
CrowdStrike 101:
CrowdStrike is a next-gen, cloud-native endpoint cybersecurity company. Its bread-and-butter is called endpoint detection and response (EDR), which replaces legacy anti-virus (AV). Beyond EDR, it offers applications in cloud security, log management, forensics, identity, data protection etc. to round out its “Falcon Platform.” Falcon’s edge is in its ability to digest near-endless amounts of data to automate and uplift breach protection. CrowdStrike uses its large and diverse dataset to constantly improve Falcon’s efficacy and use cases… all with a single console and single agent to ensure superior interoperability. It can recycle this same data over and over again to efficiently develop new products for a single interface. More utility without adding complexity.
Important Endpoint Security Acronyms:
Endpoint detection and response (EDR) provides end-to-end visibility and protection with automated remediation and flagging services.
Managed detection and response (MDR) encompasses CrowdStrike’s team of threat hunters to augment EDR with human touch when needed.
Extended detection and response (XDR) is EDR with 3rd party, non-endpoint data sources infused. The incremental data sharpens breach protection and extends it beyond the endpoint.
Important Log Management Acronyms:
Log Scale ingests, organizes and stores data logarithmically. This allows for ingestion with more scale and faster time to value. As an important aside, Log Scale is a key ingredient for Falcon XDR. It is instrumental in XDR onboarding needed data sources in a scalable and efficient manner. This can be used to improve security and other parts of operations too.
Security Information and Event Management (SIEM) aggregates security logs/data to help organizations uncover and remediate threats faster. Log Scale is closely related to SIEM, as Log Scale is what actually collects data from various sources to be utilized here.
Important Cloud Security Acronyms:
Cloud Security & Posture Management (CSPM) tells you about your vulnerabilities and misconfigurations.
Cloud Infrastructure Entitlement Management (CIEM) tells you who is entering a software environment. It tells you if these entrants are allowed and exactly what they’re allowed to do.
Cloud Workload Protection (CWP) is a preventative measure to observe if anything bad is being done by entrants. This sounds the alarm bell while preventing and remediating cloud infrastructure attacks. It’s closely related to CSPM and CIEM.
Cloud Native Application Protection Platform (CNAPP) is the overall suite tying all of these cloud products together.
Application Security Posture Management (ASPM) locates and facilitates the safe control of cloud apps.
Now let’s dig into the detailed quarterly review:
a. Demand
Beat revenue estimates by 1.8% & beat guidance by 1.9%.
Subscription revenue rose by 34% Y/Y.
Beat annual recurring revenue (ARR) estimates by 0.6%. Net new ARR (NNARR) estimates beat by about 5%-10% depending on the source. Most indicate the beat was closer to 10%. Regardless, really good.



b. Profits & Margins
Beat 78% non-GAAP gross profit margin (GPM) estimates by 30 basis points (bps; 1 basis point = 0.01%).
Beat free cash flow (FCF) estimates by 4.0%. FCF rose by 41.7% Y/Y.
Beat EBIT estimates by 4% & beat EBIT guidance by 4.9%.
Beat $0.89 EPS estimates by $0.04 & beat EPS guidance by $0.03. EPS rose by 63% Y/Y.
Met $0.17 GAAP EPS estimates. $0.17 in GAAP EPS compares to $0.00 Y/Y.
This is its 5th straight quarter of GAAP profitability. Its entrance into the S&P 500 is inevitable in my view. When not if.


c. Balance Sheet
$3.7 billion in cash & equivalents.
$742 million in traditional debt.
Diluted share count rose by 3.9% Y/Y. The team reiterated expectations for 3.0% Y/Y dilution this year. Important.
CrowdStrike continues to lean back into hiring and growth investments. Headcount rose by 15% Y/Y. Leverage is regardless of this added spend appetite.
d. Annual Guidance & Valuation
Raised annual revenue guidance by 1%, which beat estimates by 0.5%.
Raised annual EBIT guidance by 7.0%, which beat estimates by 6.0%.
Raised $3.92 EPS guide by $0.06, which barely beat estimates by $0.01.
Reiterated guidance calling for a 32% FCF margin for the year.
Next quarter guidance is ahead across the board. It sees 10%-15% NNARR growth next quarter.
Guidance continues to use a “consistently prudent” methodology and assumes continued challenging macro.
