Skip to content

UPDATED 12:38 EDT / AUGUST 29 2026

SECURITY

CrowdStrike’s post-Mythos surge: Moat, momentum and the blast-radius test

CrowdStrike Holdings Inc.’s most recent earnings print shows that Anthropic PBC’s Mythos model transformed artificial intelligence security from something chief information security officers needed to worry about down the road into an immediate buying event.

The company’s entrenched position in endpoint  – along with its single lightweight agent, proprietary intelligence and a rapidly expanding portfolio of modules – have converted Mythos urgency into record new logo momentum, record net new annual recurring revenue and what we see as a likely a compressed timeframe to hit $10 billion ARR (a target CrowdStrike set for FY 2031 at last year’s investor day).

Falcon Flex is one of the key mechanisms driving commercial adoption according to CrowdStrike, but buyer research from Qualitate shows that customers think about Flex as more than just a contracting vehicle. Specifically they translate Flex into value: lower complexity, faster deployment and improved unit economics.

The one caution we put forth for CrowdStrike customers is that while every step on your consolidation journey gives Falcon more context and better data, it also gives it more AI authority, which raises the importance of resilience and controlling the AI to contain the potential risks of an expanded blast radius. Nonetheless, the numbers from CrowdStrike’s quarter speak for themselves. Mythos and other highly capable models are proving to be a significant tailwind for CrowdStrike.

In this Breaking Analysis, we’ll dig into how CrowdStrike and Falcon are converting the AI threat from Mythos and other frontier models into platform expansion. We’ll introduce data from an exciting new data intelligence firm, Qualitate, which has conducted many thousands of buyer surveys on CrowdStrike and other firms. We’ll also discuss why containing the new blast radius is a key to operational, technical and financial sovereignty in this AI era.

The post-Mythos ARR pop underscores the momentum

Let’s start with what changed between CrowdStrike’s Q1 and Q2.

In Q1, Mythos wreaked havoc on SecOps teams and quickly became an agenda item at board meetings. The questions to the CISO came at a furious pace: What does this all mean? How exposed are we? What do we do about it? How do we protect ourselves now?

Mythos created chaos.

In Q2, this chaos turned into cash for CrowdStrike as shown by the impressive numbers below. CrowdStrike’s momentum is confirmed by the Qualitate conversation shown in the “Q2. Conversion” box (see full quote below).

CrowdStrike delivered $333 million in net new ARR, up 51% year over year and more than $45 million above the high end of guidance. Ending ARR reached $5.84 billion, with growth accelerating for the fourth consecutive quarter.

New-logo net new ARR hit a record. Gross retention improved. Net dollar retention improved. And management raised its full-year net-new-ARR growth outlook by 630 basis points, to 34% at the midpoint of its guide.

Yes, this was a beat and a raise. But the real news is the trajectory of the business changed. And the stock responded – up over 20% at Thursday afternoon’s close.

Independent buyer evidence supports the thesis

First, let’s introduce you to Qualitate. Qualitate is an AI-native, primary data intelligence platform that automates expert interviews and market research for investors and corporate strategy pros. The company has built the world’s most intelligent AI Moderator to capture expert insights at massive scale – across virtually any industry, including enterprise tech. The firm was founded by Sagar Kadakia, who was the head of data science and one of the founding employees at ETR. Qualitate is bringing non-obvious, proprietary intelligence to its clients and we’re thrilled to be sharing some of their data with you today.

Above is just one example on graphic. First, Qualitate tells us that CrowdStrike is very prominently mentioned in Mythos-related conversations within 1,249 CrowdStrike customer conversations. Here’s the full verbatim quote from a late June 2026 Qualitate CrowdStrike customer survey:

“Our strategy really changed from we didn’t care about this [AI security] that much… to we need to do this because of Mythos and AI capabilities that we expect to accelerate and outperform any kind of vulnerability numbers that we’ve seen before.” – Deputy Group CISO, FinServ (Large Enterprise)

Now we’re not saying Mythos generated every dollar of that $333 million. Falcon Flex, endpoint recovery, SIEM, cloud security, identity, exposure management and large competitive displacements all contributed.

