Search/CrowdStrike
Source

CrowdStrike

Connections
19 relationships
CrowdStrike Announces Agentic Identity Provider
AI agents are evolving identity as we know it. They execute code, invoke tools, access applications and sensitive data, and take action on behalf of humans and systems. Increasingly, they operate autonomously and delegate work to other agents. They work at machine speed. Yet the identity infrastructure enterprises rely on today was built for people and predictable workloads, not autonomous software that can reason, act, and move dynamically across systems. Traditional identity providers force organizations to represent agents through service accounts, API keys, and workload identities. Agents effectively inherit the identity and credentials of the humans they act for, operating under trust established by the existing user. This makes it difficult to distinguish the agent from the person, independently govern what the agent can do, or reliably ensure accountability for its actions. Before an AI agent's access can be continuously governed, the agent itself must first be established as a trusted identity. Today at Fal.Con 2026, CrowdStrike is introducing Agentic Identity Provider (Agentic IdP) in CrowdStrike Falcon® Next-Gen Identity Security, creating the identity control plane for the agentic enterprise. Agentic Identity Provider gives every AI agent a trusted identity, connects it to the humans and workloads behind it, and gives it only the access it needs, when it needs it. We're also expanding modern privileged access across SaaS applications, endpoints, code repositories, and cloud infrastructure. This extends Continuous Identity and zero standing privileges wherever humans and AI agents operate. Together, these innovations advance CrowdStrike's vision for Continuous Identity by establishing trusted identities for AI agents and replacing standing privileges and point-in-time authorization with access that continuously adapts to real-time security and business context. Introducing the Agentic Identity Provider Traditional identity providers answer a fundamental question: Who are you? For humans, this answer starts with an established identity tied to an employee, credentials, and an authentication process. For AI agents, it isn't as simple. Agents don't onboard like employees. Representing them as traditional service accounts or long-lived credentials creates a dangerous mismatch between how agents operate and how enterprises govern identity. CrowdStrike’s Agentic Identity Provider, built for this new model, provides the identity foundation AI agents need before their access can be continuously governed. It can: Establish trusted identities: CrowdStrike Falcon® Guardian discovers AI agents across the enterprise and identifies who owns and uses them. The Agentic Identity Provider automatically registers agents in a single directory and gives each one a cryptographically verifiable identity. Only trusted, registered agents can be granted access. Enrich AI agents with identity context: Falcon Next-Gen Identity Security adds critical context to each identity, including whether they are high-risk or compromised and what privileges they hold. This gives security teams a clearer picture of who or what is behind each agent and the risk it poses. Broker short-lived, least-privilege access: Instead of assigning agents standing credentials of their own, the Agentic Identity Provider securely brokers short-lived, tightly scoped access on their behalf, providing only the access required for as long as it is needed to complete a task. Maintain end-to-end attribution: Every agent, and every action it takes, remains linked to the human or workload it acts on behalf of. This preserves a continuous chain of accountability as agents interact with systems and delegate work. Earlier this year, CrowdStrike introduced Continuous Identity for AI Agents to bring real-time, context-aware authorization to agent actions. Continuous Identity replaces point-in-time access decisions with dynamic enforcement based on live identity, device, threat, and business context. This capability grants access when it is justified and revokes it the moment conditions change. The Agentic Identity Provider establishes who the agent is. Continuous Identity determines what that agent should be allowed to access and what it should be allowed to do continuously. Together, they create an identity model built for autonomous action. Extending Modern Privileged Access Everywhere Work Happens Standing privilege remains standing risk, whether the identity accessing a critical resource is an AI agent, administrator, developer, or business user. However, traditional privileged access management was designed around a narrow set of administrative accounts and predictable workflows. Today's privileged interactions happen everywhere: in cloud infrastructure, SaaS applications, endpoints, servers, and private enterprise resources. CrowdStrike is expanding modern privileged access across these environments. Rather than leaving persistent privilege, modern privileged access grants access only when the task requires it, continuously evaluates it while in use, and revokes it when it is no longer justified. CrowdStrike is extending these capabilities across: SaaS applications: Bring modern privileged access to business-critical applications including Salesforce and GitHub. Endpoints and servers: Give users elevated access to endpoints and servers only when they need it, instead of leaving administrator privileges permanently enabled. Private applications and enterprise resources: CrowdStrike brings enterprise browser security and privileged access together, connecting users to SaaS, cloud, and on-premises resources while giving them only the privileges they need to get work done. This includes just-in-time access to workloads like Linux over SSH and Windows over RDP, custom apps, and much more. Next-Gen Identity Security grants access based on security and business context, while CrowdStrike Falcon® Seraphic® Enterprise Browser provides the secure connection, without additional agents or browsers. If risk changes or a threat is detected, access is immediately revoked. Cloud infrastructure: Earlier this year, CrowdStrike announced modern privileged access for AWS through Okta. CrowdStrike is now extending this support to AWS environments using Microsoft Entra. The result is a fundamentally different approach to privileged access. Access isn't trusted simply because it was approved once. It remains trusted only while the identity, device, security, and business context continue to justify it. This distinction becomes even more critical as humans and AI agents increasingly interact with the same applications, infrastructure, and data. Falcon Next-Gen Identity Security | Just-In-Time Access for Salesforce and GitHub Falcon Privileged Access | Zero Standing Privileges for Private Apps MDR for the Modern SaaS Attack Surface As SaaS becomes a critical operating layer for humans and AI agents, it is also becoming a high-value target for adversaries. Compromised identities can give attackers legitimate access to SaaS applications, which allows them to operate undetected and makes continuous detection and response more critical than ever. CrowdStrike is extending CrowdStrike Falcon® Complete MDR services to CrowdStrike Falcon® Shield, bringing 24/7 expert-led monitoring, investigation, and response to the SaaS security capabilities within Falcon Next-Gen Identity Security. CrowdStrike experts leverage Falcon Shield’s visibility across identities and threats targeting SaaS applications to identify and stop malicious activity in real time. By combining high-fidelity detections, agentic workflows, and expert-led operations, Falcon Complete for Falcon Shield turns SaaS visibility into action, helping organizations rapidly contain threats, reduce operational burden, and extend continuous protection across the agentic enterprise. Identity Security Built for the Agentic Enterprise The agentic enterprise requires a new identity security model. AI agents can't be secured like service accounts, privilege can’t remain static while risk changes, and identity security can’t stop at authentication. CrowdStrike is bringing identity establishment, authentication, authorization, privileged access, detection, and response together through Falcon Next-Gen Identity Security. By connecting identity to real-time context across endpoint, cloud, SaaS, and enterprise systems, CrowdStrike can help organizations continuously grant, adjust, and revoke access as risk and business context change. Additional Resources Learn more about Falcon Next-Gen Identity Security Read about Continuous Identity for AI Agents Learn more about modern privileged access Forward-Looking Statements This blog includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.
