Home / Companies / Crowdstrike / Blog / January 2022

January 2022 Summaries

18 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
The text provides a comprehensive overview of CrowdStrike's recent activities and achievements in the cybersecurity domain, emphasizing its leadership in managed detection and response services. It highlights the company's role in addressing critical vulnerabilities, as seen in the September 2025 Patch Tuesday, and its recognition as a leader in several industry reports like The Forrester Wave and IDC MarketScape. The document discusses advancements in machine learning for cybersecurity, particularly through the EMBER2024 initiative, and illustrates how CrowdStrike's Falcon platform enhances security in cloud environments, especially against threats like Kubernetes container escapes. Additionally, the text underscores CrowdStrike's strategic partnerships, innovative AI security services, and its proactive measures in threat detection and response to maintain robust cybersecurity defenses across various sectors.
Jan 31, 2022 2,433 words in the original blog post.
CrowdStrike is actively enhancing its cybersecurity offerings with a focus on protecting against sophisticated threats through its Falcon platform, which provides unified visibility, threat detection, and continuous monitoring. The platform is equipped with machine learning and behavior-based detections to protect against threats like data-wiping malware, demonstrated in its response to the WhisperGate attack targeting Ukraine. CrowdStrike's efforts include advancements in AI security, identity protection, and endpoint security, while also addressing data protection challenges and vulnerability management. The company has been recognized as a leader in various cybersecurity reports and continues to innovate in areas such as cloud security, next-generation security information and event management (SIEM), and managed detection and response (MDR) services. Additionally, CrowdStrike is expanding its capabilities by acquiring companies like Pangea and Onum to bolster enterprise AI security and data analysis, aiming to secure AI development and usage across enterprises.
Jan 31, 2022 1,840 words in the original blog post.
CrowdStrike's intelligence analysis highlights the ongoing cyber operations against Ukraine, primarily attributed to the Russian group VOODOO BEAR, which is believed to be linked to Russia's GRU. These operations have evolved from targeted wiper malware attacks to sophisticated pseudo-ransomware campaigns, leveraging techniques like supply chain compromises and strategic web compromises. They aim to disrupt Ukrainian sectors, influence political processes, and erode public trust in state institutions, often resulting in collateral damage beyond Ukraine's borders. The campaigns frequently employ information operations to amplify their impact, including publicizing data breaches and utilizing hacktivist personas to obscure true intentions. Although these operations align with broader Russian strategic objectives, they remain distinct from overt military actions. Future threats are expected to continue this pattern, using destructive attacks masked as ransomware, with potential for unintended international repercussions. CrowdStrike's assessments are provided with varying degrees of confidence, indicating ongoing uncertainty and the need for further intelligence gathering.
Jan 28, 2022 3,180 words in the original blog post.
In a detailed exploration of cybersecurity threats targeting cloud environments, CrowdStrike highlights the persistent challenge posed by cryptomining groups exploiting exposed Docker APIs for cryptocurrency mining, particularly Monero. This issue is exacerbated by the widespread availability of techniques and procedures for exploiting Docker and Kubernetes containers, leading to numerous attack attempts by groups like WatchDog. The blog underscores the importance of protective measures such as authentication, zero-trust policies, and image scanning in CI/CD pipelines to mitigate these risks. Additionally, CrowdStrike's advanced solutions, including the Falcon platform and Threat Graph, provide pre-deployment scanning and runtime protection to detect and neutralize malicious activities, enhancing cloud security posture management. The narrative emphasizes the competitive nature of cryptomining operations and the continuous evolution of tactics by experienced groups to maintain profitability.
Jan 27, 2022 3,163 words in the original blog post.
The StellarParticle campaign, linked to the COZY BEAR adversary group, showcases the group's sophisticated use of novel tactics and techniques to infiltrate multiple organizations' systems, leveraging access for espionage and financial gain. CrowdStrike's investigation revealed the group's methods, including credential hopping, browser cookie theft to bypass multifactor authentication, and the use of malware families like TrailBlazer and a Linux variant of GoldMax to maintain persistence. The campaign also exploited Microsoft O365 environments through service principal manipulations and application impersonation, targeting sensitive information repositories and using advanced knowledge of victims' infrastructures. These actions highlight the threat actors' capacity to remain undetected for extended periods, showcasing a high level of operational security and a comprehensive understanding of both Windows and Linux systems, as well as cloud environments.
Jan 27, 2022 7,404 words in the original blog post.
CrowdStrike's recent initiatives and achievements highlight the company's commitment to advancing cybersecurity across various domains, including AI, cloud, next-generation security information and event management (SIEM), and identity protection. The company's focus is on integrating innovative technologies to provide robust data protection solutions, aligning with global privacy and security standards such as GDPR, CCPA, and Japan's APPI. CrowdStrike emphasizes the importance of a holistic approach to data protection, combining security and privacy by design, and addresses the evolving risks posed by cyber adversaries in the context of increased remote work and digital transformation. With a strong presence in endpoint security, threat intelligence, and exposure management, CrowdStrike is recognized as a leader in several industry reports and market evaluations, underscoring its influence in shaping cybersecurity best practices and policies.
Jan 27, 2022 1,877 words in the original blog post.
The text is an extensive overview of various cybersecurity initiatives, developments, and strategies by CrowdStrike as of 2025. It highlights the company's efforts in advancing AI security, identity protection, and cloud security, with specific emphasis on tools like Falcon Cloud Security and Threat AI, which are designed to enhance threat intelligence and data protection. The text also discusses methodologies for detecting and mitigating malware threats, particularly focusing on techniques like memory scanning that can help in identifying malicious activities. Additionally, there's a focus on practical use cases for memory extraction in Linux shells, revealing how these techniques can be applied for both attack and defense purposes in cybersecurity. Overall, CrowdStrike's consistent innovations and strategic acquisitions aim to strengthen its position as a leader in the cybersecurity industry, providing comprehensive protection against evolving digital threats.
Jan 27, 2022 3,422 words in the original blog post.
CrowdStrike is leveraging advanced technologies such as BERT embeddings to enhance its cybersecurity capabilities, particularly in detecting anomalous command-line executions. By training a BERT model with a vast amount of unlabeled telemetry data, CrowdStrike improves feature extraction for command lines, which are then analyzed using various anomaly detection models like PCA, Isolation Forest, and autoencoders. The ensemble approach of combining multiple strategies offers robust anomaly detection, which strengthens the CrowdStrike Falcon® platform by identifying outliers, including potential misconfigurations and suspicious activities. This innovative use of machine learning techniques not only aids in enhancing security measures but also exemplifies CrowdStrike's commitment to advancing cybersecurity solutions in an unsupervised and efficient manner.
Jan 26, 2022 2,671 words in the original blog post.
CrowdStrike's blog highlights its strategic advancements in cybersecurity, emphasizing the integration of AI, cloud security, and identity protection to combat evolving threats such as ransomware and supply chain attacks. The company underscores the importance of managed cybersecurity services, like Falcon OverWatch and Falcon Complete, which combine human expertise with automated technology to detect and disrupt sophisticated threats rapidly. CrowdStrike's proactive threat hunting and response capabilities leverage cloud-scale telemetry and global threat intelligence to provide 24/7 protection, addressing the skill gaps faced by organizations and ensuring immediate action against potential intrusions. The blog also discusses recent innovations, including the introduction of Threat AI, advancements in next-gen identity security, and collaborations with AI leaders, portraying CrowdStrike as a leader in the cybersecurity landscape for its comprehensive, scalable security solutions.
Jan 21, 2022 2,571 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple cybersecurity areas, including the 2025 IDC MarketScape for Worldwide Incident Response Services and Exposure Management, indicating its strong position in the industry. The company is actively expanding its capabilities through strategic acquisitions, such as Onum, to enhance data-driven security operations centers (SOC). CrowdStrike's innovative use of artificial intelligence and machine learning is evident in its new AI security services and its advanced threat detection and response systems. The company also focuses on various sectors, from cloud and application security to endpoint protection and threat hunting, demonstrating its comprehensive approach to cybersecurity. Furthermore, the Microsoft Protection Log (MPLog) plays a crucial role in forensic investigations by providing valuable data on process execution and file access, which is essential for understanding and mitigating threats, such as ransomware incidents involving tools like Rclone.
Jan 20, 2022 1,954 words in the original blog post.
The text provides an overview of recent updates and initiatives by CrowdStrike, a cybersecurity company, focusing on its advancements in AI security, identity protection, and cloud security. It highlights the company's launch of Threat AI, a pioneering threat intelligence system, and its efforts to prevent data leaks associated with generative AI technologies through unified data protection strategies. Additionally, CrowdStrike's recognition as a leader in managed detection and response services, identity security, and exposure management reflects its prominent position in the industry. The narrative also touches on the WhisperGate malware incident, illustrating CrowdStrike's ongoing intelligence and threat analysis work, and emphasizes its commitment to enhancing cybersecurity measures across various sectors, including healthcare and small businesses.
Jan 19, 2022 1,787 words in the original blog post.
CrowdStrike's blog post emphasizes the importance of addressing cybersecurity vulnerabilities through a comprehensive patch management strategy, highlighting updates for 97 vulnerabilities as part of January 2022's Patch Tuesday. The post stresses the criticality of prioritizing patches related to remote code execution and privilege escalation attacks, particularly for Microsoft products like Windows and Microsoft Exchange Server, which are often targeted by attackers. The blog also underscores the necessity of a layered security approach, utilizing tools like Falcon Spotlight to enhance vulnerability management and ensure rapid detection and response to potential threats. Moreover, CrowdStrike's insights into the Common Vulnerability Scoring System (CVSS) provide guidance for organizations to assess the severity of vulnerabilities effectively, aiming to minimize the risk of breaches through timely and strategic mitigation efforts.
Jan 14, 2022 2,518 words in the original blog post.
The text provides an overview of CrowdStrike's activities and achievements in cybersecurity up to September 2025, highlighting its consistent recognition as a leader in various security domains by reputable industry analysts like The Forrester Wave™ and IDC MarketScape. It underscores CrowdStrike's strategic advancements, including the development of AI-powered security solutions to tackle the evolving cyber threat landscape, while also addressing the significant increase in Linux-targeted malware in 2021. Key initiatives such as the training of machine learning models against evasive malware and the emphasis on secure AI to defend the expanding digital attack surface are also discussed. The company's efforts in enhancing protection for Linux systems, particularly against prominent malware families like XorDDoS, Mirai, and Mozi, are emphasized, showcasing the integration of advanced technologies such as machine learning and behavior-based indicators within its Falcon platform to provide comprehensive security solutions across various environments.
Jan 13, 2022 2,063 words in the original blog post.
CrowdStrike is actively enhancing its cybersecurity solutions with a focus on Zero Trust security, managed detection and response (MDR), and advanced threat detection technologies. The company is recognized as a leader in various industry reports, including The Forrester Wave for Managed Detection and Response Services in Europe and the IDC MarketScape for CNAPP. CrowdStrike is expanding its Zero Trust partner ecosystem, integrating with companies like Airgap, Appgate, and CyberArk to improve endpoint protection and reduce attack surfaces. Their Falcon platform, which utilizes AI-powered threat detection, is designed to provide comprehensive security across hybrid enterprises, safeguarding against diverse modern threats. The company's innovations in AI, cloud security, and endpoint protection aim to bolster defenses against sophisticated attacks, ensuring organizations remain resilient in a rapidly evolving cybersecurity landscape.
Jan 13, 2022 2,078 words in the original blog post.
CrowdStrike has developed the Incident Response Tracker, a tool designed to streamline digital forensics and incident response (DFIR) by providing a structured approach to documenting and managing incident details. This tracker includes various tabs that allow teams to consolidate and communicate critical information, such as incident timelines, host and network indicators, and relevant contact information, thereby enhancing the efficiency and accuracy of incident investigations. Emphasizing the importance of maintaining "tracker hygiene," CrowdStrike highlights the tool's ability to improve collaboration and investigative outcomes when used consistently and correctly. The company has made the tracker template publicly available to assist the DFIR community in improving their response processes, underscoring its commitment to advancing cybersecurity practices.
Jan 11, 2022 2,707 words in the original blog post.
TellYouThePass ransomware, initially discovered in 2019, has resurfaced with new samples written in Golang, highlighting its evolution in targeting both Windows and Linux systems. This ransomware is associated with the Log4Shell vulnerability and uses RSA-1024 and AES-256 encryption to lock files, demanding a ransom in bitcoin for decryption. The malware is noted for its cross-platform capabilities due to Golang's flexibility, which allows developers to compile the same codebase for multiple operating systems. It specifically targets popular media and file extensions while excluding certain directories from encryption. CrowdStrike's Falcon platform leverages cloud-based and on-sensor machine learning to detect and protect against this ransomware, showcasing its ability to handle sophisticated threats by using behavioral detection and indicators of attack (IOAs). This protection extends to various environments, ensuring comprehensive security against the evolving threat landscape.
Jan 11, 2022 2,977 words in the original blog post.
CrowdStrike has introduced several advancements and innovations in cybersecurity, focusing on identity security, data protection, vulnerability management, and threat intelligence. Notably, it has enhanced its Falcon platform with next-gen identity security features that unify protection across all identities and domains, and introduced a system to stop GenAI data leaks through unified data protection measures. Additionally, CrowdStrike has launched a risk-based patching system for vulnerability management and announced Threat AI, the first agentic threat intelligence system. The company has been recognized as a leader in various cybersecurity sectors, including exposure management and managed detection and response services, and continues to collaborate with AI leaders to secure enterprise AI use. Furthermore, CrowdStrike's Falcon Identity Protection offers proactive measures to detect and prevent exploitation of Microsoft Active Directory vulnerabilities, reinforcing the importance of continuous security and Zero Trust policies.
Jan 11, 2022 1,942 words in the original blog post.
The text delves into the complexities of securing cloud environments, emphasizing the significant challenges posed by poor visibility, management issues, and misconfigurations, which lead to costly data breaches. It highlights the necessity for a unified, adversary-focused security approach that leverages real-time threat intelligence and continuous visibility to detect and prevent cloud breaches effectively. CrowdStrike's strategy involves using its Security Cloud to correlate vast amounts of security data and identify adversarial tactics, thereby enhancing detection, protection, and response capabilities. The dynamic nature of cloud environments requires organizations to integrate security measures seamlessly and extend them from on-premises to the cloud, ensuring comprehensive protection against diverse attack vectors.
Jan 07, 2022 1,981 words in the original blog post.