Press Releases
CrowdStrike and ExtraHop® Expand Partnership to Stop Shadow AI Risks
April 30, 2025
New integration empowers SOC teams to detect and contain unauthorized AI usage with real-time, unified visibility and automated response across the enterprise
AUSTIN, Texas and RSAC 2025, San Francisco – April 30, 2025 – CrowdStrike (NASDAQ: CRWD) and ExtraHop today announced an expanded partnership to help enterprises detect and contain shadow AI risks. By ingesting market-leading network intelligence from ExtraHop into CrowdStrike Falcon® Next-Gen SIEM, the new integration gives SOC teams real-time visibility into unauthorized AI service usage and the ability to automate response actions – protecting sensitive data without slowing innovation.
Shadow AI is rapidly becoming a critical risk for enterprises as employees use and adopt AI tools outside the visibility of IT and security teams. These tools frequently bypass established security controls, creating blind spots that adversaries can exploit to access sensitive data or introduce misconfigurations that lead to breaches.
To close this gap, CrowdStrike and ExtraHop are giving SOC teams unified visibility and control over AI service usage across endpoints, networks, cloud environments, and on-premises infrastructure. By integrating deep network telemetry from ExtraHop with first- and third-party data from Falcon Next-Gen SIEM and automated remediation from Falcon Fusion SOAR, security teams can identify unauthorized AI models and agents, visualize usage patterns, and automate containment actions to reduce the risk of sensitive data exposure.
“Shadow AI has quickly emerged as a major security blind spot, often going undetected by legacy tools and exposing sensitive data,” said Daniel Bernard, chief business officer, CrowdStrike. “Together with ExtraHop, we’re delivering AI-native security and real-time network intelligence that empowers security teams to detect, stop and control unauthorized AI. This integration helps organizations embrace AI innovation without losing visibility, control or protection of sensitive data.”
“From the moment commercial AI services began to gain traction, ExtraHop recognized the vital role of network telemetry in providing crucial visibility into their burgeoning use across the enterprise,” said Kanaiya Vasani, chief product officer, ExtraHop. “Our deepening partnership with CrowdStrike allows us to build on this foresight, leveraging that visibility to deliver unparalleled insight into the broad spectrum of AI services in use today. Together, we offer organizations a streamlined solution for identifying and mitigating potential security risks from increasing use of AI tools across their environments.”
Additional Resources
About ExtraHop
ExtraHop empowers enterprises to stay ahead of evolving threats with the most comprehensive approach to network detection and response (NDR).
Since 2007, the company has helped organizations across the globe extract real-time insights from their hybrid networks with the most in-depth network telemetry. ExtraHop uniquely combines NDR, network performance management (NPM), intrusion detection (IDS), and packet forensics in a single, integrated console for complete network visibility and unparalleled context that supports data-driven security decisions. With a powerful all-in-one sensor and cloud-scale machine learning, the ExtraHop RevealXTM platform enhances SOC productivity, reduces overhead, and elevates security postures.
Unlock the full power of network detection and response with ExtraHop. To learn more, visit www.extrahop.com or follow us on LinkedIn.
© 2025 ExtraHop Networks, Inc., RevealX, RevealX 360, RevealX Enterprise, and ExtraHop are registered trademarks or trademarks of ExtraHop Networks, Inc.