March 2022 Summaries
23 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
In a detailed examination, CrowdStrike uncovers inconsistencies in Microsoft 365 Azure AD sign-in logs, which inaccurately show successful logins via legacy authentication protocols such as IMAP, despite being blocked at the mailbox level. This discrepancy could mislead organizations into erroneously believing that mailbox contents have been compromised, potentially leading to significant legal and regulatory implications. CrowdStrike's proof of concept illustrates that while SMTP authentication was successful, no mail synchronization occurred, highlighting the need for accurate logging. The report advises implementing conditional access policies to block these legacy protocols and enhance security monitoring through the MailItemsAccessed operation. With Microsoft planning to disable certain legacy authentication methods by October 2022, these recommendations are critical for reducing risks associated with outdated authentication protocols.
Mar 31, 2022
2,402 words in the original blog post.
CrowdStrike, a prominent cybersecurity firm, has been recognized as a leader in various industry reports, such as the Forrester Wave™ and IDC MarketScape, for its Managed Detection and Response Services and Incident Response Services, reflecting its prowess in the cybersecurity domain. The company has been actively advancing its cybersecurity measures, notably through initiatives like EMBER2024, which focuses on training machine learning models to combat evasive malware, and by enhancing cloud security with agentic AI. CrowdStrike's intelligence team has identified and tracked adversary groups like EMBER BEAR, which is linked to Russian state-sponsored cyber activities, highlighting the firm's role in identifying and mitigating cyber threats on a global scale. The company is also expanding its technology offerings, integrating AI to secure SaaS environments and collaborating with major tech firms like Microsoft to bolster cyber threat attribution, demonstrating its commitment to enhancing cybersecurity resilience across different sectors.
Mar 30, 2022
1,531 words in the original blog post.
CrowdStrike emphasizes the importance of a comprehensive and unified security strategy across cloud and endpoint environments to combat complex threats and vulnerabilities effectively. The company advocates for a single integrated platform that extends endpoint protection to cloud resources, ensuring security consistency and visibility across the entire infrastructure. This approach helps eliminate security silos, reduces operational costs, and enhances the speed and effectiveness of threat response. CrowdStrike's Falcon Cloud Security platform offers automated compliance and workload protection for containers, Kubernetes, and applications from development through runtime, seamlessly integrating with public cloud providers like AWS, Azure, and GCP. By focusing on simplicity and integration, CrowdStrike aims to provide robust security measures that cover the entire spectrum from data endpoints to cloud infrastructures, thereby optimizing security processes and reducing response times to existing threats.
Mar 29, 2022
1,583 words in the original blog post.
CrowdStrike Named a Leader in The Forrester Wave™: Cybersecurity Incident Response Services, Q1 2022
CrowdStrike has been consistently recognized as a leader in various cybersecurity domains, including incident response services, exposure management, and endpoint protection platforms, as highlighted in multiple 2025 IDC MarketScape reports. The company is making strategic moves to enhance its cybersecurity capabilities, such as acquiring Onum to transform data usage in the Agentic SOC and integrating AI technologies to defend against evolving cyber threats. CrowdStrike's Falcon platform is renowned for its ability to prevent breaches and serve as a critical component in the cyber insurance industry, emphasizing their approach to incident response through comprehensive threat visibility and real-time system recovery. The firm's collaborative exercises and partnerships with legal and IT recovery experts further enhance their capacity to manage and mitigate sophisticated cyber threats, ensuring clients are better prepared to handle potential cyberattacks and maintain operational resilience.
Mar 28, 2022
2,215 words in the original blog post.
CrowdStrike's comprehensive blog post details the company's prominent achievements and contributions in the cybersecurity domain, highlighting its recognition as a leader in multiple industry reports such as The Forrester Wave and IDC MarketScape for Managed Detection and Response Services. The blog discusses various aspects of their cybersecurity efforts, including the development of AI models to counter evasive malware, enhancements in cloud security, and innovations in endpoint protection. It also covers significant vulnerabilities found in Cisco devices during the Pwn2Own Austin 2021 contest, demonstrating their expertise in uncovering and responsibly disclosing security weaknesses. The blog emphasizes CrowdStrike's strategic approach to integrating AI and machine learning to improve threat detection and response capabilities, illustrating their role in fortifying digital infrastructures against evolving cyber threats.
