CrowdStrike Falcon Next-Gen SIEM gives you the platform. What it does not give you is the detection content for your environment: your log sources, your applications, your definition of normal. That layer is built, and it is where most SIEM projects either succeed or quietly stall.
All three layers run inside the Falcon platform you already license. No second system, no separate log store, and no data leaving the EU.
The CQL Hub is public and free: 174 CQL queries and 15 lookup files for Falcon Next-Gen SIEM and LogScale, plus a CrowdStrike-certified Foundry app that keeps the lookups current in your tenant. Many teams take it from there on their own. Three things regularly stop the ones who cannot.
The library itself stays open and free: browse all 174 queries on the CQL Hub, no account and no contract required.
Some teams already run Falcon Next-Gen SIEM and want more out of it. Others are still on a legacy platform and need to move without losing detection coverage on the way. The route differs, the deliverable does not: rules that fire on the right things, documented well enough for your team to own them.
Copying a query out of the hub and running it once is easy. Keeping a detection accurate while your environment keeps moving is a different discipline. In our projects it comes down to five questions.
Most teams sit at level 3. If the real gap is that nobody is watching the alerts around the clock, our Managed CSIRT and MDR service covers that side.
No. The library is public and free, with or without a contract, and it stays that way. It exists because working CQL queries for Falcon Next-Gen SIEM are hard to find anywhere else. If the queries are all you need, take them.
Yes, and it is one of the two ways most projects start. We inventory the log sources, data models and active use cases in the existing platform, build a staged migration plan with dependencies and dates, stand up the new environment alongside the old one and carry the use cases over with testing at each stage.
An implementation with a defined set of log sources and use cases runs a few weeks. A migration depends on how many rules and parsers sit in the old platform, which is exactly what the inventory in the first phase establishes. Larger projects are staged so detections reach production early instead of everything landing at the end.
Yes. Rule documentation, runbooks and reporting are delivered in English or German. The team sits in Munich, so log data and evidence stay inside the EU. ByteRay is listed by Germany's federal cyber agency (BSI) as a qualified APT response provider under Section 3 BSIG.
Yes. Either the platform alone, which covers operation, log source monitoring, parsing and normalisation checks, updates and regular reporting, or the platform together with round-the-clock monitoring of its alerts through our Managed CSIRT. Both work alongside Falcon Complete.
The fastest check is your own Falcon console: under Foundry › App catalog you will find the ByteRay CQL Hub marked as a certified app, reviewed by CrowdStrike and released to all customers rather than self-published. The public library behind it is at cql-hub.com, and our consultants hold the CrowdStrike Certified SIEM Engineer qualification.