CrowdStrike's Falcon Fund backs Above Security, folding AI-native insider risk into Falcon
Above Security, a Tel Aviv-based insider-threat platform, announced a strategic investment from the CrowdStrike Falcon Fund at Black Hat USA 2026, alongside an integration that gives Falcon customers ready-made insider risk investigations built on Falcon Next-Gen SIEM telemetry.
Above Security announced a strategic investment from the CrowdStrike Falcon Fund at Black Hat USA on August 4, 2026, alongside a product integration with the CrowdStrike Falcon platform. Above runs a fleet of continuously reasoning AI agents that correlate behavior across identities, applications, and data movement into investigation-ready cases, complete with behavioral timelines and the reasoning behind each risk classification, rather than a raw alert queue. Through the CrowdStrike integration, Falcon customers can extend their existing deployment with insider-risk investigations powered by Falcon Next-Gen SIEM telemetry. The investment follows a $50 million round earlier this year led by Ballistic Ventures, Merlin Ventures, and Norwest, and comes after Above placed as runner-up in the CrowdStrike Cybersecurity Startup Accelerator, run with AWS and NVIDIA, at RSAC 2026.
Why it matters
Insider risk sits at the intersection of identity and behavior: the access was legitimate, so the signal has to come from what an identity actually did, not whether it was authorized to log in. That's a harder detection problem than credential theft, and it's why insider-risk tooling increasingly leans on the same identity-plus-application-plus-data correlation that identity threat detection platforms use for external attackers.
A major EDR vendor's venture fund backing a dedicated insider-risk platform, rather than building the capability in-house, is a signal that the market still sees this as a specialized problem worth a standalone vendor, not a checkbox feature to bolt onto an existing SIEM.
Source: PR Newswire
Related on Start with Identity
- BlogGoogle Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the defa
- BlogAkeyless ships Runtime Authority, authorising AI agents per action instead of per session
Agents hold no secrets and get no standing privilege. Every action is authorised at the moment it happens, and the audit trail links the originating prompt to t
- BlogAzure AD is now Microsoft Entra ID: what actually changed
Microsoft announced the Azure AD to Entra ID rename in July 2023 and finished the visible relabelling by the end of that year. No tenant, protocol, or licence c
- VendorCrowdStrike Falcon Identity Protection
top_tier
- Comparisoncrowdstrike-falcon-identity-vs-microsoft-defender-identity
Both bring identity threat detection and response (ITDR) to the directory layer, watching Active Directory and Entra ID for attacks like credential theft, later
- VendorLexisNexis Risk Solutions
strong