What we can say is we believe the post-Mythos demand environment was an inflection point and it accelerated broader platform momentum that CrowdStrike already had in place. The most obvious post-Mythos evidence is CrowdStrike’s $5.84B ARR, which increased 25% year on year. So our belief is that Mythos heightened the urgency, but the breadth of the Falcon platform gave CrowdStrike multiple ways to monetize it – but we can’t pin it to any single product or module.

Having said that, on its earning call, CrowdStrike mentioned AI detection & response (AIDR) sixteen times, clearly aligning it with the post Mythos surge. Qualitate tells us it is seeing a major uptick in CrowdStrike discussions mentioning AIDR relative to its last study. But, in the next section we’ll try to show why this is more than just an AIDR story.

The post-Mythos tailwind is broad across CrowdStrike’s portfolio

The data from Qualitate highlights an important nuance that’s relevant to our findings today. Much of Qualitate’s Mythos-related buyer comments show up in an application security context. But that doesn’t mean CrowdStrike is missing from app security. Rather this is a top of funnel signal that can lead to downstream buying activity based on where the customer is in the buyer journey. For example, application security can identify code vulnerabilities. But the buyer may also want to know how those vulnerabilities create exposures across its estate, leading to a posture management purchase.

Buyers want to know: Where are we exposed, and can an adversary exploit those weaknesses faster than we can patch them?

Remember the phrase “Patch Tuesday?” It came from firms like Microsoft releasing patches and fixes on the second Tuesday of the month. The not so funny joke was patch Tuesday meant breach Wednesday, implying the hackers would pounce before the updates were put in place. Well the window is no longer twenty-four hours. In fact the idea of a patch window completely changes in the agentic era from how long do I have to implement the fix to continuous patch deployment, where the window becomes a series of “micro-windows” for individual services without human intervention. But there needs to be a window in time in case something goes wrong and I need to roll back.

In the graphic above you can see the momentum across several of CrowdStrike’s businesses. Let’s call out exposure management specifically because it is now front and center in customer conversations. CrowdStrike participates directly with Falcon Exposure Management, which accelerated sequentially in Q2. Project QuiltWorks was launched by CrowdStrike in April of this year. It’s an industry-wide coalition to help organizations find, prioritize, and fix software vulnerabilities discovered by advanced artificial intelligence models. QuiltWorks extends CrowdStrike’s sales motions across the ecosystem, using Falcon and frontier models to discover, prioritize and remediate vulnerabilities. CrowdStrike says the initiative now includes more than 25 partners, with nearly $400 million in total-contract-value pipeline.

But the commercial opportunity does not stop there.

Endpoint ARR accelerated for a fourth consecutive quarter because the endpoint is increasingly where agentic work is consumed and runtime is the most obvious place to stop the breach. AIDR is an incremental module on the same Falcon agent and its ending ARR nearly tripled sequentially. So the customer does not have to deploy another sensor or create another data silo to add AI visibility and response.

Then the momentum continues across the platform.

Next-gen SIEM passed $695 million in ARR. Identity exceeded $585 million, with Falcon Shield up more than 185% and privileged-account security growing more than 35-fold year over year – both important indicators around the rise of nonhuman identities. Cloud security exceeded $905 million in ARR. And collectively, SIEM, identity and cloud produced record Q2 net new ARR.

So the fact that Mythos often enters through application security is not necessarily a problem for CrowdStrike. It is a top of funnel indicator that leads to sales of other modules. Mythos may have opened the door for motions around exposure management, however, CrowdStrike is monetizing risk mitigation across the entire Falcon platform.

And that breadth underscores that CrowdStrike should not be viewed as an endpoint company with a collection of add-ons.

CrowdStrike is no longer only an endpoint company

The headline on the following slide deliberately states the obvious: CrowdStrike is no longer an endpoint company.

For quite some time we’ve said CrowdStrike’s history in endpoint remains a powerful anchor but there’s much more to the story.

CrowdStrike now presents Falcon as a 33-module platform built around a single lightweight sensor that spans ten control points: endpoint, cloud, identity, SIEM, threat intelligence, data protection, exposure management, the data pipeline, AI security and browser security.

The financials tell the story and it’s impressive. Cloud security has passed $905 million of ARR, next-gen SIEM $695 million and next-gen identity $585 million. In and of themselves these could be pre-IPO companies if they were standalone entities. Combined, these exceed $2.18 billion of ARR and are growing above 39 percent year over year. Our back of napkin calculation, using assumed minimums puts that at roughly 37 percent of CrowdStrike’s total ARR. So Falcon may start with endpoint, but a meaningful share of the business now comes from other areas.

CrowdStrike’s investor deck estimates a $149 billion TAM in calendar 2026, rising to $325 billion by 2030. Regardless of what you think of TAM figures, there is no shortage of market. The more important point is that the company has built entries many adjacent security businesses.

This is also where the blast-radius test becomes more important. Consolidation can reduce tool sprawl and complexity — but as endpoint, identity, SIEM, cloud, posture and AIDR consolidate, the risk domain grows. A bad update, policy or over-zealous agent can propagate across more of the security estate.

And that is where sovereignty enters. Sovereignty does not mean rejecting a strategic platform like Falcon. It means retaining the operational and technological control to bound authority, override it if necessary and isolate failure and recover independently.

The next section digs into CrowdStrike’s land-expand-and-consolidate engine.

The land-expand-consolidate engine is working

Now let’s look at the mechanics behind CrowdStrike’s platform expansion.

At the top of this graphic is the product proof. Among subscription customers, 51 percent now use six or more Falcon modules, 35 percent use seven or more and 26 percent use eight or more. That tells us a meaningful portion of the installed base is standardizing across multiple security control points.

Falcon Flex is the lever that turns that product breadth into a repeatable expansion sales motion. CrowdStrike added more than 935 Flex accounts in Q2 – more than it added in the prior three quarters combined. Ending ARR from accounts that have adopted Flex reached $2.29 billion, up 101 percent year over year. That is approximately 39 percent of CrowdStrike’s total ARR.

And the expansion math is impressive. Flex new-logo ARR contributed 34 percent of Q2 net new ARR. Customers moving from standard subscriptions to Flex produced more than a 40 percent average ending-ARR uplift. Their first re-Flex added another 25 percent, on average, from that new baseline. And customers that have re-Flexed at least twice were 53 percent above their initial Flex starting point.

So the flywheel shown above is this: CrowdStrike gets the sensor in, then activates modules, moves into Flex, re-Flexes as requirements expand and gives Falcon more context. Better outcomes then reinforce the next expansion.

But we need to read the $2.29 billion carefully. It is ARR from accounts that have adopted Flex. It is not the same as committed Flex capacity, modules already consumed or ARR generated beyond endpoint. The conclusion is that Flex is increasingly associated with CrowdStrike’s largest and fastest-expanding accounts, not that every dollar in those accounts was created by Flex.

George Kurtz said flex is the commercial harness. But to us, customer value is what matters most.

So let’s get into that next.

Wall Street hears Flex. Customers buy simplification. Surveys show virtually no churn.

On the earnings call, CrowdStrike talked about Falcon Flex constantly – by our count, roughly 50 mentions. That emphasis is understandable. Flex is central to the go-to-market motion, associated with $2.29 billion of ARR and strong new-logo and expansion economics.

But what stood out in the Qualitate survey is this…Across 1,250 discussions with CrowdStrike customers, only three proactively mentioned Flex by name. Buyers instead described the benefits in a very different language: fewer tools, faster deployment, lower complexity and better economics.

This doesn’t mean Flex is failing or CrowdStrike is hyping. We believe it means Flex works behind the scenes as a commercial contracting mechanism, while buyers experience the result as simplification.  As we show above based on the Qualitate surveys, customers talk about one Falcon agent supporting EDR, data protection, AI and identity. They talk about turning on capabilities without deploying another agent. And they talk about consolidating point tools, reducing investigation and operations work, and improving both manpower efficiency and unit price.

By the way, in speaking with the Qualitate data team, they are seeing clear indication that CrowdStrike is increasingly being viewed as more cost effective (relative to previous surveys) and it’s likely Flex is part of the reason. In Qualitate’s first-half research, CrowdStrike ranked ahead of Palo Alto Networks, Wiz and Zscaler on economics. Buyers cited built-in services, easy activation and lower logging-ingestion costs relative to products such as Splunk and Google Chronicle.

CrowdStrike ultimately made essentially the same point on the call: at the end of the day, it is the platform sale, better outcomes and lower cost that matter.

The stickiness is equally impressive. Of 217 CrowdStrike customers Qualitate polled since early July, not one voiced an intention to churn.

There is one caution we saw in the data. A satisfied Flex customer called recurring ACV escalation an “OEM tax” and said buyers still need continual diligence. So the platform can lower total system cost while also increasing CrowdStrike’s commercial average contract values.

Here’s the verbatim quote from the Qualitate survey:

The CrowdStrike component of increased spending is the OEM tax that happens every year where the bill goes up. It’s built into our three-year contract of CrowdStrike Flex right now as well. We’re happy with them. It’s increasing. We like the Flex package that CrowdStrike has, but as part of your due diligence, you’ve got to be constantly reviewing what you’ve got out there. – Field CISO, IT & Telecom (Large Enterprise)

That is a tension to watch. But the key takeaway is, to quote George Kurtz…“Flex is the commercial harness to enable customer success in the agentic era.”

To that we say “Customer success is measured in fewer tools, less friction and better unit economics.”

Wall Street hears Flex. Customers buy simplification.

The next section digs into why that customer value comes from a system-level moat, not a capability that a frontier model vendor can easily copy.

The moat is the system, not the individual module. You can’t vibe code Falcon.

Now let’s get to what we believe is CrowdStrike’s sustainable moat. It is not just Charlotte AI. It is not just AIDR. And it is not any single model or module. Those products are important, but features can be copied. The harder-to-match asset is the closed-loop system shown below.

Falcon starts with a single deployed sensor that generates first-party telemetry. It’s a real-time data pipeline that combines endpoint, identity, cloud and third-party telemetry. An enterprise graph adds asset, threat and risk context. CrowdStrike’s threat intelligence helps with prioritization. Charlotte AI – which received very high marks in the Qualitate surveys – AgentWorks and AIDR then reason over that context. Trusted and governed actions lead to outcomes, and those outcomes feed the next decision. So the system is constantly learning and updating. CrowdStrike describes Charlotte as the reasoning engine across Falcon and AgentWorks as a way for security agents to operate natively on Falcon data.

This is why frontier labs do not automatically commoditize Falcon.

Anthropic, OpenAI or another model provider can write great code, they can improve reasoning, and perform threat analysis. But they don’t possess CrowdStrike’s installed endpoint estate or proprietary attack-and-response data. They don’t have customer-specific context and the first party data and procecess knowledge CrowdStrike possesses.

CrowdStrike claims it has spent 15 years building threat, attack and mitigation data that is specifically trained and labeled – and much of this data is unavailable outside CrowdStrike’s walls. Barclay’s Saket Kalia made a similar point in his analysis of the quarter – i.e. that proprietary security data is critical when thinking about the potential risk from frontier labs 

Now a feedback loop is not automatically a moat. It still must demonstrate that broader telemetry produces better detection, less analyst fatigue and faster containment. And as AI begins to act, the standard of excellence rises. Actions must be explainable, controlled, observable and undone if necessary. Otherwise, the same agents that create advantages become potential liabilities.