Mar 24, 2022
3,717 words in the original blog post.
The text provides an overview of CrowdStrike's recent cybersecurity activities and achievements, emphasizing its proactive threat detection and response capabilities. The Falcon OverWatch team demonstrated its effectiveness by thwarting a sophisticated ransomware attack by the BlackCat/ALPHV group, which used advanced tools and techniques like Rust-based ransomware and file exfiltration tools. Despite challenges such as initial access on an unmanaged host, OverWatch's human-driven threat hunting augmented the Falcon platform's automated detection, enabling rapid response and remediation. CrowdStrike's leadership in cybersecurity is further highlighted by recognitions in industry analyst reports, new advancements in AI security services, and its role in managing vulnerabilities and patching critical zero-day vulnerabilities, demonstrating the company's comprehensive approach to cybersecurity across various domains.
Mar 23, 2022
2,714 words in the original blog post.
CrowdStrike has been actively enhancing its cybersecurity offerings, focusing on AI, cloud, identity protection, and threat intelligence to address modern security challenges. Recent developments include the introduction of Threat AI, the first agentic threat intelligence system, and advancements in next-gen identity security with three key innovations. The company has also launched Falcon Cloud Security to protect AI development and prevent data leaks in cloud environments. Additionally, CrowdStrike has been recognized in various industry reports for its leadership in managed detection and response services, cloud workload security, and endpoint protection platforms. They continue to innovate in areas such as runtime security, cloud-native application protection, and seamless integration into CI/CD pipelines, reinforcing their commitment to providing comprehensive security solutions across diverse technology landscapes.
Mar 23, 2022
1,871 words in the original blog post.
CrowdStrike is advancing cybersecurity with innovative solutions across various domains, including identity and data protection, endpoint security, and threat intelligence. Recent developments highlight the integration of AI and cloud-native technologies to enhance the security posture of organizations against sophisticated threats. The CrowdStrike Falcon® platform, a cloud-native endpoint security solution, provides comprehensive protection by leveraging real-time indicators of attack, threat intelligence, and enriched telemetry. It offers unmatched scalability and performance through a lightweight-agent architecture that supports a wide range of devices and operating systems. The platform's capabilities are designed to address the limitations of traditional antivirus solutions and provide holistic security across modern digital environments without relying on on-premises infrastructure. Additionally, CrowdStrike's recent innovations include risk-based vulnerability management, agentic threat intelligence systems, and next-gen identity security, which collectively aim to strengthen enterprise cybersecurity in an increasingly complex threat landscape.
Mar 21, 2022
1,852 words in the original blog post.
CrowdStrike's collaboration with Cloudflare enhances their Zero Trust security framework, providing comprehensive protection for distributed workforces by integrating Cloudflare's secure global network with CrowdStrike Falcon's enriched telemetry. This partnership allows organizations to implement conditional access policies based on device health and compliance checks while leveraging Cloudflare's Zero Trust Network Access (ZTNA) and Secure Web Gateway (SWG) for secure application and network access. The integration aims to mitigate risks from compromised devices, prevent lateral movement, and stop breaches by combining insights from both platforms through the CrowdXDR Alliance. Additionally, CrowdStrike's involvement in the Critical Infrastructure Defense Project alongside Cloudflare and Ping Identity seeks to bolster U.S. cybersecurity for critical infrastructure, offering free cyber protections to hospitals, and water and power utilities.
Mar 17, 2022
1,952 words in the original blog post.