crowdstrike.comSep 2, 2026source
CrowdStrike Delivers the Next Evolution of the Agentic SOC
The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to the CrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real time. CrowdStrike is delivering new innovations with the next evolution of the agentic SOC, in which analysts and AI agents work together in a unified system. In the legacy SOC, evidence lives in disconnected systems. Automation is split across separate interfaces and execution logs. Analysts toggle between tools and manually stitch together context. Only a subset of detections receives real investigation while everything else piles up as a structural blind spot. But most security teams struggle to achieve an agentic SOC transformation, for three key reasons. First, fragmented data prevents cross-domain investigations. When context lives in separate tools and isn't AI-ready, agents can't connect the dots across identity, cloud, endpoint, SaaS, and network. Second, isolated agents reach incorrect or late verdicts. Because they work in silos with sequential handoffs, they see only a partial picture, which reverts the work back to analysts. Third, ungoverned automation creates breach points. Agents act in your environment and connect to your systems; if you can't build, monitor, and control them, you can't see what's running, what it's connected to, or what it costs. CrowdStrike takes a different path. The CrowdStrike Falcon® platform is not just where agents run. It is where the data is generated, enriched, investigated, orchestrated, and governed. New at Fal.Con 2026: The Evolution of the Agentic SOC At Fal.Con, CrowdStrike is delivering the next evolution of the agentic SOC, a production operating model where expert agents and analysts stop breaches as one system. New capabilities in the Falcon platform include: A more unified foundation: Third-party data now arrives detection-ready through certified pipelines, with detection logic running inside the pipeline before data reaches its destination. This accelerates both time-to-value and mean time to detect (MTTD). Coordinated teams of specialist agents: For actions ranging from cross-domain investigations to proactive reconnaissance, teams can deploy fleets of battle-tested agents built by CrowdStrike experts and coordinated by an orchestrator agent, all of which work out of the box. A unified agentic SOAR workspace. Charlotte AI AgentWorks, SOAR orchestration, and CrowdStrike Falcon® Foundry converge in one place to build and govern rule-based and agentic automation alike, with expanded flexibility for how security teams can build agents and connect them to their security stack via MCP. See it in action: Coordinated expert agents investigate every domain at once and converge on a single verdict Let’s take a closer look at what’s new. Certified Data, Ready for Agents The Falcon platform starts from native telemetry and extends outward, delivering petabytes of cross-domain data refined by elite security experts in one unified foundation. Teams decide what is ingested and what is federated, and critical first-party data has no ingestion cost. The result is agents with a complete view of their environment that is AI-ready from the start. Third-party data traditionally depends on pipelines customers build and maintain themselves, with no guarantee that data lands complete or usable. A single dropped field or schema change can break a detection without anyone noticing. In an agentic SOC, where agents act on data automatically, that risk compounds. CrowdStrike is closing this gap with new capabilities that optimize how third-party data gets in, what happens to it in flight, and whether teams can trust it when it lands. These include: Certified data pipelines (Public Preview). Teams will get pre-built, pre-tested data flows that CrowdStrike validates and maintains, starting with Zscaler and Palo Alto Networks. Sources go live in hours and arrive detection-ready, so coverage starts when a new source is connected. There is no pipeline overhead to carry, and only security-relevant data reaches the platform.
crowdstrike.comSep 2, 2026source
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report found. Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every day. The endpoint is where those malicious packages land, execute, and need to be stopped. CrowdStrike is advancing endpoint security with Real-Time Supply Chain Attack Protection, a capability natively embedded in the lightweight CrowdStrike Falcon® sensor. It detects and blocks malicious open-source packages as they reach the endpoint, before any embedded code can execute, and provides a global inventory of installed packages across the organization. It requires no new sensor deployment, separate tool, or changes to developer workflows. The Problem Extends Beyond Developer Workstations When most organizations think about software supply chain risk, they think about developers running npm install or pip install on their workstations. That is a critical surface, but the picture has gotten much larger. In the AI era, everyone is a developer. Agentic applications like Claude Code and ChatGPT Codex are now used across marketing, HR, finance, and operations teams. These tools automate tasks, generate content, and build internal workflows. When an agentic application recommends downloading a package to complete a task, employees across the business may unknowingly expose their endpoints to compromised dependencies. The attack surface has expanded from a few hundred developer machines to potentially every company endpoint. Adversaries are capitalizing on this expanded surface, as documented in the CrowdStrike 2026 Threat Hunting Report: STARDUST CHOLLIMA poisoned 131 AI framework packages, which are trusted building blocks that can inherit access to sensitive enterprise assets and become attack paths for credential theft and persistence. ALTERED SPIDER compromised more than 300 software dependencies in a single day, spreading poisoned packages at scale and turning trusted code into downstream supply chain compromise.1 How Real-Time Supply Chain Attack Protection Works Real-Time Supply Chain Attack Protection extends the Falcon sensor’s visibility and control to non-executable software packages. When a package manager transaction is initiated, the Falcon sensor intercepts the download and evaluates suspicious files against CrowdStrike Falcon® Adversary Intelligence. If a match is found, the sensor immediately quarantines the file before any embedded setup script can execute. This is modern endpoint security doing what endpoint security does best: seeing and stopping threats where they land. The same unified sensor, already deployed, already protecting the fleet, now covers packages too, whether they’re downloaded by a human or an AI agent. Key capabilities include: Continuously monitor package activity: The Falcon sensor maintains a constant watch over package downloads across npm and PyPI on Windows, macOS, and Linux, closing critical entry-point blind spots and giving security teams visibility into active, incoming code across the enterprise fleet. Stop malicious packages at download: The Falcon sensor automatically detects and quarantines compromised packages the moment they are written to disk, neutralizing threats before malicious embedded scripts have a chance to execute. This is real-time prevention, not after-the-fact detection that requires a separate response workflow to contain damage. Automate fleet-wide investigation: The moment a new package is flagged as compromised, the Falcon platform instantly runs an intelligent lookback query across enterprise data. If a historical match is discovered, automated containment workflows isolate the threat and remediate affected endpoints, minimizing manual analyst triage. Gain full visibility with global package inventory: Falcon provides comprehensive visibility into software packages installed across the enterprise fleet, helping security teams understand package relationships and identify where risky versions reside, directly from the unified Falcon console. Implement proactive policy controls and cooldown protection: Falcon reduces software supply chain risk with granular, risk-based controls including minimum package age requirements, restrictions on publicly available packages, and automated fallbacks to approved versions. Security teams gain proactive governance over what code reaches their endpoints. Watch how it works: Proactive Protection: Control and Cooldown Beyond real-time detection and prevention, CrowdStrike is delivering granular policy controls that address a well-documented pattern: The first few days after a new package version is released represent a critical risk window, before malicious versions are widely identified and removed. Freshly published packages carry the highest risk because they have undergone the least community scrutiny. Proactive policy controls allow security teams to enforce minimum package age requirements before a package can be installed on a protected endpoint, effectively placing new and untrusted packages in a cooldown period. Organizations can also restrict access to publicly available packages or redirect users to approved, vetted versions. This gives security teams governance over what code reaches their endpoints while preserving productivity. Proactive policy controls are set to be released in Q4. Global Package Inventory Visibility is a prerequisite for control. Real-Time Supply Chain Attack Protection provides a comprehensive global inventory of installed software packages across the enterprise via CrowdStrike Falcon® Exposure Management, enriched with CrowdStrike Counter Adversary Operations intelligence. Security teams can understand package relationships, identify where risky package versions reside across the fleet, and take action from the same unified console they already use for endpoint protection. This inventory spans the entire managed fleet, covering every endpoint where packages are present, including the non-developer machines that developer-only solutions cannot see. Global Package Inventory is set to be released in Q3. Unified Through the Falcon Platform Real-Time Supply Chain Attack Protection ships through the existing Falcon sensor. There is nothing additional to deploy, no developer workflow to change, and no separate console to manage. Organizations that already run the Falcon sensor gain supply chain protection by enabling a policy. Our single-sensor architecture stands in sharp contrast to the alternative: deploying a separate developer workstation sensor from one vendor, a supply chain scanner from another, and still having no coverage for the majority of endpoints where agentic applications are actively downloading packages. The Falcon sensor already protects the fleet. Real-Time Supply Chain Attack Protection extends that protection to the package layer for every endpoint, with real-time blocking and automated remediation built in from Day One. As adversaries continue to weaponize the software supply chain at scale, defenders need real-time enforcement at the point of impact. Real-Time Supply Chain Attack Protection puts that enforcement exactly where it belongs: at the endpoint, at the moment of download, before code executes. Additional Resources Learn more about stopping supply chain attacks with CrowdStrike. See Real-Time Supply Chain Attack Protection in action. Read the CrowdStrike 2026 Threat Hunting Report to learn more about recent supply chain threats and adversary tradecraft. Disclaimer This blog includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available. 1 CrowdStrike 2026 Threat Hunting Report