So… The model can commoditize. The deployed feedback system – and trusted authority to act – are the strategic assets.

And that leads directly to the paradox in the next section: the architecture that digs the moat, also expands the blast radius.

Moat and blast radius share the same architecture

Now we get to the crux of the conundrum at the center of this analysis. The same architecture that builds Falcon’s moat also creates three distinct blast domains.

First is the update plane. Yes the customer gets fast, protection throughout…. But remember, the 2024 update incident showed the inverse: i.e. a defective content or software update designed to protect, can propagate through a privileged estate. The tests that should be in place are phased rollouts, hold periods, version control and automatic rollback.

Second is the platform plane. The customers get shared telemetry and consistent policy with consolidation…awesome. But as endpoint, identity, SIEM, cloud, posture and AI policy come together on common data and controls, one error can propagate failure across modules. The test is whether services fail independently and whether recovery systems are available and work when something goes wrong in the primary control plane.

Third is the agentic action plane. The benefit is machine-speed containment – that’s the upside. But lots can go wrong. When there are 100x more agents than humans, a security agent could be compromised and go rogue, or bad policy can cut across systems at machine speed. The controls that need to be in place should focus on agentic identities, approval processes, an independent kill switch and the like.

Now, CrowdStrike offers a credible story for containing its customers’ AI agents. On the Q2 call, George Kurtz described a nonhuman identity control plane, data protection, runtime visibility, exposure awareness, visibility into where agents are calling out, and guardrails around identity, data execution and network connectivity.

What we heard much less about was how CrowdStrike contains a failure originating inside Falcon itself. We hope to hear more about this at Falcon next week. We would expect CrowdStrike to have deeper answers for customers than an earnings call provides. Think of this as more research is needed, not a conclusion…we don’t know for sure yet.  But it’s a fair question for a platform gaining both context and authority.

Things like microsegmentation help, but it is not the complete answer. Microsegmentation constrains east-west movement. It does not automatically stop a rogue privileged sensor update or a trusted automated action gone bad. Those can travel through the very channels the architecture is designed to allow.

This is where blast radius also becomes a sovereignty issue – not primarily territorial, but operational, technological and financial. Operational sovereignty means binding and interrupting authority if necessary. Technological sovereignty means retaining an independent recovery process. Financial sovereignty means avoiding an emergency re-platform on someone else’s timetable because something went wrong or you drastically exceeded your token budget.

So the old question was: How widely can a bad update propagate?

The new question is: How widely can a trusted automated decision act?

We believe customers should absolutely take advantage of the benefits of consolidation, whether from CrowdStrike and its partners or Palo Alto or Microsoft, etc. But they should also keep the things simple and practical. For example, as Falcon is trusted to do more, buyers should ask three basic questions:

  1. What can the system do on its own?
  2. How far could a mistake spread? And
  3. How quickly could we stop it and recover?

This is not a criticism of consolidation or so-called platformization; it is common-sense for any AI-powered security platform. In our view, sovereignty in this context simply means that the customer – not the software or the vendor – retains ultimate control.

Next, let’s close with a scorecard.

The post-Mythos scorecard

In this scorecard we’ll assess what the quarter and the Qualitate buyer data tell us, and what still requires more research.

It’s hard not to rate CrowdStrike’s momentum green given its record-breaking quarter. CrowdStrike delivered $333 million in net new ARR, up 51%. Ending ARR accelerated for a fourth consecutive quarter, and the fiscal 2027 net-new-ARR growth outlook rose to 34%.

The quality of CrowdStrike’s financials are clearly green, with a 26% free-cash-flow margin and a 25% non-GAAP operating margin.

