CrowdStrike and Mandiant announced a strategic partnership on April 7, 2022, under which Mandiant planned to use CrowdStrike’s Falcon platform and subscriptions in incident-response services and proactive consulting. On May 9, 2024, CrowdStrike and Google Cloud announced an expansion: Mandiant’s Incident Response and Managed Detection and Response services would use Falcon alongside Google Cloud Security Operations.
What did CrowdStrike and Mandiant announce in 2022?
The April 7, 2022 announcement described a mission-focused partnership for joint customers. Mandiant planned to use CrowdStrike Falcon and its subscription offerings in incident-response work and proactive consulting engagements. The stated aim was to support customers through investigation and remediation, as well as ongoing defense.
The announcement also said Mandiant Managed Defense intended to add support for customers using Falcon later that year. That was a plan stated in 2022, not a guarantee of current service packaging. CrowdStrike’s original announcement quoted the companies’ leaders describing the arrangement as a way to combine security technology and expertise.
What changed in the 2024 expansion?
On May 9, 2024, CrowdStrike and Google Cloud announced an expanded strategic partnership to power Mandiant Incident Response (IR) and Managed Detection and Response (MDR) services. The expanded services leverage both CrowdStrike Falcon and the Google Cloud Security Operations platform, with an emphasis on endpoint detection and response (EDR), identity threat detection and response (ITDR), and Exposure Management. The expansion announcement describes the technology and service scope.
#1 Best Overall
This is an expansion involving Google Cloud, rather than a replacement of the original CrowdStrike–Mandiant relationship. The 2022 announcement centered on Mandiant using Falcon; the 2024 announcement named Google Cloud Security Operations as an additional platform used in the IR and MDR services.
How does Mandiant use CrowdStrike Falcon?
In the original arrangement, Falcon was the technology platform Mandiant planned to use while delivering incident response and proactive consulting to joint customers. The 2024 announcement broadened the stated technology context: Mandiant’s IR and MDR services would leverage Falcon in concert with Google Cloud Security Operations, across EDR, ITDR and Exposure Management.
These announcements establish the intended service and technology relationship, but do not specify a complete deployment design, feature-by-feature integration, or the exact products and subscription tiers required for an individual customer. Buyers should confirm current service scope and commercial availability with the vendors.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is this an incident-response or MDR offering?
It encompasses both, but the terms describe different kinds of work. Incident response is focused on investigating and helping remediate an incident. MDR refers to managed detection and response, a service model for ongoing detection and response. The 2022 announcement also described proactive consulting, while its reference to Mandiant Managed Defense was a forward-looking plan. In 2024, the companies explicitly described both IR and MDR services powered by Falcon and Google Cloud Security Operations.
So the partnership is not simply a new security product or a standalone software bundle. It is a relationship combining security platforms with Mandiant’s professional and managed services for customers. The announcements do not provide partnership-specific revenue, customer counts, or measured outcome statistics.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

