CrowdStrike Holdings
Combined average of Moat (AI Resilience), Growth, and Valuation scores.
Moat Score
Falcon platform's single-agent architecture, Threat Graph network effects, and deep switching costs create a durable cybersecurity moat.
CrowdStrike's moat is built on Data Network Effects, Platform Depth, and Switching Costs:
- Threat Graph (Network Effects): CrowdStrike's Threat Graph processes over 1 trillion security events per day across 24,000+ customers. Each new customer improves detection accuracy for all others — creating a self-reinforcing data moat that widens with scale.
- Single-Agent Platform Depth: The Falcon platform delivers 33 modules from one lightweight agent (IR deck). Q2 module adoption: 51% / 35% / 26% on six / seven / eight or more modules (exhibit). As customers consolidate onto Falcon — Flex ending ARR >$2.29B, +101% YoY — replacement is a multi-year undertaking. The beat does not mark this pillar up.
- Switching Costs & Certification Lock-In: Ripping out an endpoint security platform requires re-imaging machines, retraining staff, and re-certifying compliance. FedRAMP High and IL5 certifications further lock in federal customers for years.
Moat Verdict
CrowdStrike's moat is highly AI-resilient — AI enhances the Threat Graph by processing more telemetry faster, and Charlotte AI / AIDR add a consumption layer on top of existing data assets. The Q2 FY2027 beat (NNARR $333M, +51%; Flex $2.29B, +101%) does not change that, and it does not retire Microsoft Defender bundling as a growth residual. AI is an accelerant to CrowdStrike's moat, not a disruptor.
70.8 resilient · 71.5 vulnerable · 80/20 = 71.0 · = 71
Open a moat to read its note.
Security analysts trained on Falcon's console, threat hunting workflows, and detection tuning are reluctant to migrate — institutional knowledge compounds switching costs.
Custom detection rules, threat hunting queries, and automated response playbooks are encoded into each customer's Falcon instance — real switching cost, but it is customer-owned configuration rather than CrowdStrike-owned logic competitors cannot replicate. Same bar as Datadog monitors and Snowflake SQL (intact). The vendor franchise is the Threat Graph and the sensor, not the customer's query library.
CrowdStrike publishes threat intelligence reports (Adversary Intelligence) but its primary moat is proprietary telemetry from its sensor network, not public data.
CrowdStrike's threat intelligence team (Counter Adversary Operations) is a scarce talent pool — nation-state adversary tracking expertise is extremely difficult to replicate.
Falcon's 33 modules (IR deck; endpoint, identity, cloud, SIEM, threat intel) allow CrowdStrike to replace 5–10 point solutions. Q2 module adoption 51% / 35% / 26% on 6+ / 7+ / 8+ (exhibit) and Flex ending ARR >$2.29B are more bundle surface, not a status change. This pillar is CrowdStrike's own bundle, not Microsoft Defender — Q2 did not produce a filing that removes the Defender residual on the growth pillar. Do not mark this up because they beat.
Threat Graph holds years of cross-customer attack telemetry and is a real detection advantage, but it is not a dataset rivals cannot match: Microsoft processes 78 trillion security signals a day across Defender, Entra and Azure (2024 Digital Defense Report). CrowdStrike's edge is detection quality, which shows up in retention under transactionEmbedding. Re-rated from strong to intact in the proof-point pass.
FedRAMP High, IL4/IL5, StateRAMP and CMMC make Falcon procurable for government and regulated buyers, but Microsoft Defender, Palo Alto and SentinelOne hold the same authorisations. Standard certifications are table stakes in this market — they bar small entrants, not the peers this name competes with — so they rate intact; strong is reserved for a barrier few competitors in the market can clear. Re-rated from strong to intact.
Each new sensor feeds the Threat Graph, but that is the same cross-customer dataset rated under proprietaryData — a data flywheel, not a separate two-sided network. Re-rated from strong to intact so one fact is not scored twice.
Falcon's single agent runs on every protected endpoint and cloud workload, and security decisions, alerts and automated responses flow through it in real time. The proof is retention: gross retention has held around 97%, including through the July 2024 outage.
For incident response and threat hunting, Falcon serves as the system of record for endpoint telemetry — compliance teams, IR firms, and SOC analysts depend on its data for forensic investigations.
Software at near-zero marginal cost: scale shows up as network effects, data or bundling, which are rated there. No separate unit-cost lead to credit.
Buyers are enterprises choosing on switching cost, integration and performance, which the other pillars rate. The name carries reputation, not a price premium it could hold on brand alone.
Combined average of Moat (AI Resilience), Growth, and Valuation scores.
Moat Score
Falcon platform's single-agent architecture, Threat Graph network effects, and deep switching costs create a durable cybersecurity moat.
Growth Score
Q2 FY2027 (quarter ended July 31, reported Aug 26) printed revenue $1.47B, +26% YoY from $1.17B — the fifth consecutive quarter of acceleration — with subscription $1.40B, +27%. Ending ARR $5.84B (+25% YoY); record net new ARR $333M (+51% YoY; exhibit $332.8M). The named Q2 trip — net new ARR growth stalls below 25% — did not fire. Falcon Flex ending ARR exceeded $2.29B, +101% YoY. Non-GAAP operating income a record $372M (25% margin; exhibit $371.6M); CFO $530.3M vs $332.8M; FCF $377.4M vs $283.6M (26% of revenue). GAAP net income $5.3M / $0.01 vs a year-ago loss. Q3 guided ARR $6.1844–$6.1884B (implied NNARR $343–$347M), revenue $1.5232–$1.5292B, non-GAAP EPS $0.31. FY27 raised: ARR $6.6030–$6.6119B, revenue $5.9911–$6.0111B, NNARR growth 34% at the midpoint (+630 bps), non-GAAP EPS $1.25–$1.26. IR modeling points (not in exhibit 99.1): Q3 FCF margin 27.5% at midpoint, FY27 FCF margin at least 30%.
Valuation Score
Regular-session close $227.96 on Aug 27 (Yahoo Finance; market cap $232.122B). Aug 26 close $189.18 was pre-print (AMC 5pm ET call); the Aug 18 card's ~$226 is also not the post-print tape — both of those are what not to use. Unchanged ladder $140 / $195 / $275. At $227.96 the stock is 17% above the $195 base and 41% of the way to the $275 bull — piecewise 57, same as the Aug 18 card at ~$226. The Q2 beat-and-raise does not move the ladder; valuation remains the residual (richest multiple in coverage). Live valuation will recompute against the tape; this static 57 is the Aug 27 close against the held corridor.
The Threat Graph Moat
CrowdStrike's moat is built on Data Network Effects, Platform Depth, and Switching Costs:
- Threat Graph (Network Effects): CrowdStrike's Threat Graph processes over 1 trillion security events per day across 24,000+ customers. Each new customer improves detection accuracy for all others — creating a self-reinforcing data moat that widens with scale.
- Single-Agent Platform Depth: The Falcon platform delivers 33 modules from one lightweight agent (IR deck). Q2 module adoption: 51% / 35% / 26% on six / seven / eight or more modules (exhibit). As customers consolidate onto Falcon — Flex ending ARR >$2.29B, +101% YoY — replacement is a multi-year undertaking. The beat does not mark this pillar up.
- Switching Costs & Certification Lock-In: Ripping out an endpoint security platform requires re-imaging machines, retraining staff, and re-certifying compliance. FedRAMP High and IL5 certifications further lock in federal customers for years.
Moat Verdict
CrowdStrike's moat is highly AI-resilient — AI enhances the Threat Graph by processing more telemetry faster, and Charlotte AI / AIDR add a consumption layer on top of existing data assets. The Q2 FY2027 beat (NNARR $333M, +51%; Flex $2.29B, +101%) does not change that, and it does not retire Microsoft Defender bundling as a growth residual. AI is an accelerant to CrowdStrike's moat, not a disruptor.
70.8 resilient · 71.5 vulnerable · 80/20 = 71.0 · = 71
Open a moat to read its note.
Security analysts trained on Falcon's console, threat hunting workflows, and detection tuning are reluctant to migrate — institutional knowledge compounds switching costs.
Custom detection rules, threat hunting queries, and automated response playbooks are encoded into each customer's Falcon instance — real switching cost, but it is customer-owned configuration rather than CrowdStrike-owned logic competitors cannot replicate. Same bar as Datadog monitors and Snowflake SQL (intact). The vendor franchise is the Threat Graph and the sensor, not the customer's query library.
CrowdStrike publishes threat intelligence reports (Adversary Intelligence) but its primary moat is proprietary telemetry from its sensor network, not public data.
CrowdStrike's threat intelligence team (Counter Adversary Operations) is a scarce talent pool — nation-state adversary tracking expertise is extremely difficult to replicate.
Falcon's 33 modules (IR deck; endpoint, identity, cloud, SIEM, threat intel) allow CrowdStrike to replace 5–10 point solutions. Q2 module adoption 51% / 35% / 26% on 6+ / 7+ / 8+ (exhibit) and Flex ending ARR >$2.29B are more bundle surface, not a status change. This pillar is CrowdStrike's own bundle, not Microsoft Defender — Q2 did not produce a filing that removes the Defender residual on the growth pillar. Do not mark this up because they beat.
Threat Graph holds years of cross-customer attack telemetry and is a real detection advantage, but it is not a dataset rivals cannot match: Microsoft processes 78 trillion security signals a day across Defender, Entra and Azure (2024 Digital Defense Report). CrowdStrike's edge is detection quality, which shows up in retention under transactionEmbedding. Re-rated from strong to intact in the proof-point pass.
FedRAMP High, IL4/IL5, StateRAMP and CMMC make Falcon procurable for government and regulated buyers, but Microsoft Defender, Palo Alto and SentinelOne hold the same authorisations. Standard certifications are table stakes in this market — they bar small entrants, not the peers this name competes with — so they rate intact; strong is reserved for a barrier few competitors in the market can clear. Re-rated from strong to intact.
Each new sensor feeds the Threat Graph, but that is the same cross-customer dataset rated under proprietaryData — a data flywheel, not a separate two-sided network. Re-rated from strong to intact so one fact is not scored twice.
Falcon's single agent runs on every protected endpoint and cloud workload, and security decisions, alerts and automated responses flow through it in real time. The proof is retention: gross retention has held around 97%, including through the July 2024 outage.
For incident response and threat hunting, Falcon serves as the system of record for endpoint telemetry — compliance teams, IR firms, and SOC analysts depend on its data for forensic investigations.
Software at near-zero marginal cost: scale shows up as network effects, data or bundling, which are rated there. No separate unit-cost lead to credit.
Buyers are enterprises choosing on switching cost, integration and performance, which the other pillars rate. The name carries reputation, not a price premium it could hold on brand alone.
Growth Analysis
Growth Drivers
Key Risk
The Q2 trip (NNARR growth stalls below 25%) did not fire: printed $333M, +51% YoY. Next hard test is Q3 FY2027 implied NNARR $343–$347M (ARR $6.1844–$6.1884B) and the FY27 34% NNARR-growth midpoint. Falsifiable: Q3 NNARR prints below $343M, or a subsequent guide cuts FY27 NNARR growth below that 34% midpoint. Microsoft Defender/Sentinel bundling is unchanged — Q2 did not produce a new fact that removes it. Residual: at $227.96 the stock is ~39× FY27 revenue and ~182× company FY27 non-GAAP EPS $1.25–$1.26, the richest multiple in coverage; if the raise proves a one-off, the multiple compresses toward ~24× NTM revenue.
Score Derivation
86.0 base + 4.0 trajectory + 4 margin − 5 risk = 89
Base 86 (22–26% CAGR, midpoint 24%, baseFromCagr: 80 + ((24−15)/15)×10 = 86) + 4 trajectory (3 of 3 drivers accelerating) + 4 margin expanding (non-GAAP OM 25% vs 22% YoY; FCF margin 26% vs 24% YoY) − 5 moderate keyRisk (Microsoft Defender bundling unchanged; multiple still the residual) = 89. Do not bump because they beat. The old author string that added +4 TAM expansion and printed 93 is retired — primaryType does not score.