CrowdStrike's Cloud Threat Research team discovered a critical vulnerability, dubbed "cr8escape" and tracked as CVE-2022-0811, in the CRI-O container runtime engine used by Kubernetes. This vulnerability allows an attacker to escape from a Kubernetes container, gain root access to the host, and execute arbitrary code across the cluster, posing a significant threat due to the widespread use of CRI-O. CrowdStrike disclosed this vulnerability to Kubernetes, which issued a patch, and recommends that all CRI-O users update immediately to mitigate the risk of exploitation. The detection and prevention of attempted exploits are facilitated by CrowdStrike’s Falcon sensor for Linux and the Falcon Cloud Security module. The vulnerability underscores the importance of maintaining up-to-date security measures in cloud environments to prevent potential breaches and data compromises.
Mar 15, 2022
2,900 words in the original blog post.
The provided text is a comprehensive overview of CrowdStrike's recent achievements, initiatives, and strategic developments within the cybersecurity sector. It highlights CrowdStrike's repeated recognition as a leader in several prominent industry reports such as The Forrester Wave™, IDC MarketScape, and GigaOm Radar, particularly in areas like managed detection and response services and incident response services. The text also discusses advancements in AI and machine learning, specifically in training models against evasive malware, as well as the company's efforts to enhance its partner ecosystem, emphasizing the importance of collaboration and communication with partners to drive growth and profitability. Notable initiatives include the launch of new AI security services, advancements in cloud security, and the expansion of their partner program, Elevate 2.0, which seeks to provide high-margin opportunities through services like incident response and managed detection and response. Additionally, CrowdStrike's strategic acquisitions and integration with technologies such as ChatGPT are projected to bolster its capabilities, while its continuous investment in partner and MSSP support underscores its commitment to delivering comprehensive cybersecurity solutions globally.
Mar 15, 2022
2,252 words in the original blog post.
CrowdStrike's Falcon OverWatch team has effectively identified and mitigated a widespread intrusion campaign orchestrated by NIGHT SPIDER, which used bundled .msi installers to deliver malicious payloads, such as the Zloader trojan, alongside legitimate software. By leveraging advanced threat hunting techniques focused on behavior, prevalence, and timing, OverWatch detected these campaigns, which sought to evade traditional detection methods through the use of low-prevalence files and native utilities for malicious purposes. The team's ability to quickly recognize suspicious activities, such as attempts to bypass security protocols and manipulate system configurations, underscores the effectiveness of CrowdStrike's real-time visibility and patented tooling in providing high-fidelity notifications to affected organizations, enabling them to address threats before they cause significant damage. This approach highlights the importance of proactive threat hunting in maintaining cybersecurity defenses against evolving adversarial tactics.
Mar 14, 2022
2,118 words in the original blog post.
CrowdStrike, a leading cybersecurity firm, is enhancing its offerings through the CrowdStrike Store, which provides a platform for discovering and implementing IT and security solutions tailored to organizational needs. The store allows users to trial various Falcon modules and partner applications, such as Falcon Insight for endpoint detection and response and Falcon FileVantage for file integrity monitoring, without affecting resources or productivity. By integrating with partners like SecurityScorecard and IPQualityScore, CrowdStrike enriches threat detection and improves response accuracy by providing continuous visibility into cyber risk. The company's approach leverages a single-agent cloud-native architecture to streamline security operations and unify the security stack, enabling organizations to defend against sophisticated threats efficiently. The focus on SaaS security is addressed through partnerships like Adaptive Shield, enhancing security posture management and supporting a Zero Trust approach. Overall, CrowdStrike's ecosystem aims to simplify security operations and fortify defenses against modern cyber threats by providing comprehensive, interoperable tools that maximize the return on existing investments.
Mar 11, 2022
2,249 words in the original blog post.
The blog discusses the increasing importance of identity security in the context of modern cyber threats, specifically highlighting the risks associated with relying on identity security solutions bundled with identity management systems from the same vendor. It emphasizes the need for a dedicated and neutral identity security solution that offers comprehensive protection across various layers of enterprise risk, such as endpoints, cloud workloads, identities, and data. The text underscores CrowdStrike's approach to identity security, which focuses on eliminating vendor lock-in and integrating seamlessly with multiple identity and MFA providers for a holistic security strategy. Furthermore, it critiques the limitations of legacy systems like Microsoft Active Directory in addressing modern security challenges and promotes the benefits of using a specialized security vendor to enhance protection against identity-driven breaches.
