
CrowdStrike invests in Israeli cyber startup Above as insider threats climb the security agenda
The strategic investment strengthens product integration with Falcon and underscores growing demand for AI-native security tools that monitor trusted users, not just outside attackers.
CrowdStrike has made a strategic investment of several million dollars in Israeli cybersecurity startup Above Security, deepening a partnership centered on insider threats.
The investment comes less than five months after Above emerged from stealth with a $43 million Series A round led by Merlin Ventures, Ballistic Ventures, and Norwest Venture Partners, with participation from Jump Capital and QPV Ventures. Within just six months of its founding, the company had completed both a $7 million Seed round and the $43 million Series A, raising $50 million before the latest investment.
While financial terms of CrowdStrike's investment were not disclosed, the deal is accompanied by a closer product integration that will allow Above's technology to operate directly within the CrowdStrike Falcon platform, giving CrowdStrike customers access to AI-powered insider threat investigations using Falcon's security telemetry.
The investment highlights growing investor interest in a corner of cybersecurity that has become increasingly important as enterprises adopt artificial intelligence and employees gain access to more sensitive data across cloud applications. Unlike conventional cybersecurity tools designed to stop external attackers, insider risk platforms seek to detect malicious or negligent behavior originating from legitimate users inside an organization.
Above was founded in 2025 by Aviv Nahum, a veteran of Unit 81, and Amir Boldo, a veteran of Unit 49, both elite branches of Israel's Unit 8200. Both founders are experienced entrepreneurs with previous exits. The company has developed a platform designed to identify and respond to insider threats inside organizations by using autonomous AI agents to continuously investigate user behavior rather than relying on traditional policy-based monitoring.
According to the company, its platform analyzes activity across user identities, enterprise applications, data movement and workflow context to build behavioral narratives that explain not only what happened, but also why a user's actions may represent a security risk. Instead of generating isolated alerts, the system produces investigation-ready cases that include behavioral timelines, contextual analysis, risk assessments and recommended responses.
Related articles:
The partnership will integrate those capabilities with CrowdStrike's Falcon platform. Above will use telemetry from Falcon's Next-Gen SIEM, correlating endpoint, identity and third-party data into completed insider risk investigations before sending the results back into the Falcon platform.
"The Falcon Fund invests in companies developing innovative technologies that solve meaningful cybersecurity challenges," said Michael Sentonas, President of CrowdStrike. "Above has built a compelling agentic approach to insider risk management."
For Above, the investment further strengthens a relationship that has expanded rapidly over the past year. Earlier this year, the company was selected from nearly 1,000 applicants to participate in the CrowdStrike Cybersecurity Startup Accelerator, presented in collaboration with Amazon Web Services and Nvidia. It advanced to the live finals at the RSA Conference and finished as the program's runner-up.
"Today's insider risk won't be solved through policies alone, it will be solved through investigation," said Aviv Nahum, Above's co-founder and CEO. "By combining Above's AI investigative agents with CrowdStrike's platform and go-to-market reach, we're helping organizations operationalize insider risk management at scale."