Platform expansion is green as well. Cloud, next-gen SIEM and identity now exceed $2.18 billion of combined ARR, and customer module depth continues to rise.

Customer value may be the most important green test. Qualitate buyers describe one agent covering EDR, data protection, AI and identity – with benefits in manpower, operating efficiency and unit price.

AI perception is also strong. CrowdStrike scored 89% favorable in Qualitate’s work, placing it among the leading vendors along with Palo Alto and Wiz. Charlotte as well has drawn consistently positive buyer citations, and AIDR nearly tripled sequentially.

The next proof point to watch is durability: Q3 conversion, adjacent growth relative to endpoint and sustained customer outcomes at renewal.

Now to the yellow and open areas.

Flex is yellow – not because the commercial motion is weak. The uplift and re-Flex behavior are proven. The questions are consumption versus commitment, renewal economics and CrowdStrike’s pricing leverage. One satisfied buyer described recurring escalation as an “OEM tax.” How much of the Flex momentum is related to Mythos fear and how much is sustainable? As competitors copy the flexible model, will CrowdStrike’s first-mover advantage be challenged?

AIDR has a similar disclosure asterisk: The percentage growth is exceptional, but CrowdStrike has yet to disclose absolute ARR.

Autonomous authority is also yellow, if only because it’s early. The product ingredients are emerging, but customers still need evidence on bad-action rates, approval gates, rollback times and maximum affected scope.

Blast-radius containment remains open because the earnings call did not provide details. Nor did the Qualitate data uncover any insights here. So we’re left with our own reasoning and knowledge from speaking with SecOps pros. In fairness, this is a research gap, not a negative call against CrowdStrike. This is one of the items we’ll be digging into next week at Fal.Con.

By the way, this is also an operational-sovereignty test: Can the customer bind, interrupt and recover from an agent’s action on its own terms?

Then comes the Fal.Con checkpoint. Barclays sees a plausible path to move the $10 billion ARR milestone from fiscal 2031 to fiscal 2029. Note, this is not CrowdStrike guidance – it’s a buy-side analyst projection. Fal.Con can hopefully show us whether pipeline durability and product innovation support that acceleration while imposing technical controls.

So, where do we arrive in this analysis?

Momentum is clearly validated. The trust test is open – let’s give it some time to prove itself out.

Post-Mythos momentum is real. The moat is strengthening. But as Falcon becomes more central to the AI SOC, the trust bar rises with it and it’s too early to claim a definitive “mission ccomplished.”

One thing we haven’t touched on is ecosystem. CrowdStrike’s ecosystem is exploding – as we predicted at our first Fal.Con in 2022. Last year we said, “They need a bigger boat.” Under the leadership of Daniel Bernard, chief commercial officer at CrowdStrike, the ecosystem has become a key part of the flywheel. And we’ll be watching for which key players in the network are leaning into the story.

We’ll also be watching for new product innovations, and how CrowdStrike is leveraging some of its recent acquisitions like Pangea and SGNL, a continuous identity and real-time access control platform acquired in January of this year – obviously very relevant to the blast radius discussion we had today.

Let us know how you see the landscape. Are you able to consolidate the number of vendors and tools in your security stack? How is AI helping? How concerned are you about the blast radius issues we’ve raised here and how are you mitigating those risk?

Image: theCUBE Research
Disclaimer: All statements made regarding companies or securities are strictly beliefs, points of view and opinions held by SiliconANGLE Media, Enterprise Technology Research, other guests on theCUBE and guest writers. Such statements are not recommendations by these individuals to buy, sell or hold any security. The content presented does not constitute investment advice and should not be used as the basis for any investment decision. You and only you are responsible for your investment decisions.
Disclosure: Many of the companies cited in Breaking Analysis are sponsors of theCUBE and/or clients of Wikibon or theCUBE Research. None of these firms or other companies have any editorial control over or advanced viewing of what’s published in Breaking Analysis.

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry