<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Soar — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/soar/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 28 Mar 2026 09:22:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/soar/feed.xml" rel="self" type="application/rss+xml"/><item><title>CrowdStrike Charlotte AI AgentWorks and Agentic SOAR for Automated Security Operations</title><link>https://feed.craftedsignal.io/briefs/2026-03-charlotte-ai-agentworks/</link><pubDate>Sat, 28 Mar 2026 09:22:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-charlotte-ai-agentworks/</guid><description>CrowdStrike introduces Charlotte AI AgentWorks and Agentic SOAR to enhance security operations through AI-driven automation and orchestration, reducing manual workloads and improving decision accuracy.</description><content:encoded><![CDATA[<p>CrowdStrike is introducing Charlotte AI AgentWorks and Agentic SOAR as a new approach to security operations, designed to leverage AI to automate tasks, orchestrate workflows, and amplify analyst capabilities. Announced in March 2026, Charlotte AI AgentWorks serves as a central hub for building and scaling security agents across the enterprise, integrating with models from Anthropic, NVIDIA, and OpenAI, and promoting collaboration among security innovators. Charlotte Agentic SOAR is designed to enable the coordinated operation of these agents within complex security workflows, providing mission-ready agents for common tasks like triage and malware analysis. The aim is to reduce manual workloads, enhance decision-making accuracy, and provide a security-first foundation for AI-driven automation. To help customers accelerate AI adoption, CrowdStrike offers free AI credits for experimentation within their environments.</p>
<h2 id="attack-chain">Attack Chain</h2>
<p>This brief describes new product capabilities and not an active attack chain. Therefore, a typical attack chain is not applicable. However, the following steps outline how a security team might leverage the capabilities:</p>
<ol>
<li><strong>AI Model Integration:</strong> The organization integrates various AI models from providers like Anthropic, NVIDIA, and OpenAI into the Charlotte AI AgentWorks platform, choosing the most suitable models for specific security tasks.</li>
<li><strong>Agent Development:</strong> Security engineers use Charlotte AI AgentWorks to develop custom security agents tailored to their environment, leveraging the platform&rsquo;s tools and frameworks.</li>
<li><strong>Workflow Design:</strong> Using Charlotte Agentic SOAR, analysts design automated workflows that incorporate the newly created and out-of-the-box agents to address specific security challenges, such as threat triage or malware analysis.</li>
<li><strong>Agent Deployment:</strong> The security agents are deployed across the CrowdStrike Falcon platform, inheriting the platform&rsquo;s telemetry, security guardrails, and access controls.</li>
<li><strong>Task Automation:</strong> The agents automatically perform tasks such as triaging alerts, analyzing malware samples, prioritizing exposure management, and generating correlation rules.</li>
<li><strong>Human Oversight:</strong> Analysts monitor the agents&rsquo; activities through the unified case management interface, ensuring that actions align with established security policies and compliance requirements.</li>
<li><strong>Workflow Optimization:</strong> The security team identifies operational bottlenecks and streamlines investigations based on the data provided by the case management system, continuously improving the automated workflows.</li>
<li><strong>Analyst Amplification:</strong> Analysts leverage the AI-driven automation to reduce manual tasks, accelerate response times, and focus on strategic oversight and complex investigations.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful implementation of Charlotte AI AgentWorks and Agentic SOAR can lead to a significant reduction in manual investigation workloads, potentially by as much as 70%, and a restoration of over 40 hours of team capacity per week. The platform aims to achieve greater than 98% decision accuracy in automated tasks. By automating repetitive and time-consuming processes, organizations can free up security analysts to focus on more strategic initiatives, improving overall security posture and reducing the risk of successful attacks. The platform&rsquo;s goal is to reshape the analyst experience, eliminate toil, accelerate outcomes, and help teams seize an operating advantage in the AI era.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Explore the capabilities of Charlotte AI AgentWorks and Agentic SOAR within a test environment using the free AI credits offered by CrowdStrike, to evaluate the potential benefits for your organization (Charlotte AI AgentWorks, Agentic SOAR).</li>
<li>Leverage the out-of-the-box agents available in Charlotte Agentic SOAR to automate common security tasks such as threat triage and malware analysis, and customize them to your environment (Charlotte Agentic SOAR).</li>
<li>Evaluate existing security workflows and identify areas where AI-driven automation can reduce manual effort and improve decision accuracy, designing new workflows using Charlotte Agentic SOAR (Charlotte Agentic SOAR).</li>
<li>Monitor the performance of deployed agents and automated workflows through the unified case management interface, identifying and addressing any bottlenecks or areas for optimization (Charlotte Agentic SOAR).</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>ai</category><category>automation</category><category>security operations</category><category>soar</category></item></channel></rss>