Fal.Con 2026 Recap: CrowdStrike Finds Threats, Torq Finishes Them

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

The Torq team headed back to Vegas for CrowdStrike’s Fal.Con conference this week, and it quickly became clear that the conversation has moved past whether AI belongs in the SOC. This year, everyone wanted to know what happens after a detection fires and who actually closes the case.

That question is the reason Torq and CrowdStrike fit together so well: CrowdStrike finds threats, and the Torq AI SOC Platform finishes them. Here’s what stood out from the week.

The Gap in the Current SOC Model

We said it last year, and it was even more true this year. There are too many alerts, too few analysts, and too many threats slipping through the gap between the two. Detection has never been better. Closure is where teams still drown.

What changed in 2026 is the noise around the fix. The market is now crowded with “AI SOCs” that stop at triage — they summarize an alert, maybe suggest a next step, and hand it back to a human. That is not finishing the job. A CrowdStrike Falcon detection deserves a platform that carries it all the way from alert to closed case, automatically, and that was the bar everyone at Fal.con was measuring against.

What Everyone Was Talking About at Fal.Con 2026

Four themes came up at Torq’s Fal.Con booth.

  1. Finishing the job, not just flagging it: A CrowdStrike Falcon detection flows straight into Torq Auto Triage, then investigation, then response, then a closed case, with prebuilt CrowdStrike steps and no manual handoff in between. Watching an alert close itself is a different demo than watching one get summarized.
  2. Grounding agentic decisions in your SOC’s reality: Beneath Torq’s AI Agents sits the Torq SOC Brain™, the layer that makes autonomy trustworthy: the Context Graph models your environment, Torq Recall draws on your case history from day one, and Torq Reflex learns your team’s judgment over time. It is the difference between a platform that starts every shift from zero and one that remembers.
  3. Turning autonomy into a dial: Socrates orchestrates Torq HyperAgents™ with transparent, auditable reasoning and analysts on the loop. The point that landed: autonomy is a dial you widen as trust builds, not an all-or-nothing switch.
  4. Bridging the SOC and the rest of the stack: Torq sits across CrowdStrike Falcon and other data sources to correlate, act, and manage data across the whole environment, not just one console. For teams running more than one data lake, that was the unlock.

Torq + CrowdStrike: Better Together

The Torq and CrowdStrike partnership runs deep. Torq’s AI SOC platform natively integrates across CrowdStrike Falcon detections, incident response, and vulnerability management with nearly 100 pre-built CrowdStrike steps ready to embed in Torq HyperAgents. There is no manual handoff between CrowdStrike finding a threat and Torq closing the case.  

While Falcon Fusion automates inside the CrowdStrike ecosystem, Torq orchestrates those signals across the entire security stack — spanning identity, cloud, email, and ticketing. A Falcon detection triggers endpoint containment and then coordinates action wherever else it needs to go across the entire SOC.

Above the integration sits Socrates, Torq’s agentic AI SOC orchestrator that reasons through an investigation, plans next steps, and closes nearly 95% of cases automatically. But the entire action plan still runs on Falcon-native data from detection to remediation: 

  • Detection: Falcon Next-Gen SIEM telemetry via CrowdStrike trigger
  • Investigation: Natural language hunting over Falcon telemetry through a Torq NGSIEM query agent
  • Response: Falcon Real Time Response commands executed from inside Torq
  • Vulnerability prioritization: CVEs from Falcon Exposure Management scores against CISA and NIST

Every alert triggered by CrowdStrike is fed into Torq Auto Triage for filtration and prioritization, and every security case gets AI case summaries, agentic investigation, and a full audit trail with explainable reasoning. The agentic decisions are based on the Torq Context Graph, building on Falcon telemetry with a real grounding in what’s true about the entire environment in that moment, and each alert allows the Torq AI SOC Platform to learn over time and produce more accurate responses. 

The Torq and CrowdStrike partnership is the difference between a detection and a defensible outcome, with:

  • 60-second average triage time
  • 60x increased triage velocity
  • 10x faster response
  • 95%+ of Tier 1 work auto-remediated
  • Near-real-time case management on CrowdStrike data

Onstage: What a Unified AI SOC Actually Looks Like

I had 20 minutes on the Fal.Con theater stage this year, and I used them to unpack a finding from Torq’s 2026 AI SOC Leadership Report: 94% of security teams now use AI somewhere in the SOC, the average team runs seven different AI tools, and 85% still say they want something different. 

During the discussion, we talked about the tension in those data points. AI adoption is high, and so is the confidence, but most teams still aren’t satisfied. The reason is that most “AI SOC” tools stop at triage, so teams keep adding another one to cover the next gap until they end up with disconnected solutions that aren’t seeing the full picture, or worse, shelfware. 

The data shows that it all comes down to trust and transparency in AI decisions. CISOs and security leaders need to see why AI reached a decision and how it got to that point before trusting it to actually act on the next one. When we asked those same CISOs what specifically they were looking for, the results were clear:

  • 92%: Continuous learning & adaptation to attack patterns
  • 90%: Explainable AI decisions
  • 89%: End-to-end SecOps: triage to remediation 
  • 89%: Autonomous response actions (e.g., containment, remediation)
  • 86%: Full platform integration

The answer: a unified AI SOC platform.

I walked through what transparent, end-to-end agentic SecOps actually requires — carrying an alert from detection through remediation on one platform — and how enterprises like Carvana, Valvoline, and Kenvue are operationalizing it in production today, using the Torq AI SOC Platform. 

See Torq + CrowdStrike in Action

Detection isn’t the hard part anymore. The advantage is in closing the case at machine speed, with a full audit trail behind every decision. CrowdStrike finds it. Torq finishes it. If we missed you at the booth, we’ll show you what that looks like on your own stack, running on your Falcon data.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO