Security Engineer at a healthcare company with 1,001-5,000 employees
Real User
Top 20
Sep 2, 2026
Charlotte AI has not changed the way my security team investigates or responds to threats; it simply makes the process a little bit faster. It improves our speed by approximately ten percent. I do not believe Charlotte AI has helped my team reduce investigation time or repetitive manual work; it removes one step of writing out the narrative and makes the process a little bit faster. It improves our investigation by reducing investigation time by approximately ten minutes. Charlotte AI has positively affected analyst productivity and my team's ability to handle a larger volume of security activity. We validate Charlotte AI responses in the same way we would validate information if it was not there, by going through the triage process we have for that specific case. It makes my investigation a little bit faster because it is correct a lot of the time. I personally do not trust it, but it is correct a lot of the time, and especially for junior analysts who do not know what they are looking at, it is easier for them. I would rate this review as a seven out of ten.
Engineer at a financial services firm with 201-500 employees
Real User
Top 20
Sep 1, 2026
Charlotte AI has helped my team reduce investigation time. For repetitive manual work, I am not aware that my team has used it. We mainly use it to ask questions whenever I get lost in the application or need more information quickly. It has shortened the time and directs me exactly where to go. The main challenge is the learning curve. AI chatbots are new, and the more I use them, the better they become. For now, I believe we are satisfied with what we have. My advice to other organizations considering Charlotte AI is that it is a good consideration compared to what is available in the market. It depends on whether they are buying the Falcon products from CrowdStrike. It is a good add-on. If an organization is new to CrowdStrike, I strongly advise getting Charlotte AI to navigate through the application. I would rate my overall experience with Charlotte AI as an eight out of ten.
Senior Security Analyst at a healthcare company with 1,001-5,000 employees
Real User
Top 20
Sep 1, 2026
I normally use the conversation capabilities of Charlotte AI the most. Charlotte AI has affected analyst productivity and my team's ability to handle a larger volume of security activity, especially since we are a very small team. Having this capability has been very useful for us. As I mentioned earlier, it decreases the amount of time we need to spend combing through countless logs, as it can do all of that very quickly and efficiently for us and give us a starting point or a lead. Charlotte AI has helped my team reduce investigation time and repetitive manual work. Charlotte AI has affected the experience or learning curve for less experienced members of my security team in a limited way because we are such a small team and we outsource to a third-party SOC for low-level detections. Anything they cannot handle, they escalate to our team, which is all senior-level people, a small group of senior-level analysts. I validate Charlotte AI's responses and recommendations by starting with the responses by going into our SIEM, which is Splunk, looking up the logs, and also looking at the log data we have coming into NextGen SIEM and into CrowdStrike's management console. In terms of its findings, I take it with a grain of salt. Its conclusions can be good but are susceptible to being incorrect. So, it does need to be verified. However, it provides an excellent starting point to anyone looking to investigate an event. I have not really expanded usage of Charlotte AI, as I do not think that applies to us so much. I actually use Charlotte AI the most of anyone on the team, which may also be the reason I have the most complaints since I see the good and the bad about it. I use it on just about every type of detection that comes in. It is a conversation I have with Charlotte AI, and it really depends on what I am looking for and what I want to get out of the conversation with the AI. If I am coming into it having no idea where to start, I can approach it that way, and Charlotte AI will give me a full breakdown if I ask for it. Alternatively, I could come in with preconceived notions and already gathered evidence and just want a second opinion on something, which I could also get from Charlotte AI that way. I advise other organizations considering Charlotte AI that it really depends on their budget, but if they can fit it in, I think it is definitely a valuable tool and will increase the power of any analyst they have. Overall, I would rate this review a 7.
System Architect at a university with 501-1,000 employees
Real User
Top 20
Sep 1, 2026
The advice I would give to other organizations considering Charlotte AI is that they need to be open-minded. They must be able to use it efficiently, input logs, and try different methods. Every organization is different, but the biggest thing is you have to be able to figure out what works for you. So I would say an organization needs to think of it as a companion rather than a threat to their job, using it to help them do their job faster and better. What worked for us is that pretty much everything we have tried so far works well. I am not saying that we will not face challenges in the future, but right now, initially, we haven't had anything that did not work well. I have not expanded usage yet, but I want to learn more about the credits—how we can get more and what we are going to get charged. That is the only uncertainty we have because once we know that, we can expand its use more on a daily basis without the fear of running out of credits. I would rate this review a 9 out of 10.
CrowdStrike Charlotte AI is a generative AI-powered cybersecurity capability built into the Falcon platform. It helps security teams investigate threats, automate repetitive tasks and make faster, more informed decisions by combining AI with CrowdStrike’s security telemetry, threat intelligence and expertise.
What features make Charlotte AI stand out?
AI-Powered Investigations: Accelerates threat analysis and surfaces relevant context.
Workflow Automation: Automates repetitive security...
Charlotte AI has not changed the way my security team investigates or responds to threats; it simply makes the process a little bit faster. It improves our speed by approximately ten percent. I do not believe Charlotte AI has helped my team reduce investigation time or repetitive manual work; it removes one step of writing out the narrative and makes the process a little bit faster. It improves our investigation by reducing investigation time by approximately ten minutes. Charlotte AI has positively affected analyst productivity and my team's ability to handle a larger volume of security activity. We validate Charlotte AI responses in the same way we would validate information if it was not there, by going through the triage process we have for that specific case. It makes my investigation a little bit faster because it is correct a lot of the time. I personally do not trust it, but it is correct a lot of the time, and especially for junior analysts who do not know what they are looking at, it is easier for them. I would rate this review as a seven out of ten.
Charlotte AI has helped my team reduce investigation time. For repetitive manual work, I am not aware that my team has used it. We mainly use it to ask questions whenever I get lost in the application or need more information quickly. It has shortened the time and directs me exactly where to go. The main challenge is the learning curve. AI chatbots are new, and the more I use them, the better they become. For now, I believe we are satisfied with what we have. My advice to other organizations considering Charlotte AI is that it is a good consideration compared to what is available in the market. It depends on whether they are buying the Falcon products from CrowdStrike. It is a good add-on. If an organization is new to CrowdStrike, I strongly advise getting Charlotte AI to navigate through the application. I would rate my overall experience with Charlotte AI as an eight out of ten.
I normally use the conversation capabilities of Charlotte AI the most. Charlotte AI has affected analyst productivity and my team's ability to handle a larger volume of security activity, especially since we are a very small team. Having this capability has been very useful for us. As I mentioned earlier, it decreases the amount of time we need to spend combing through countless logs, as it can do all of that very quickly and efficiently for us and give us a starting point or a lead. Charlotte AI has helped my team reduce investigation time and repetitive manual work. Charlotte AI has affected the experience or learning curve for less experienced members of my security team in a limited way because we are such a small team and we outsource to a third-party SOC for low-level detections. Anything they cannot handle, they escalate to our team, which is all senior-level people, a small group of senior-level analysts. I validate Charlotte AI's responses and recommendations by starting with the responses by going into our SIEM, which is Splunk, looking up the logs, and also looking at the log data we have coming into NextGen SIEM and into CrowdStrike's management console. In terms of its findings, I take it with a grain of salt. Its conclusions can be good but are susceptible to being incorrect. So, it does need to be verified. However, it provides an excellent starting point to anyone looking to investigate an event. I have not really expanded usage of Charlotte AI, as I do not think that applies to us so much. I actually use Charlotte AI the most of anyone on the team, which may also be the reason I have the most complaints since I see the good and the bad about it. I use it on just about every type of detection that comes in. It is a conversation I have with Charlotte AI, and it really depends on what I am looking for and what I want to get out of the conversation with the AI. If I am coming into it having no idea where to start, I can approach it that way, and Charlotte AI will give me a full breakdown if I ask for it. Alternatively, I could come in with preconceived notions and already gathered evidence and just want a second opinion on something, which I could also get from Charlotte AI that way. I advise other organizations considering Charlotte AI that it really depends on their budget, but if they can fit it in, I think it is definitely a valuable tool and will increase the power of any analyst they have. Overall, I would rate this review a 7.
The advice I would give to other organizations considering Charlotte AI is that they need to be open-minded. They must be able to use it efficiently, input logs, and try different methods. Every organization is different, but the biggest thing is you have to be able to figure out what works for you. So I would say an organization needs to think of it as a companion rather than a threat to their job, using it to help them do their job faster and better. What worked for us is that pretty much everything we have tried so far works well. I am not saying that we will not face challenges in the future, but right now, initially, we haven't had anything that did not work well. I have not expanded usage yet, but I want to learn more about the credits—how we can get more and what we are going to get charged. That is the only uncertainty we have because once we know that, we can expand its use more on a daily basis without the fear of running out of credits. I would rate this review a 9 out of 10.