MDR partner · CrowdStrike Falcon

MDR for CrowdStrike Falcon, without changing licence.

For teams that already own Falcon but have nobody to act on a detection at night, or an MSSP that forwards alerts instead of containing them. The Fortgale MDR service runs on your Falcon console with analysts who have the mandate to contain, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × CrowdStrike
MDR · live
CrowdStrike sensor activeEndpoint · cloud · identity telemetry
CrowdStrike
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native CrowdStrike responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, CrowdStrike + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
CrowdStrike Falcon
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on CrowdStrike.

The Falcon modules the SOC operates, on Windows, macOS and Linux endpoints, cloud workloads and identities. If Falcon is not in place yet, licensing and sensor deployment are part of the service.

01

Falcon Insight XDR

Endpoint detection and response on the Falcon sensor, with Fortgale indicators loaded as Custom IOCs and behavioural Custom IOA rules.

02

Falcon Identity Protection

Identity threat detection on Active Directory and Entra ID: lateral movement, credential abuse and LDAP anomalies read in the same console as the endpoint.

03

Falcon Cloud Security

Cloud workloads and containers on AWS, Azure and GCP, monitored with the same sensor and correlated with endpoint and identity activity.

04

Falcon Exposure Management

Asset and vulnerability visibility (the former Falcon Discover and Spotlight), prioritised on CVEs actively exploited in the wild.

05

Falcon Next-Gen SIEM

Third-party logs brought next to Falcon telemetry in Next-Gen SIEM, so that correlation does not stop at the endpoint.

06

Threat hunting on Falcon telemetry

Hunting sessions led by Fortgale analysts for silent lateral movement, persistence and data staging that automatic detections miss.

What we add

What Fortgale adds on top of CrowdStrike.

What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.

On Falcon the analyst contains from the console: network containment of the host, process kill, file removal and a Real Time Response session to collect forensic artefacts or run remediation scripts on the machine.

Falcon Identity Protection adds policy-based enforcement on Active Directory and Entra ID, such as blocking a risky authentication or requiring MFA. Revoking cloud sessions outside those policies is not a Falcon action: it happens in the identity provider, with the permissions agreed at onboarding.

Because Fortgale indicators live in Falcon as Custom IOCs and IOA rules, an infrastructure already attributed to an actor raises a detection even before its behaviour is complete on the endpoint.

Takeover

How we take over your CrowdStrike environment.

Falcon sensors already deployed stay untouched: takeover works on your existing CID, with no reinstallation.

Monitoring goes live as soon as console access is in place, and technical onboarding closes in one week: roles, host groups and Fortgale rules are in place and the service runs at full capacity.

What we need from you: console users with the roles agreed for our analysts, the host groups where containment is pre-authorised and the people to call when a decision is yours.

From the field

MacSync: when the victim types the attack.

In July 2026 Fortgale published its analysis of MacSync, a macOS infostealer sold as a service. It arrives through poisoned search results and fake installation guides on GitHub that ask the user to paste a command such as curl … | zsh into the terminal; once running, it collects browser databases, session tokens, Keychain, SSH keys and wallets. On a developer's Mac at a customer, three execution attempts were stopped by behavioural detection on the endpoint, before the payload was downloaded.

The article is not about Falcon, but the lesson holds for any EDR with a macOS sensor: MaaS infrastructure rotates within days, the behaviour stays the same. On Falcon this is the kind of chain (terminal, curl, shell) a Custom IOA rule catches, and the analyst who gets the detection can contain the host and check in RTR that no file was written.

FAQ

What buyers running CrowdStrike actually ask.

Do we need Falcon Complete to work with Fortgale?

No. Falcon Complete Next-Gen MDR is the managed service of CrowdStrike. Fortgale works independently on the Falcon subscription you already have, with analysts in a SOC in Milan who operate in European time zones and under European rules.

What happens to our Falcon console and our access?

On an existing instance nothing is transferred to us: your CID, your policies and your administrator accounts remain yours. Our analysts log in with the console roles agreed at onboarding, and their containment and RTR sessions appear in the Falcon audit trail.

How do we move from another provider without a gap in coverage?

If the previous provider also worked on Falcon, the sensors do not move: only console users and response authorisations change hands. Our monitoring starts as soon as access is live, so the old contract can end once technical onboarding is complete, after one week.

Do we buy the Falcon licences, or do you?

Either way. If you already own Falcon, Fortgale integrates the SOC on your existing instance; if not, Falcon licensing is included in the MDR service with no separate purchase.

Does the service help with NIS2 obligations?

NIS2 does not require an MDR and no service makes you compliant on its own. The service covers capabilities you have to answer for: continuous monitoring, incident handling and, for a significant incident, the technical evidence for the early warning within 24 hours and the notification within 72 hours. On Falcon that evidence comes from the detection timeline, the artefacts collected in RTR and the containment audit trail.

See a real runbook

A real runbook on your Falcon console.

We walk through a containment on Falcon step by step: the detection that fired, the RTR commands the analyst ran, when the host was contained and what the identity policy did. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.