Mar 11, 2022
2,462 words in the original blog post.
CrowdStrike has been recognized as a leader in several cybersecurity areas, including Managed Detection and Response Services in Europe and Worldwide Incident Response Services by the Forrester Wave™ and IDC MarketScape, respectively. The company actively develops advanced cybersecurity measures like its Falcon platform and XDR solutions to enhance security operations across various domains, including endpoint security, cloud and application security, and AI-powered threat detection. CrowdStrike is also advancing machine learning capabilities for cybersecurity, highlighted by their initiative EMBER2024, aimed at training models against evasive malware. They emphasize the integration of existing security tools with their XDR platform to enhance operational efficiency and reduce alert fatigue, and have formed the CrowdXDR Alliance to ensure optimal architecture and outcomes. Additionally, CrowdStrike is involved in various sectors, including public, small business, and threat intelligence, while continuously innovating across AI, cloud, and identity protection services.
Mar 09, 2022
2,254 words in the original blog post.
CrowdStrike is actively enhancing its cybersecurity strategies through various initiatives, including acquiring Pangea to bolster enterprise AI security and expanding its Falcon Platform to lead in the Agentic Security Era. The company has been recognized as a leader in several industry reports, such as the 2025 IDC MarketScape for exposure management and the Forrester Wave for managed detection and response services in Europe. CrowdStrike continues to address emerging threats by adapting its services, such as the Falcon Complete Hub, which transforms MDR visibility into actionable insights, and by launching new AI security services to improve SOC readiness. Additionally, the company remains proactive in vulnerability management, as seen in its responses to recent Patch Tuesday updates, including addressing zero-day vulnerabilities and critical issues in Microsoft products. Through these efforts, CrowdStrike aims to fortify its cybersecurity framework and maintain a robust defense against evolving cyber threats.
Mar 09, 2022
2,425 words in the original blog post.
CrowdStrike is enhancing its cybersecurity offerings with a focus on Zero Trust strategies, partnering with industry leaders like Okta and Zscaler to support the Cloud Security Alliance's Zero Trust Advancement Center. The company is addressing security challenges such as identity-based attacks, which have become prevalent due to sophisticated adversaries exploiting authentication systems. CrowdStrike's Zero Trust solution aims to minimize breach impacts by enforcing continuous, real-time risk-based validations across all resources and environments, leveraging its Falcon platform for comprehensive protection. The initiative aligns with broader industry trends and government directives emphasizing endpoint detection and Zero Trust, exemplified by CrowdStrike's collaboration with the Cybersecurity and Infrastructure Security Agency (CISA) for securing federal endpoints. The company continues to develop and integrate its platform with strategic partners to enhance security across various technology landscapes, including macOS and Linux.
Mar 09, 2022
2,232 words in the original blog post.
The blog highlights CrowdStrike's significant advancements and recognitions in the cybersecurity field, specifically focusing on their innovative approaches to combating evolving threats. Key achievements include being named a leader in the 2025 IDC MarketScape for Worldwide Incident Response Services and the acquisition of Onum to enhance data utilization within SOCs. The company is also advancing machine learning models to tackle evasive malware, as showcased in their EMBER2024 initiative. CrowdStrike's proactive threat detection and response capabilities are emphasized, including the prevention of cloud breaches using agentic AI and the development of custom XGBoost objectives for improving machine learning model stability. Additionally, the blog touches on CrowdStrike's engagement with AI and machine learning to secure AI agents and their partnership with Microsoft for harmonizing cyber threat attribution, reflecting the company's ongoing commitment to innovation and leadership in cybersecurity.
Mar 07, 2022
1,881 words in the original blog post.
CrowdStrike is at the forefront of cybersecurity innovation, offering a range of solutions and advancements to tackle modern cyber threats. The CrowdStrike Falcon® platform is a cloud-native solution that integrates endpoint protection, identity security, and data protection to defend against multifaceted attacks. The platform's capabilities include automated vulnerability management, real-time identity protection, and advanced threat detection powered by machine learning. CrowdStrike's approach emphasizes a layered defense strategy, combining proactive threat detection with streamlined patch management, to protect enterprise environments from sophisticated cyberattacks such as ransomware and supply chain threats. Additionally, CrowdStrike's collaborations and acquisitions aim to enhance security for AI applications and enterprise systems, reflecting its commitment to maintaining leadership in the cybersecurity sector.
Mar 07, 2022
1,761 words in the original blog post.
CrowdStrike is enhancing its cybersecurity capabilities by integrating Intel's Threat Detection Technology (TDT) accelerated memory scanning into its Falcon sensor for Windows, aiming to improve detection of fileless attacks that operate entirely in memory without leaving traditional malware signatures on disk. The integration allows for high-performance scanning of large memory areas using Intel CPUs and integrated GPUs, optimizing the process to identify malicious byte patterns efficiently. This advancement addresses the increasing reliance of threat actors on fileless attacks, which often use legitimate tools like PowerShell and Task Scheduler for malicious purposes, and complements existing Falcon features like Script Control and behavioral indicators of attack (IOAs) to offer a robust layered defense. The new memory scanning capability, introduced in beta with Falcon sensor version 6.37, provides real-time protection by allowing CrowdStrike's rapid response teams to deploy new memory pattern specifications from the cloud to customer endpoints swiftly, enhancing the company's ability to respond to dynamic threats and zero-day vulnerabilities.
Mar 03, 2022
2,664 words in the original blog post.
CrowdStrike's recent developments highlight its strategic advancements in cybersecurity through innovative solutions that address evolving threats and improve identity security. The company has introduced several new products and services, including the Falcon Cloud Security to protect AI development, unified data protection measures to prevent GenAI data leaks, and advancements in next-gen identity security with three key innovations. CrowdStrike also launched Threat AI, the first agentic threat intelligence system, and expanded its capabilities in endpoint security and AI-powered threat detection. The firm has been recognized as a leader in various industry reports, underscoring its influence in the cybersecurity landscape. Additionally, CrowdStrike emphasizes the importance of a robust identity protection strategy, which includes implementing multifactor authentication to bolster defenses against ransomware and identity-focused attacks, thus aligning with cyber insurance requirements.
Mar 02, 2022
2,195 words in the original blog post.
CrowdStrike has advanced its cybersecurity offerings through the introduction of Falcon Identity Threat Protection Complete, a fully managed identity protection solution that addresses modern threats arising from compromised credentials. The service integrates real-time identity threat prevention and IT policy enforcement with the expertise of the Falcon Complete team, enabling rapid incident response and policy enforcement to shrink attack surfaces and prevent unauthorized access. This identity threat protection technology autonomously enforces risk-based conditional access and provides detailed enterprise-wide visibility into authentication patterns, supporting a mature identity security program without the burden of an internal setup. CrowdStrike's solution emphasizes the importance of combining technology with human expertise to mount an effective defense against sophisticated attacks, maintaining a proactive stance in the evolving threat landscape.
Mar 02, 2022
1,892 words in the original blog post.
CrowdStrike's detailed analysis of the PartyTicket ransomware, which targeted Ukrainian entities in February 2022, reveals that the malware, developed using Go, is characterized by significant implementation errors that make its encryption breakable. The ransomware superficially encrypts files with a consistent AES key, generated due to a coding flaw, allowing for potential decryption. PartyTicket is politically themed, with references to the U.S. political system, and while it attempts to encrypt a wide array of file types, its execution is inefficient, creating excessive threads and leaving files recoverable. This suggests the author may have been inexperienced or operating under time constraints. The deployment of PartyTicket, alongside the more advanced DriveSlayer wiper, indicates its use as an additional, perhaps politically motivated, payload rather than a serious extortion attempt. CrowdStrike provides a script to exploit these flaws and decrypt files affected by PartyTicket.
Mar 01, 2022
2,544 words in the original blog post.