crowdstrike.comSep 2, 2026source
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches. This shift demands a new approach to AI security. Traditional tools can discover AI assets, govern access, or inspect individual interactions, but they were not designed to connect agent activity with the downstream system actions they trigger. Securing the agentic enterprise requires visibility and control at agent runtime. CrowdStrike is introducing CrowdStrike Falcon® Guardian, the evolution of Falcon AI Detection and Response (AIDR) and CrowdStrike’s flagship solution for the AIDR category. Falcon Guardian includes Falcon AIDR’s AI visibility, governance, data protection, and threat detection and response capabilities across endpoint, cloud, and SaaS environments, while introducing powerful new capabilities to comprehensively discover, investigate, and secure AI agents on the endpoint, where AI executes. Falcon Guardian will include a new AI gateway capability to provide a centralized control and monitoring point for enterprise AI traffic. CrowdStrike is also extending our elite security services, expanding support for cross-domain threat hunting and managed detection and response (MDR) to Falcon Guardian. With Falcon Guardian, CrowdStrike is extending our runtime security architecture into the agentic layer. Falcon Guardian fuses AI agent activity with CrowdStrike Falcon® platform endpoint telemetry to establish a direct causal chain from prompt to runtime behavior and impact. This gives security teams the context to understand what agents do, investigate AI threats and their blast radius, and respond before threats spread. Secure AI Agents Where They Execute AI agents introduce a new execution layer. They may reason at the AI layer, but when they take action, those actions execute through the operating system and interact with files, credentials, networks, applications, and other enterprise resources. This makes the endpoint a critical control point for understanding and securing autonomous AI behavior. Built on the Falcon platform, Falcon Guardian combines continuous agent discovery with runtime visibility, investigation, and control to help organizations understand which AI agents are operating and what they do. New capabilities include: Discover shadow AI agents: Falcon Guardian continuously discovers known and previously unknown AI agents across supported Windows, macOS, and Linux endpoints. It identifies where they are running, who is using them, and their security status. Connect AI activity to runtime impact: Falcon Guardian fuses AI agent activity with Falcon endpoint telemetry to connect prompts, skill use, tool calls, MCP servers, and identity with downstream system execution for supported agents. This establishes prompt-to-runtime-behavior that shows security teams what an agent was asked to do and what happened. Turn AI governance into runtime control: Falcon Guardian enables organizations to define which supported AI agent types are permitted to operate on managed endpoints, helping security teams sanction approved agents and prevent unauthorized agent types from running. Existing Falcon Guardian controls continue to protect supported AI interactions against threats such as prompt injection and sensitive data exposure. Investigate threats to agents, determine blast radius, and stop breaches: Falcon Guardian reconstructs agent sessions and downstream execution into a unified causal investigation, allowing analysts to trace suspicious activity across affected agents and systems. Teams can quickly pivot to related activity to understand the scope of exposure and drive automatic containment by blocking malicious agent behaviors and compromised assets at runtime across agents. Falcon Guardian’s new AI agent security capabilities build on a broader foundation of AI protection. It continues to help organizations discover shadow AI across endpoint, cloud, and SaaS environments, govern access to models and AI tools, protect sensitive data, and detect AI-specific threats. This foundation protects both workforce AI adoption and enterprise-developed AI systems.
crowdstrike.comSep 1, 2026source
Benchmaxxing: When the Benchmark Becomes the Target
Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space. As Goodhart’s Law suggests, measures become less useful when they become targets. Gaming, ceiling effects, and data leakage erode the signaling value of doing well on public benchmarks. In the AI and cybersecurity space, the problem carries greater consequences because benchmark results can shape real security decisions. The industry has seen this before. Last decade, we called it "detection coverage" and learned through experience that vendors passing canned tests was a poor proxy for stopping adaptive adversaries in real environments. As AI becomes more deeply embedded in cybersecurity, we should not repeat the same mistake with a new class of benchmarks. In this blog, we examine the limitations of public cyber benchmarks and describe an approach for task-coupled internal benchmarks that drive rigorous science rather than optimizing for visibility or attention. The Challenges of Cyber Benchmarking The headlining failure of most cyber-relevant AI benchmarks is that they fail to measure what matters most: the ability of defensive cyber agents to reason end-to-end across exploits, telemetry, and environments, and generate novel detection or remediation strategies. In short, benchmarks fail to measure the ability to stop breaches. Benchmarks typically need ground truth for scoring, making them retrospective and often binary. This does not reflect defenders’ real challenges, which are constantly novel and epistemically gray. Benchmarks also rarely report the harms caused by mistakes, while leaderboards commonly downplay costs and times. Those factors are critical, especially as, for instance, eCrime breakout times are plummeting. By comparison, the reference action, human red teaming and detection generation, is well understood. Overall scores often obfuscate subpopulations where solvers perform poorly. A scoreboard might show 97%, but if that 3% falls within a group of jointly exploitable attack paths, the aggregate score has little construct validity. While benchmarks can be useful regression tests, their headlining results are structurally biased against generalizing to the real world. Contamination from direct or indirect leakage, solution leakage, and retrospective tasks all lower the upper bound on generalization. When the same model and harness are shipped, they will almost certainly underperform on novel stimuli. Overfitting, an inevitable result of benchmaxxing pressure, can also occur due to repeated evaluation. Every development cycle that checks the public test set and adjusts accordingly leaks information into the model, even with zero gradient updates. More subtly, publication bias causes the error distribution to be skewed strongly downward, as published results are likely drawn from surprisingly strong runs that are unlikely to be repeated. Common reporting patterns compound this problem by downplaying the probabilistic nature of results from agentic workflows. “Solved it in at least one of ten attempts” with an unbounded budget is grade inflation, not rigor. While these issues may seem esoteric or statistical, there are also more basic issues with benchmark scores because of the extent to which agents cheat. Dreadnode reported last month that more than a third of all passes on individual tasks on Cybench, across nearly every model assessed, involved cheating. In these cases, models searched postmortems on attacks, probed evaluation infrastructure, and read or inferred answers or paths from evaluation container metadata. When cheating is this prolific, benchmarks are not only measuring the wrong thing, they are doing so poorly. Public cyber benchmarks can also create information that benefits adversaries. Leakage, and even test questions themselves, can be used for model training or uplift. The public nature of benchmarks may also help adversaries understand which existing vulnerabilities are considered important enough to measure, and how detectable they are. Advanced adversaries may reason about vulnerabilities that are not measured and treat those gaps as potential soft spots. How CrowdStrike Approaches Benchmarks and Evaluations At CrowdStrike, rigorous evaluations are core to guiding our fast-moving AI research and development agenda. Substantively, our evaluations are designed to directly measure the capabilities we care about across malware analysis, detection engineering, threat intelligence comprehension and synthesis, log and telemetry analysis, and incident response reasoning. They measure real outputs against live problems, with increased realism driven by high-quality digital twins of real-world customer environments and increased difficulty driven by adversary tradecraft emulation. Being exceptionally difficult is a hallmark of our evaluations. Evaluations and benchmarks at CrowdStrike are intended to be living methods, not static checks. Public benchmarks provide useful common reference points, but for organizations deploying frontier AI, the most meaningful measures of success are private evaluations grounded in their own data, systems, workflows, and operational outcomes. These evaluations test whether an AI system can perform reliably where it will actually be used, not simply whether it can score well on a widely known test. Instead of optimizing for success in loosely related tasks, CrowdStrike’s benchmarks are task-coupled to support sharp decision-making. We are applying this approach in practice today. Our teams introduce novel evaluation content, rotate validation sets, and assess capabilities against cybersecurity problems that reflect real operational conditions. This helps preserve benchmarks as useful mileposts while creating more relevant tests that evolve with the systems being evaluated and reduce opportunities for benchmaxxing. We also separate evaluation developers from our solution architects. This firewalling helps limit leakage and preserve the credibility of evaluations over time. Our deployment methodology supports many-time/any-time runs at scale, allowing us to measure the full error distribution of solvers and report them meaningfully. Further, our measurement scheme goes well beyond task completion to include other factors that matter in the real defensive world, including cost, latency, stealth, and completeness. Public benchmarking still has an important role when it advances shared industry understanding. In partnership with Meta, CrowdStrike introduced CyberSOCEval, an open-source benchmark suite designed around real-world SOC workflows, adversary tradecraft, and operational outcomes. Ultimately, the goal is not to produce the highest benchmark score, but to build evaluations that tell us whether AI systems can deliver reliable defensive outcomes against the complexity and uncertainty of real-world cyber threats. Additional Resources Learn how CrowdStrike Falcon® AI Detection and Response secures AI. Download our guide to explore the five steps for frontier AI security readiness. Explore cutting-edge cybersecurity research at Day Zero 2026, a summit for the threat research community. Experience Fal.Con 2026 from anywhere with Fal.Con Digital, featuring keynote livestreams and on-demand access to 100+ sessions.