The team reiterated its path to $10 billion in ARR. It continues to do so while other quality software names like Snowflake and Palo Alto have rescinded their long term targets.
CrowdStrike trades for 75x-80x earnings. Earnings are expected to grow by about 30%-32% Y/Y after likely upward revisions.
e. Call & Release
The Winning Platform:
The CrowdStrike formula continues to work like a charm. The lightest-weight, single agent… one console… one interface… no onboarding headache or required re-boot… no downtime… one round of data ingestion to recycle that data across 28 thriving modules. The team thinks all 28 of these are among best-in-class products, but the magic happens in tying all of them together to work in a perfectly cohesive fashion. Point solutions can’t do this. Pseudo-platforms (as Founder/CEO George Kurtz calls them) can’t do this either.
Its obsession with building “golden plumbing” (or a strong architectural foundation) has set this company up to sprint for decades while others struggle to jog. The foundation ensured superior interoperability, an easier means to properly integrate M&A and a near-endless list of accolades from 3rd party research firms (Forrester, IDC, Gartner, KuppingerCole, SE Labs, SC Europe etc.). This is the highest quality platform play across endpoint, identity and cloud security, with this quarter being the latest dose of evidence.
CrowdStrike’s team was asked multiple times in the Q&A: “how are you enduring the same macro trends cited by others and outperforming by such a large margin?” How? Via the formula just described. Budget scrutiny is ongoing, along with macro anxiety. CrowdStrike’s ability to displace disparate point solutions and vastly bolster breach protection means it can overcome this strong headwind. Per IDC, $1 spent on the Falcon platform nets $6 in cost savings for its customers. The cost-to-value ratio here is off the charts. It’s not seeing any pricing pressures.
“When a platform delivers real value, you don’t have to give it away.”
Founder/CEO George Kurtz
So? In a budget-constrained world, spending more on Falcon allows companies to pocket considerable costs and do more with less. The desire and motivation to consolidate and standardize on the Falcon platform continues to build… and CrowdStrike continues to blossom. This is why its profitable, scaled growth engine is one of one in public markets. This is why it deserves a large valuation premium. This is why CrowdStrike is the “Ferrari” of its sector — as its charismatic CEO would tell you.
Let’s back this idea up with some quantitative evidence:
Deal size is growing as the team “closes some of its largest contracts ever.”
8+ module deals rose 95% Y/Y.
It’s landing with “more modules than ever before.”
Cloud, identity and SIEM deals rose by more than 100% Y/Y.
Q2 deal pipeline set new highs.

From CRWD’s Investor Presentation
Go to Market:
Great tech is a prerequisite for winning in next-gen cybersecurity. But? You have something truly special when you can marry that great tech with great go-to-market. CrowdStrike does that. So while we’ve heard Palantir, SentinelOne, Zscaler, Cloudflare & others cite the need to overhaul go-to-market over the last couple quarters, CrowdStrike’s selling machine is firing on all cylinders.
It’s deepening already tight relationships with AWS and Google Cloud as AWS standardized on Falcon (8 figure contract) and as CrowdStrike now powers Mandiant’s MDR (owned by Google).
It’s finding managed security service provider (MSSP) partners abandoning work with other vendors to embrace CrowdStrike more singularly. This is one of its fastest growing selling outlets; the channel netted CRWD a large batch of customer wins from an MSSP wanting to leave VMWare’s Carbon Black.
The Falcon Flex product is also deeply resonating. This allows customers to purchase from its suite of modules in more of an á la carte manner. That added optionality is leading to an acceleration in large deal flow; in less than a year, this bundle has netted $500 million in contract value. This kind of revenue ramp is becoming cliché for this company in the best of ways.
It’s also more aggressively and proactively turning Microsoft Defender blunders into its own customer wins. Following yet another high profile breach this quarter, CRWD (at the request of prospective customers) debuted Falcon for Defender. This offers threat hunting and report procurement to “validate and verify” "activity and to clean up MSFT messes. It directly pulls from the same Falcon sensors that power its native offerings. This not only means more demand but also gives Falcon a great chance to tryout for new business before these Defender contracts expire.