Price Scenarios (12–24 Months)
Valuation Multiples
| Trailing P/E (GAAP) | N/A |
| Forward P/E (FY27, non-GAAP) | ~182× |
| PEG Ratio | ~7.6× |
| Price / Sales (FY27) | ~39× |
| Price / FCF (FY27E) | ~129× |
Post-print tape $227.96 (Aug 27 close, Yahoo) ripped +20.5% from the $189.18 Aug 26 pre-print close and sits near the $229.08 52-week high. Forward multiple is ~182× on the company's own $1.25–$1.26 FY27 EPS guide and ~39× FY27 revenue — richer than the Aug 18 ~151× on a stale ~$1.49 consensus, still the richest multiple in coverage. Yahoo 1y target est $210.54 / high $256 (quote page; Jefferies $230 was Aug 24, pre-print). The beat-and-raise and record Q2 FCF still justify a premium to slower cyber peers; the margin of safety is the residual, not a fire. Next test is Q3 NNARR $343–$347M and the FY27 34% NNARR midpoint, not a restated ladder.
Approximate figures as of August 26, 2026.
Where We Are vs Targets
Loading live price…
The AI-security re-rating deflates: Q3 NNARR misses $343–$347M or the FY27 34% NNARR midpoint is cut, Microsoft Defender bundling pressures SMB retention, and the multiple compresses from ~39× toward ~24× NTM revenue.
- Q3 NNARR prints below $343M, or a subsequent guide cuts FY27 NNARR growth below the 34% midpoint — the Q2 +51% re-acceleration proving a one-off rather than a durable trend
- NRR slips below 112% for two consecutive quarters as SMB budget pressure limits upsell of identity and SIEM modules
- Microsoft Defender + Sentinel bundling converts 5%+ of Falcon's SMB installed base by end of 2026 — Q2 did not produce a new fact that removes this
- Multiple compresses to ~24× NTM revenue as the AI-security premium fades
CrowdStrike delivers the raised FY2027 guide (revenue $5.9911–$6.0111B, ARR $6.6030–$6.6119B, NNARR growth 34% at the midpoint) with FCF margin at least 30%, while the multiple normalises toward last-sourced Street (Yahoo 1y mean ~$211) as the re-acceleration proves durable but not endlessly re-rateable. Ladder held; do not mark this up because they beat.
- Q3 NNARR lands in the $343–$347M implied range; FY2027 revenue at the $5.9911–$6.0111B guide with NNARR growing 34% at the midpoint; ARR crosses $6.6B
- Next-Gen SIEM, Cloud, and Next-Gen Identity combined stay on the >$2.18B / +39% YoY path printed in Q2 (IR deck); do not require SIEM alone to recapture the old +75% rate
- Identity >$695M and Cloud >$905M (Q2 IR deck) keep consolidating; Falcon Flex ending ARR holds the $2.29B run-rate
- FCF margin at least 30% for FY27 (IR modeling point) as operating leverage on the $5.8B+ ARR base offsets growth investment — Q2 printed 26%, Q3 modeled 27.5%
CrowdStrike cements itself as the AI-native security operating system — Charlotte AI / AIDR consumption and platform displacement re-accelerate ARR toward $8B+, supporting a sustained premium above last-sourced Street high (Yahoo ~$256) and a ~45×+ NTM revenue multiple.
- ARR reaches $8B+ by FY2028 as Next-Gen SIEM, Cloud, and Identity keep compounding off the Q2 >$2.18B combined base (IR deck)
- Charlotte AI / AIDR (agentic security layer) drives a new consumption model, adding $500M+ ARR from AI-native workflows — named in the print, not yet a sourced ARR line
- Falcon Flex stays a doubling-class motion off the $2.29B Q2 base (already +101% YoY this print); Re-Flex conversion keeps the >40% ARR uplift the deck printed
- International (EMEA 18% / APAC 11% of Q2 revenue, IR deck) and sovereign cloud add an incremental vector — this print did not book a government-contract dollar figure