crowdstrike.comAug 19, 2026source
Teaching AI to Reason Through Detection Triage
Every security alert begins with a deceptively simple question: Is this a real threat or just noise? Detection triage sits at the front of the response lifecycle, where answering this question quickly and accurately can determine what gets investigated, prioritized, or safely closed. CrowdStrike’s NVIDIA Nemotron-powered detection triage models already answer this question at machine speed, reading a detection and producing a true positive (TP) or false positive (FP) verdict with a calibrated confidence score. But experienced analysts do more than arrive at a verdict. They reason toward weighing evidence across command lines, behavioral context, and other signals to understand not only what happened, but why it matters. So we taught our triage model to do the same. Our latest research paper, “Cybersecurity Detection Classification with Reasoning-enabled Language Models” (Khanna et al., July 2026) which supports the Open Secure AI Alliance, trains a CrowdStrike Charlotte AI™ triage classifier to reason through a detection step by step, and produce a transparent chain of reasoning, before it commits to a verdict. The result is more accurate triage, more detections that can be safely automated, and a rationale that SOC analysts can read, evaluate, and trust. Below are the broader lessons from our findings: Reasoning makes triage better and more transparent: Teaching the model to think through a detection improves accuracy while producing an auditable rationale that analysts can evaluate. More automation is done safely: Large gains in high-confidence recall mean more benign alerts are auto-closed and more real threats can be prioritized for analysts, directly reducing alert fatigue. Specialization beats scale: A fine-tuned Nemotron 3 Nano 30B-A3B open model outperforms frontier general-purpose models many times its size on this task. (See figure 2) The agentic SOC keeps advancing: This research, currently focused on Windows endpoint detections, points to where our NVIDIA Nemotron 3 Nano 30B-A3B-powered triage is headed next, with more platforms to follow. From Labels to Reasoning The conventional approach to LLM-based triage asks the model to read a detection and output a label directly. This is fast and scalable, and produces a usable confidence score; however, it treats a reasoning-driven task as an instinctive response. Chain-of-thought reasoning changes that. Before deciding, the model works through the evidence in the detection: what the process is doing, where it came from, whether the parent-child process chain looks legitimate, and how the pieces fit together. This reasoning trace empowers better verdicts and provides an auditable explanation that an analyst can review, turning an opaque label into a decision they can stand behind. How We Trained the Model to Reason Getting a model to reason well about real detections took a four-stage training recipe, each stage building on the last: Prompt optimization: We automatically searched for the strongest possible reasoning prompt rather than hand-writing one. Crucially, we guarded the search with an LLM judge that rewarded genuine multi-field reasoning, preventing the model from collapsing into brittle numeric shortcuts that score well but don't generalize or explain anything useful. Self-training: The model learned from its own best work. It generated reasoning traces, kept the ones that reached the correct verdict, and fine-tuned them, concentrating its effort on the hardest detections it hadn't yet mastered. Reinforcement learning with verifiable rewards: Because a triage verdict is either right or wrong, we could reward the model directly for correct, well-formed answers. This allows it to discover better reasoning strategies on its own. Notably, it became both more accurate and more concise, reasoning in fewer tokens over the course of training. Confidence calibration: Reasoning introduces a subtle problem: Once the model has argued its way to a conclusion, its final label token is nearly always near-certain, so the token's probability is no longer a trustworthy confidence signal. We solved this by training a separate calibrator that reads the full reasoning trace and estimates the probability that the verdict is correct, restoring the reliable confidence score that automated triage depends on. Results The payoff shows up where it matters most: at the high-confidence operating point that governs automated triage. At this tier, detections can be auto-closed or prioritized with minimal analyst intervention, so higher recall here translates directly into more workload removed from the queue. Compared to the direct-label approach, the reasoning-enabled system surfaces dramatically more actionable detections at the same high precision. This 43.0 percentage point increase in high-confidence false positive recall means far more benign alerts can be automatically and safely closed, while the 18.3 percentage point gain in true positive recall means more genuine threats can be prioritized for analysts. Just as striking is what delivers this performance. The reasoning system reaches 82.6% overall accuracy, well above every off-the-shelf model we tested, including frontier general-purpose models many times its size. In our comparisons, leading general-purpose models clustered around 55% to 71% accuracy on this task, roughly in line with an untrained NVIDIA Nemotron 3 Nano 30B-A3B model and well below the fine-tuned result.
crowdstrike.comAug 17, 2026source
LABYRINTH CHOLLIMA Evolves into Three Adversaries
LABYRINTH CHOLLIMA has evolved into three distinct adversaries with specialized malware, objectives, and tradecraft: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA now likely operate separately from the core LABYRINTH CHOLLIMA group. GOLDEN CHOLLIMA and PRESSURE CHOLLIMA target cryptocurrency entities and are distinguished by the scale and scope of their operations; core LABYRINTH CHOLLIMA operations continue to focus on espionage, targeting industrial, logistics, and defense companies. Despite operating independently, these three adversaries share tools and infrastructure, indicating centralized coordination and resource allocation within the DPRK cyber ecosystem. LABYRINTH CHOLLIMA is among the most prolific DPRK-nexus adversaries that CrowdStrike Intelligence tracks and is responsible for some of North Korea’s most notable intrusions including destructive attacks against South Korean and U.S. entities, and the global WannaCry ransomware incident. CrowdStrike Intelligence assesses that three distinct, highly specialized operational subgroups have emerged since 2018, each with specialized malware, objectives, and tradecraft. This assessment reflects a comprehensive re-evaluation of historical data and a deliberate challenge to our previous LABYRINTH CHOLLIMA attribution framework. We now track these subgroups as GOLDEN CHOLLIMA, PRESSURE CHOLLIMA, and the core LABYRINTH CHOLLIMA group. Effective intelligence demands we constantly reassess established assumptions, relentlessly pursuing an objective, actionable depiction of the threat landscape. LABYRINTH CHOLLIMA’s History and Evolution LABYRINTH CHOLLIMA activity originates from the KorDLL malware framework (active 2009-2015), a source code repository containing implant templates, command-and-control (C2) protocols, libraries for common tasks, and code for various obfuscation techniques. This framework spawned several epoch-defining malware families, including Dozer, Brambul, Joanap, KorDLL Bot, and Koredos, and would evolve into the Hawup and TwoPence frameworks used by LABYRINTH CHOLLIMA and STARDUST CHOLLIMA, respectively.
crowdstrike.comJan 29, 2026source
Data Protection Day 2026: From Compliance to Resilience
January 28 marks Data Protection Day, a date rooted in one of the earliest milestones of the digital age: the anniversary of the 1981 signing of Convention 108, the first legally binding international treaty for data protection. What began as a European initiative has since evolved into a global observance recognized across North America, parts of the Middle East, and beyond. Each year, Data Protection Day offers an opportunity to reflect not only on legal frameworks and regulatory progress, but on whether our collective understanding of data protection still matches the realities of today’s digital environment. Those realities have fundamentally changed. As outlined in the CrowdStrike 2025 Global Threat Report and CrowdStrike 2025 Threat Hunting Report, cyber adversaries now operate with unprecedented speed, scale, and sophistication. eCrime groups, state-backed actors, and hacktivists increasingly rely on advanced social engineering, resilient criminal ecosystems, and the systematic abuse of identities. Stolen credentials, access brokerage, and the misuse of legitimate user accounts have become primary pathways to unauthorized access, data theft, and operational disruption. At the same time, the volume and distribution of data have expanded exponentially, driven by cloud and AI adoption, SaaS sprawl, remote work, and data-driven business models. Data is no longer a static asset protected at the perimeter. It is continuously accessed, replicated, and moved across identities, environments, and third parties. This expansion has fundamentally altered the risk landscape, creating new and compounding vulnerabilities that traditional compliance-centric approaches were never designed to address. These trends underline a hard truth that has become increasingly difficult to ignore: Legal requirements mandate robust security measures as a foundational element of compliance, and security is critical to resilience. Organizations meeting data protection requirements without scrutinizing evolving security standards may not be compliant at all, as they can still be exposed to operational failure, data loss, or large-scale breaches. Data protection, in practice, lives or dies at the intersection of legal safeguards, technical controls, organizational processes, and real-time operational response. When Risk Comes from Within Today’s data protection risks no longer originate solely from external adversaries. They also increasingly emerge from within organizations themselves, whether from insider threats or driven inadvertently by the rapid and often uncontrolled adoption of AI tools. The question is no longer whether organizations should use AI, but whether they can do so in a way that is legally sound, technically secure, and operationally resilient. As generative AI, autonomous agents, and non-human identities proliferate, they introduce an entirely new attack surface that traditional security and privacy tools were never designed to protect. Prompts can be manipulated, models misused, and sensitive data exposed, often without ever crossing a conventional network boundary. Generative AI services and large language models like enterprise copilots and publicly available tools are now deeply embedded in daily workflows. Employees may unintentionally input confidential, regulated, or personal data into AI systems, including information that must not be disclosed or reused for model training under data protection law. This creates a new and pressing challenge for data protection: how to enable innovation and productivity without losing control over sensitive data. For organizations, this means modern data protection must move beyond reliance on individual user behavior toward resilience by design. Automation, real-time monitoring, and policy enforcement at the interaction layer become essential to preventing failure before it occurs. As AI adoption scales across the enterprise, protecting data, models, and infrastructure is no longer enough. The prompt and agent interaction layer, where decisions are made and actions executed, must also be secured. CrowdStrike addresses this challenge with Falcon AI Detection and Response (AIDR). This extends the Falcon platform to secure one of the fastest-growing and least understood attack surfaces by monitoring, governing, and defending AI interactions across workforce AI use and AI development. By detecting and preventing prompt injection, jailbreaks, model manipulation, and unauthorized tool execution in real time, Falcon AIDR helps prevent sensitive data from being exposed or misused. Crucially, it aligns security and privacy with operational resilience by enforcing controls at runtime and delivering visibility, auditability, and seamless integration into security operations without disrupting legitimate workflows. Addressing this new internal risk landscape also requires controls that span identity, endpoints, and the browser. This approach is reflected in CrowdStrike’s recently announced intent to acquire SGNL and Seraphic, which will focus on securing AI-era access decisions and browser-based data exposure. Moving Beyond the Illusion of Absolute Control The ongoing debate around data sovereignty and “sovereign cloud” solutions highlights why this challenge cannot be solved by assuming fully localized or on-premises solutions offer the same security outcomes as those delivered by global infrastructure. CrowdStrike’s Global Data Sovereignty initiative is grounded in the fact that regional data residency must reinforce protection from adversaries, not isolate defenders. At its core, cybersecurity is a data problem. Limiting how security data can be analyzed, correlated, and acted upon reduces visibility, slows response, and can weaken the global threat intelligence required to counter modern adversaries. Data isolation constrains defenders, not adversaries. By enabling customer-directed data flows and resilient data architectures while preserving unified visibility across environments, CrowdStrike helps security teams correlate signals, apply intelligence, and respond effectively as threats move across systems, allowing cybersecurity to operate at the scale and speed of the adversary. This approach is guided by secure governance, responsible data handling, and respect for jurisdictional realities. Data is managed lawfully, transparently, and with discipline as AI reshapes how organizations operate. By combining regional data residency with global protection, CrowdStrike stops breaches in a world where attacks do not respect borders. The conversation needs to shift from data protection as a static compliance exercise to data protection as a core pillar of organizational and cyber resilience. Achieving resilience requires identifying risks, mitigating those risks, and implementing robust means to limit the impact and likelihood of occurrence of such events. Data protection compliance consequently involves an adaptive posture, active defense, and a focus on preventing ever-evolving threats to privacy. This means ensuring legal principles are supported by technologies and governance models capable of withstanding real-world pressure. Drew Bagley is VP and Counsel, Privacy and Cyber Policy, at CrowdStrike. Christoph Bausewein is Assistant General Counsel for Data Protection and Policy at CrowdStrike. Additional Resources Our Data Protection Day employee checklist can help your organization avoid accidental data leaks. For more about Falcon AIDR, read this blog post: CrowdStrike Secures Growing AI Attack Surface with Falcon AI Detection and Response Learn more about the growing risk of data leakage from AI-powered applications in this blog post: Data Leakage: AI’s Plumbing Problem Check out these Cybersecurity 101 articles about AI: The Role of AI in Cybersecurity, Generative AI (GenAI) in Cybersecurity Read more about GDPR in these blogs on previous Data Protection Days: Data Protection Day 2025: The Evolving Role of AI in Data Protection, Data Protection Day 2024: As Technology and Threats Evolve, Data Protection Is Paramount, Data Protection Day 2023: Misaligned Policy Priorities Complicate Data Protection Compliance, Data Protection Day 2022: To Protect Privacy, Remember Security, Data Protection Day 2021: Harnessing the Power of Big Data Protection Keep up-to-date with cybersecurity policy developments in the CrowdStrike Public Policy Resource Center. Learn more about CrowdStrike’s compliance validations and certifications in the CrowdStrike Trust Center.
crowdstrike.comJan 28, 2026source
CrowdStrike 2025 Threat Hunting Report: AI Becomes a Weapon and a Target
Today’s enterprising adversaries are weaponizing AI to scale operations, accelerate attacks, and target the autonomous AI agents quickly transforming modern businesses. The CrowdStrike 2025 Threat Hunting Report details this new chapter in the threat landscape. This year’s report, based on frontline intelligence from CrowdStrike’s elite threat hunters and intelligence analysts, examines how threat actors are using AI to do more with less. They’re targeting software used to build AI agents and weaponizing AI at scale, using it to gain access, steal credentials, and deploy malware. eCrime and hacktivist actors abuse AI to automate tasks that once required advanced skill, including malware development and technical problem solving. Organizations that understand adversaries’ evolving activity are better equipped to stop them. The CrowdStrike 2025 Threat Hunting Report contains the critical insights they need. AI Weaponization Accelerates AI-powered adversary tradecraft is transforming traditional insider threats into scalable and persistent operations. CrowdStrike observed DPRK-nexus adversary FAMOUS CHOLLIMA infiltrated over 320 companies in the last 12 months — a 220% year-over-year increase — by using generative AI (GenAI) at every stage of the hiring and employment process. FAMOUS CHOLLIMA IT workers use GenAI to create attractive resumes for companies, reportedly use real-time deepfake technology to mask their true identities in video interviews, and use AI code tools to do their jobs. Other adversaries, such as EMBER BEAR and CHARMING KITTEN, use GenAI to amplify pro-Russia narratives and deploy LLM-crafted phishing lures to target U.S. and EU entities. Threat actors are using AI to gain unauthenticated access, establish persistence, harvest credentials, and deploy malware and ransomware. As organizations adopt more AI tools and technologies, adversaries are more likely to target them. CrowdStrike has observed multiple threat actors exploiting vulnerabilities in AI software and using it to gain initial access, underscoring the potential for AI to further expand and reshape the enterprise attack surface. Lower-skilled adversaries are abusing AI to automate tasks that once required advanced expertise, including script generation, technical problem solving, and malware development. Malware families Funklocker and SparkCat demonstrate the emergence of GenAI-built malware. Cross-Domain Threats Fuel Adversaries’ Success Cross-domain attacks are the norm. Adversaries are increasingly adept at bypassing traditional security defenses to move across endpoint, identity, cloud, and unmanaged systems. SCATTERED SPIDER, an adversary known for its cross-domain proficiency, resurfaced in 2025 with faster and more aggressive tradecraft. They use vishing and help desk impersonation to reset credentials, bypass multifactor authentication (MFA), and move laterally across SaaS and cloud environments. In one case, they moved from initial access to encryption by deploying ransomware in under 24 hours. Identity is key to cross-domain attacks. When SCATTERED SPIDER impersonates legitimate employees in help desk engagements, they accurately provide employee IDs and answer verification questions. SCATTERED SPIDER and other adversaries have proven their ability to acquire personally identifiable information to pass help desk verification, which can enable them to authenticate to a system. After account takeover, SCATTERED SPIDER operators can often be seen using these accounts to quickly pivot to integrated SaaS applications, including data warehousing, document management, and identity and access management platforms. These serve as a foothold for persistence, lateral movement, and data exfiltration. The cloud continues to be a primary target: Cloud intrusions increased 136% in the first half of 2025 compared to all of 2024. CrowdStrike OverWatch observed a 40% year-over-year increase in intrusions by suspected cloud-conscious China-nexus actors, with adversaries GENESIS PANDA and MURKY PANDA evading detection through cloud misconfigurations and trusted access. GLACIAL PANDA, another China-nexus adversary, embedded deep in telecom networks and helped drive a 130% rise in nation-state activity in the telecom sector through long-term, espionage-driven operations. We now track more than 265 named adversaries and more than 150 activity clusters. The CrowdStrike 2025 Threat Hunting Report sheds light on some of these prolific threat actors and the activity we have observed this year. Below are more trends and findings we explore in its pages: 81% of interactive (hands-on-keyboard) intrusions were malware-free. Interactive intrusions increased 27% year-over-year, underscoring how adversaries are innovating their operations to bypass legacy detection methods. eCrime activity represented 73% of total interactive intrusions. Voice phishing (vishing) is on track to double last year’s volume by the end of 2025. The government sector was affected by a 71% year-over-year increase in overall interactive intrusions and a 185% year-over-year increase in targeted intrusion activity. The CrowdStrike 2025 Threat Hunting Report showcases our Counter Adversary Operations team’s relentless pursuit to disrupt the adversary. To learn more, download the full report and register for the CrowdCast: Inside the CrowdStrike 2025 Threat Hunting Report. Additional Resources Learn how CrowdStrike’s threat intelligence and hunting solutions are transforming security operations to better protect your business. Tune into the Adversary Universe podcast, where CrowdStrike experts discuss today’s threat actors — who they are, what they’re after, and how you can defend against them.
crowdstrike.comAug 4, 2025source
Inside Mondel?z’s Identity Security Strategy with CrowdStrike
Mondelēz International is one of the world’s largest snack companies, with brands like Oreo, Ritz, and Cadbury sold in more than 150 countries. But behind the scenes, it’s also become a model for modern cybersecurity — replacing fragmented tools and reactive workflows with a unified, AI-native defense strategy. Since deploying the CrowdStrike Falcon® cybersecurity platform, Mondelēz has achieved measurable improvements in detection and response. The security team reports sub-15-minute mean time to detect and a two-hour mean time to mitigate. More importantly, it’s shifted from disorder to control — eliminating operational blind spots, automating key processes, and enabling faster decisions across the board. At the heart of that shift is a recognition that identity is the modern attack surface, and protecting it requires more than traditional security tools can offer. Closing Identity Gaps in a Hybrid World Like many global enterprises, Mondelēz operates in a hybrid identity environment with both on-premises Active Directory and cloud-based identity providers. That complexity can be a goldmine for adversaries: Every stale account, overprovisioned user, or weak authentication pathway is a potential entry point. “Whether it’s brute force attempts, lateral movement, or insider threats, identity is often the first and last step in the attack chain,” said Emmett Koen, Senior Director of Cybersecurity Operations and North America Regional CISO at Mondelēz. To close those gaps, Mondelēz deployed CrowdStrike Falcon® Identity Protection, a module of the Falcon platform that delivers real-time visibility into identity-based threats, continuous monitoring of user behavior, and proactive enforcement across both cloud and on-premises infrastructure. From Visibility to Action With Falcon Identity Protection, Mondelēz gained improved visibility into accounts, privileges, group memberships, and risky behaviors across its entire identity ecosystem. Instead of relying on periodic audits or siloed tools, the team now has a real-time view of who is accessing what — and whether that activity poses a threat. The platform continuously monitors for signs of credential abuse and identity-based attack techniques, such as: Password spraying Kerberoasting Suspicious privilege escalation Lateral movement via RDP or VPN It also integrates with Falcon telemetry from endpoints and other sources to enrich detections and accelerate investigations. “The identity module has delivered huge value,” said Koen. “It’s helped us proactively identify gaps and misconfigurations before they became security events.” Enforcing MFA and Blocking Risky Access One standout success came when Mondelēz used Falcon Identity Protection to enforce multifactor authentication (MFA) for RDP sessions — a frequent target for attackers using stolen or brute-forced credentials. By dynamically blocking access and enforcing conditional policies, the team was able to lock down a key exposure point without disrupting business operations. This kind of real-time enforcement is built into the solution. Analysts can stop active identity-based threats with the same agility and confidence they bring to endpoint protection. “CrowdStrike doesn’t just alert us to risk,” said Koen. “It gives us the tools to shut it down immediately.” Hardening Posture and Reducing Risk In addition to threat detection and response, Falcon Identity Protection helps Mondelēz strengthen its overall identity hygiene. The tool continuously scans for misconfigured accounts, excessive privileges, and risky group memberships. It then provides prioritized remediation guidance. This shift from reactive to proactive has allowed the team to reduce attack surface and enforce zero trust principles without needing to deploy additional agents or bolt-on products. In fact, by reducing time spent mitigating attack paths to privileged accounts, Mondelēz estimates it’s saving $379,000 USD annually. CrowdStrike’s standardized identity risk scoring and reporting also support compliance and audit readiness, giving stakeholders clear insight into user activity and organizational exposure. Stronger Security Without Added Complexity Because Falcon Identity Protection is part of the unified Falcon platform, Mondelēz didn’t have to integrate or manage a separate identity solution. The same single agent and console that powers endpoint, cloud, and data security, along with other CrowdStrike protections that Mondelēz already relies on, also provides its identity protection — simplifying operations and accelerating time to value. “Instead of stitching together tools, we’re making decisions based on real-time, correlated data,” said Koen. “That’s a game changer for our team.” With Falcon Identity Protection, the company has the visibility, automation, and control to defend against modern identity-based attacks. As hybrid work and cloud adoption continue to accelerate, Mondelēz’s approach shows what’s possible when identity protection is treated not as a bolt-on but as a core pillar of enterprise security. Additional Resources Read and watch all CrowdStrike customer stories. Learn how CrowdStrike stops identity attacks in real time. Download the Complete Guide to Building an Identity Protection Strategy. Join the fastest-growing cybersecurity conference on the planet at Fal.Con 2025, Sept. 15-18 in Las Vegas.
crowdstrike.comJul 30, 2025source
CrowdStrike Named a Leader and Fast Mover in GigaOm ISPM Radar
CrowdStrike has been named a Leader and Fast Mover in the 2025 GigaOm Identity Security Posture Management (ISPM) Radar Report, recognizing the power of CrowdStrike Falcon® Identity Protection to detect and stop today’s identity-based threats. Identity compromise is among the most common, easily conducted, and potentially damaging vectors for cyberattacks as adversaries target on-premises, cloud, and hybrid identities. In 2024, 79% of detections CrowdStrike observed were malware-free, indicating adversaries are using hands-on-keyboard techniques to blend in with legitimate user activity and impede detection. Access broker advertisements, which often sell valid credentials, were up 50% year-over-year, and valid account abuse accounted for 35% of cloud detections. ISPM is critical to detect and stop these evolving threats. Unlike traditional identity and access management (IAM) tools that focus on access provisioning and authentication, ISPM solutions assess the appropriateness, risk, and alignment of identity access after it’s granted. The GigaOm ISPM Radar Report evaluates top ISPM solutions based on their ability to continuously assess and improve the security posture of both human and non-human identities. Falcon Identity Protection scored highest in Emerging Features, including NHI Security Posture, Generative AI for Identity Insights, and AI-Driven Behavioral Analytics. These high scores can be attributed to its ability to assess risk, automate remediation, and deeply integrate within ecosystems to unify visibility across human and non-human identities. This recognition builds on CrowdStrike’s earlier placement as a Leader and Outperformer in the 2025 GigaOm Radar for Identity Threat Detection and Response (ITDR). Together, these accolades validate CrowdStrike’s comprehensive identity security approach, which combines proactive posture management (ISPM) with real-time threat detection and response to stop identity-based attacks across the entire identity security lifecycle. Let’s take a closer look at what makes Falcon Identity Protection stand out. A Unified Platform to Stop Modern Identity Attacks Falcon Identity Protection delivers ISPM capabilities across on-premises, cloud, and SaaS environments, the last with the help of CrowdStrike Falcon® Shield SaaS security. It identifies and protects against misconfigurations, use of compromised credentials, and overprivileged accounts for both human and non-human identities. With Falcon Identity Protection, organizations can discover potential identity attack paths across endpoint, identity, and cloud. Falcon Identity Protection is fueled by the power of the unified CrowdStrike Falcon® cybersecurity platform. Its identity signals are correlated with endpoint, cloud, and threat intelligence data across the platform to discover and prioritize the most urgent threats. “The platform prioritizes risks by combining telemetry from endpoint security, cloud security, data protection tools, adversary tradecraft intelligence, and dark web credential monitoring to deliver rich, contextual insights,” GigaOm states in its report. As the most complete Platform Play in the GigaOm ISPM Radar, the Falcon platform enables deep ecosystem integration to power a comprehensive security posture. Falcon Identity Protection natively integrates across the Falcon platform and hundreds of third-party security tools, including on-premises and cloud-based identity providers and multifactor authentication (MFA) solutions. This provides end-to-end visibility and seamless workflows across the identity and security stack. When risks or threats are detected, Falcon Identity Protection automates response. Policy-based remediation stops threats by blocking access, enforcing multifactor identity verification, and more without manual intervention. With CrowdStrike Falcon® Fusion SOAR, our no-code SOAR engine, customers can use over 150 automated actions to respond to identity incidents. “Prevention and mitigation of identity risks is done through policy enforcement and automated remediation utilizing the no-code SOAR engine, Falcon Fusion,” the report states. CrowdStrike Leads the Industry in Identity Protection Falcon Identity Protection is built for modern enterprises that demand comprehensive, unified, and automated identity security. With adversaries increasingly abusing valid credentials and evading detection, organizations need more than basic IAM tools. They need real-time, risk-based identity protection that works across their entire environment. Being named the most complete Platform Play — and a Leader and Fast Mover — by GigaOm validates CrowdStrike’s commitment to delivering identity security that stops breaches. From unified visibility and contextual risk prioritization to automated remediation and deep ecosystem integrations, Falcon Identity Protection empowers organizations to proactively stop identity-based attacks and secure access at scale. Download the 2025 GigaOm ISPM Radar Report to learn more about how Falcon Identity Protection is redefining identity security for the modern enterprise.
crowdstrike.comJul 23, 2025source
CrowdStrike Falcon Prevents Supply Chain Attack Involving Compromised NPM Packages
Recently, five popular NPM (Node Package Manager) packages were compromised and modified to deliver a malicious DLL, dubbed “Scavenger”. The malware pushed via these compromised NPM packages executes in two stages: an initial first-stage loader, followed by a second-stage infostealer. NPM is the package manager for the Node.js JavaScript platform, which allows developers to share and manage JavaScript libraries and tools. By compromising these packages, attackers are able to perform supply chain attacks that have widespread impact and can be challenging to identify. Here, we outline this attack and explain how the CrowdStrike Falcon® platform detects and successfully prevents the malicious NPM packages and Scavenger malware observed within this campaign. Supply Chain Attack Overview On July 18, 2025, an unknown adversary was observed modifying the contents of multiple NPM packages to further actions on objectives. This access was made possible following a successful credential phishing campaign targeting an NPM package maintainer that leveraged a spoofed login page and typosquatted domain of the NPM website. In all, five NPM packages maintained by the compromised account were modified and malicious versions of those packages were published the same day. The most popular package, eslint-config-prettier, has over 30 million downloads per week, and its compromise was assigned CVE-2025-54313 with a CVSS severity rating of High. The following specific packages and their associated versions were published as part of this campaign: eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) eslint-plugin-prettier (4.2.2, 4.2.3) synckit (0.11.9) @pkgr/core (0.2.8) napi-postinstall (0.3.1) The altered packages included the install script install.js and the Scavenger DLL node-gyp.dll. The script is executed upon installation of the packages and spawns rundll32.exe to load the DLL node-gyp.dll. The Scavenger DLL reads and exfiltrates the contents of the user’s NPM configuration file .npmrc, which often contains NPM authentication and access tokens. Additionally, the Scavenger DLL writes a second-stage infostealer payload to disk, which ultimately targets the victims' browser data, including visited URLs and cached content. The affected packages have been deprecated on the NPM repository, and clean versions have been published by the maintainer. Falcon Platform Prevents Scavenger Malware CrowdStrike employs a layered approach for malware detection using machine learning and indicators of attack (IOAs). The Falcon platform prevented this attack in its initial stage by detecting and quarantining the Scavenger DLL. The rundll32.exe process spawned by install.js was also prevented by behavior-based detections (IOAs). Customers should ensure their prevention policies are properly configured with the Suspicious Processes toggle enabled.
crowdstrike.comJul 23, 2025source
Preventing Container Escape Attempts with Falcon Cloud Security's Enhanced Runtime Capabilities
Container escape represents one of the most significant security threats in modern cloud computing environments. This allows attackers to break free from container isolation mechanisms, potentially leading to complete compromise of host systems and broader cloud infrastructure. The widespread adoption of container technologies has fundamentally reshaped the modern application infrastructure landscape. Organizations have rapidly transitioned from traditional monolithic applications to microservices-based architectures deployed in containerized environments. Container orchestration platforms like Kubernetes and Docker Swarm now manage vast clusters of containers across hybrid and multi-cloud environments, creating an expanded attack surface that spans from the container runtime to the underlying infrastructure. Even minor misconfigurations or vulnerabilities can create significant risks. Consider a common scenario: an Apache web server running in a container with necessary internet exposure for business operations. In this setup, attackers can potentially exploit vulnerabilities to gain initial container access with low-level privileges. Once inside, they may leverage container escape techniques to break free from the container's isolation, compromise the host system, and escalate their privileges. In this blog post, we examine common techniques attackers use to exploit container misconfigurations, with emphasis on escape vectors and their role in breaches. Container Isolation Fundamentals At the heart of container isolation are Linux namespaces, which partition kernel resources to provide isolated views for containerized processes. Network namespaces create separate networking stacks, mount namespaces isolate filesystem views, and PID namespaces ensure process isolation. User namespaces add an additional security layer by mapping container user IDs to different host IDs, while IPC namespaces prevent unwanted inter-process communication. Control groups (cgroups) and Linux capabilities work together to enhance container security. Cgroups manage and limit resource usage, preventing containers from consuming excessive system resources, while Linux capabilities break down root privileges into granular permissions. Additional security layers including Seccomp filters and mandatory access control systems (AppArmor/SELinux) create a defense-in-depth approach that maintains container isolation while allowing necessary functionality.
crowdstrike.comJul 22, 2025source
CrowdStrike Named a Strong Performer in Forrester Wave for Unified Vulnerability Management
CrowdStrike is proud to be named a Strong Performer in The Forrester Wave™: Unified Vulnerability Management Solutions, Q3 2025. We believe this recognition underscores the strength of CrowdStrike’s vision, the pace of our innovation, and the rapid adoption of CrowdStrike Falcon® Exposure Management by customers transforming their vulnerability management, just 24 months after its launch. The need for unified, intelligent exposure management is critical. In 2024, 52% of exploited vulnerabilities observed by CrowdStrike were to gain initial access, according to the CrowdStrike 2025 Global Threat Report. Adversaries are targeting internet-exposed systems with unauthenticated remote code execution vulnerabilities and moving quickly and quietly to access high-value data, often faster than defenders can respond. Many traditional vulnerability management approaches are falling short. Their static CVSS scores, scheduled scans, and siloed dashboards make it increasingly difficult for defenders to keep pace. Security teams are overwhelmed with alerts but lack insight into which vulnerabilities are actively exploited or which assets are at highest risk. They have little to no indication of how a threat actor might move laterally through their environment. This isn’t a volume problem — it’s a risk prioritization problem. As The Forrester Wave™ explains, Falcon Exposure Management can provide the essential capabilities they need.
crowdstrike.comJul 21, 2025source
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation
Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation attempts by an unknown adversary. Two distinct zero-day vulnerabilities were made publicly available: a critical remote code execution vulnerability (CVE-2025-53770) and a server spoofing vulnerability (CVE-2025-53771). The chaining of these vulnerabilities to exploit a vulnerable SharePoint server is being referred to as “ToolShell.” Since the start of this exploitation, CrowdStrike has observed and successfully blocked hundreds of exploitation attempts across 160+ customer environments, demonstrating both the scale of this threat and the effectiveness of our protection capabilities. The CrowdStrike Falcon® platform detects and protects against exploitation of the Microsoft SharePoint zero-days, blocking known behaviors associated with these vulnerabilities. This blog post provides context surrounding this emerging threat, as well as guidance for customers on how they can use the Falcon platform to protect their environments. Customers of CrowdStrike Falcon® Adversary Intelligence Premium can find more detailed analysis in Intel report CSA-250846. Observed Exploitation of SharePoint Vulnerability CrowdStrike has observed widespread exploitation of CVE-2025-53770 involving a deserialisation attack leading to attempts to write a malicious .aspx webshell on the host. That file, spinstall0.aspx, is used to steal IIS Machine Keys, which can later be used for other post-exploitation attacks. This attack begins with a specially crafted POST request to an accessible SharePoint server. The POST request payload will attempt to write the .aspx file via PowerShell. That malicious PowerShell command, spawned from the SharePoint IIS process, is blocked by the Falcon platform.
crowdstrike.comJul 21, 2025source
CrowdStrike Named a Leader in the 2025 GigaOm SIEM Radar Report
CrowdStrike is proud to be named a Leader and Fast Mover in the 2025 GigaOm Radar for Security Information and Event Management (SIEM). This recognition positions CrowdStrike Falcon® Next-Gen SIEM as the core of the AI-native SOC and future of security operations. CrowdStrike earned perfect 5/5 scores in key areas including Attack Surface Coverage, LLM-Based Co-Pilot and Agents, Automation, and Threat Research Units. GigaOm recognized CrowdStrike as the most innovative and complete Platform Play, and the only vendor to receive the highest scores across both Key Features and Business Criteria. In a complex threat landscape where adversaries live in the gaps between tools, SOCs face overwhelming data volumes, rising costs, and alert fatigue. Security teams need to see and stop adversaries in real time, but legacy SIEM tools can’t keep up. While SIEMs bring valuable data and context together to detect, investigate, and respond to attacks, they have failed to live up to their promise as the “single pane of glass” for the SOC. GigaOm acknowledges the stagnation of a SIEM market crowded with legacy vendors: “The security information and event management (SIEM) solution space is mature and competitive. Most vendors have had well over a decade to refine their products, and the differentiation among basic SIEM functions is fairly minor.” CrowdStrike is redefining the SIEM category with rapid innovation, execution and AI-powered threat hunting. CrowdStrike enables teams to consolidate data from endpoint detection and response (EDR), threat intelligence, security information and event management (SIEM), and security orchestration, automation, and response (SOAR) tools to deliver unified visibility and AI-powered protection across the full enterprise attack surface. Read how Falcon Next-Gen SIEM protects enterprises from threats like VMware vCenter Attacks. Falcon Next-Gen SIEM Leads the Pack The 2025 GigaOm Radar for SIEM positions CrowdStrike as a Leader and Fast Mover, emphasizing the rapid pace of our innovation and the strength of our unified platform.
crowdstrike.comJul 16, 2025source