulnerability management and scanning tools including Qualys, Tenable Nessus, Rapid7 Nexpose, and Kenna Security, and interfaced with CI CD and infrastructure as code pipelines built on Azure DevOps, Jenkins, Docker, Terraform and Ansible during AWS centered Splunk migrations.
Governance and process work centered on threat modeling from the ground up, collaborating with architects and a Threat Modeling Team to embed threat modeling before development and to define mitigation playbooks. Operational practices adopted behavior driven development and Gherkin based testing for controls, formalized SIEM triage workflows, and aligned incident handling and reporting to audit and compliance frameworks including FISCAM, FISMA, NIST SP 800 53, ISO 27001 and OMB circulars, supporting security operations, incident response, and enterprise threat intelligence functions.
|
|
|
Tabcorp | Leisure and Hospitality | 5000 | $1.7B | Australia | CrowdStrike | Crowdstrike Falcon Overwatch | Threat Modeling | 2020 | n/a |
In 2020, Tabcorp implemented CrowdStrike Falcon OverWatch as part of its broader Falcon deployment. The work is classified under Threat Modeling and was executed within Tabcorp’s security and IT environment in Australia.
Tabcorp incorporated CrowdStrike Falcon OverWatch alongside Falcon Complete and Falcon Intelligence to establish continuous managed threat hunting and enhanced telemetry analysis. Falcon OverWatch was used to provide 24/7 managed threat hunting and analyst-led proactive detection across endpoints and cloud workloads, aligning with standard Threat Modeling workflows for hunting, alert triage and contextual enrichment.
OverWatch was added after the initial Falcon engagement, with the customer story noting that sequencing but not specifying the addition date. Operational coverage was focused on supporting Tabcorp’s cloud migration and managing seasonal business peaks, integrating managed hunting into the companys security operations to centralize detection and response activities.
The deployment tied CrowdStrike Falcon OverWatch, Falcon Complete and Falcon Intelligence into a combined managed detection and threat intelligence posture, and the customer narrative reports improved visibility during the cloud migration and seasonal peaks.
|
Buyer Intent: Companies Evaluating Crowdstrike Falcon Overwatch
- Investment And Development Company, a Seychelles based Construction and Real Estate organization with 110 Employees
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated |
|---|---|---|---|---|---|---|
| Investment And Development Company | Construction and Real Estate | 110 | $14M | Seychelles | 2026-06-26 |