Kurtz also worked Nvidia into the conversation. Shocking, I know. CrowdStrike and Nvidia are partnering to secure accelerated compute workloads on the Falcon platform. Per Nvidia Founder/CEO Jensen Huang, “pairing Nvidia with CrowdStrike can give enterprises unprecedented visibility into threats to protect their businesses.” Quite the stamp of approval. CrowdStrike also feels well positioned to turn the “$60 billion hardware GenAI gold rush” into strong workload demand growth. GenAI software monetization is becoming a concern for most of enterprise software… but not for CrowdStrike. After all, these models and new apps do need securing. Enter Falcon.
Deal Highlights:
7 figure Fortune 100 healthcare organization. It experienced yet another Microsoft Defender breach and then adopted Falcon Complete (full product suite). It enjoyed a 75% reduction in agents and a 7x improvement in time to detect and respond.
A large, middle eastern utilities company displaced 5 point solutions with Falcon.
Cloud, Identity & Data:
These three product buckets used to be called “emerging” by CrowdStrike. They’ve now fully emerged as large, valuable complements to its endpoint core. CRWD is not just an endpoint security company. It is an endpoint, cloud, identity and data security company with rapidly proliferating usage across many other areas. This is now obvious. That was not always the case.
Cloud utilization reached “unprecedented highs” as a strong indicator for future revenue generation. Impressively, 62% of the Fortune 100 already call Falcon Cloud security “their provider of choice.” This product category is only a few years old for CRWD. The lack of entrenched competitors is leaving virtually nothing in the way of this company already being the largest in this space.
In identity, its identity detection and response product is doing quite well. This is a first cousin of EDR. It more so extends endpoint detection to identities vs. replacing identity access brokers, such as Okta. This is the only single agent product on the market and recently added support for Azure ID, among other directories. During the quarter, this bucket won CRWD a 7 figure deal with another large healthcare provider to displace Broadcom (which competes here through its Symantec purchase). Most threat activity centers around identity. CrowdStrike is poised to serve customers here.
In log scale and next-gen SIEM, the pace of industry evolution is ramping. M&A activity from Splunk, QRadar and others is displacing large cohorts of customers and accelerating demand for this segment. The native, log scale next-gen SIEM offering means data is right where protection happens. It means customers can seamlessly tap into a vast supply of first and third party data to infuse more context into data analytics and breach protection. Bringing the data to security means lower data ingestion, storage & transport costs… and less headache. This secret weapon is how things like its Charlotte GenAI app can provide such material value. More on this later.
Falcon Fusion Security Orchestration, Automation and Response (SOAR) is a key product within this bucket. Man do these companies love acronyms. It organizes data and workflows, automates those workflows and crafts an optimized reaction to all of the insight it collects. 47% of its largest 5,000 customers now use Falcon SOAR. When pairing this with log scale and SIEM, Falcon’s XDR product realizes its vision of extending endpoint detection to areas well beyond that specific endpoint. It enhances and expedites coverage. This is how it won contracts like a Global 2000 manufacturer in an 8 figure deal.
Falcon ASPM (defined above) is now in general availability.
Debuted new cloud detection and response (CDR) tools.
Emerging Solutions:
Now that cloud, identity and log-scale/SIEM have fully “emerged” as prominent revenue drivers, CrowdStrike has a new set of emerging products to join the party. Charlotte AI is delivering a 90% “proof of value” to early prospects as a strong piece of evidence for future revenue. This is its GenAI assistant to up-level security analysts and automate protection. It will directly monetize this with a subscription up-sell.
Its data protection and data loss prevention (DLP) offering now counts “several hundred customers” early on. To the team, this product category now resembles a “hyper-growth startup” on its own. That’s similar to how it used to describe cloud/identity/SIEM in previous years.
e. Take
Even for an optimistic long term CrowdStrike bull like myself, this was a surprisingly good quarter. Compared to every other related company in its space, it delivered a phenomenal performance during a quarter in which the backdrop became incrementally more challenging. I’m excited to see the disaster insurance put hedge I added expire worthless. I’m excited to likely continue owning this company for a long time. There are very few firms that ever deserve 80x earnings. This is one of them, in my shareholder opinion. Great results.
And while CrowdStrike may be a bit overvalued today, I think the company will be much larger tomorrow. Its unmatched ability to drive new module traction outside of endpoint has doubled its TAM in just a few years. Growth, scale, profits, leverage, market share trends, balance sheet health and runway are all elite.
