Home / Companies / Crowdstrike / Blog / April 2022

April 2022 Summaries

13 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
CrowdStrike's Falcon Fusion is a powerful security orchestration, automation, and response (SOAR) framework integrated into the Falcon platform, designed to enhance incident response through automated workflows and enriched threat intelligence. It leverages capabilities such as machine learning, indicators of attack (IOAs), and unified endpoint protection to autonomously respond to sophisticated threats, thereby reducing alert fatigue and freeing analysts to focus on critical tasks. The Falcon Fusion framework demonstrated its efficacy during the MITRE Engenuity ATT&CK Enterprise Evaluation by achieving 100% automated prevention against advanced adversaries, showcasing its ability to effectively stop breaches and streamline security operations. By automating processes such as malware sandbox detonations and credential watchlist updates, Falcon Fusion enhances the speed and precision of security operations centers (SOCs), making it easier to defend against persistent cyber threats without the need for additional manual intervention or custom integrations.
Apr 28, 2022 2,255 words in the original blog post.
CrowdStrike has unveiled significant enhancements to its Cloud Native Application Protection Platform (CNAPP) to address the growing complexities of securing modern cloud environments. The new capabilities are designed to provide comprehensive visibility, detection, and remediation for cloud workloads, leveraging both agent-based and agentless solutions to combat cloud security threats effectively. By integrating threat intelligence and focusing on adversary tactics, CrowdStrike's platform aims to secure cloud applications across various infrastructures, including AWS, Azure, and Google Cloud Platform. These updates emphasize the importance of a proactive security strategy that includes automation, deep visibility, and runtime protection, ensuring that organizations can adapt to the fast-evolving threat landscape. Additionally, new features like container detection, rogue container scanning, and a cloud activity dashboard enhance the platform's ability to protect against advanced threats, misconfigurations, and identity-based risks. As businesses increasingly adopt hybrid work models and multi-cloud environments, CrowdStrike's advancements in cloud security tools aim to provide the necessary protection to keep pace with these changes and the threats targeting them.
Apr 27, 2022 2,250 words in the original blog post.
CrowdStrike's blog explores the emotional journey and practical strategies for handling a cybersecurity breach, drawing parallels with the five stages of grief outlined by Elisabeth Kübler-Ross. The article emphasizes the importance of moving swiftly through denial to execute an effective incident response, avoiding anger and bargaining to prevent distractions, and leaning on professional support during the depression phase. Acceptance is viewed as a crucial step toward implementing measures to prevent future breaches. Practical advice includes leveraging incident response service providers, conducting breach response exercises, understanding legal and regulatory requirements, carrying cyber insurance, and engaging crisis communication firms. A postmortem analysis is recommended to identify and address gaps in security measures, ensuring an organization is better prepared for future incidents.
Apr 22, 2022 2,465 words in the original blog post.
LemonDuck, a notorious cryptomining botnet, is actively targeting Docker APIs on Linux systems to mine cryptocurrency, capitalizing on the recent boom in cryptocurrency prices and increased cloud adoption by enterprises. The campaign exploits misconfigured cloud instances to run malicious containers that download disguised scripts, such as “core.png” and “a.asp,” which establish cronjobs to initiate mining operations using XMRig. LemonDuck evades detection by disabling Alibaba Cloud's monitoring service and uses proxy pools to obscure the crypto wallet addresses. The botnet also employs lateral movement via SSH keys, differentiating its approach from other mining campaigns. CrowdStrike's Falcon platform provides runtime protection and employs machine learning models to mitigate such threats, ensuring real-time security for container environments.
Apr 21, 2022 2,409 words in the original blog post.
CrowdStrike's blog highlights the integration of its Falcon Spotlight with CISA's Known Exploited Vulnerabilities Catalog to enhance threat and vulnerability management. The blog emphasizes CrowdStrike's role in the Joint Cyber Defense Collaborative (JCDC) and the importance of Falcon Spotlight's Expert Prediction Rating AI (ExPRT.AI) in prioritizing critical vulnerabilities for proactive mitigation. It provides insights into leveraging APIs and Falcon's UI for real-time assessment and management of vulnerabilities, illustrating the system's ability to prioritize and address security threats effectively. The blog underscores the need for robust vulnerability management to ensure security posture, especially in light of increasing government advisories and known exploits.
Apr 20, 2022 3,004 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity domains in 2025, including incident response services and exposure management, according to the IDC MarketScape reports. The company is actively enhancing its cybersecurity capabilities through strategic acquisitions, such as that of Onum, to transform data utilization within agentic security operations centers (SOCs). CrowdStrike's Falcon platform has demonstrated robust performance in the MITRE Engenuity ATT&CK Enterprise Evaluation, showcasing its ability to prevent threats and provide enriched threat intelligence through Falcon Intelligence. The platform integrates advanced threat detection, machine learning, and automated intelligence to offer security teams effective tools for preventing and managing cyber attacks. The company is also focused on expanding its AI security services, improving endpoint protection, and strengthening identity and cloud security measures, positioning itself as a frontrunner in the cybersecurity industry.
Apr 19, 2022 2,266 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity domains, including Managed Detection and Response Services and Incident Response Services, as noted in the Forrester Wave™ and IDC MarketScape reports for 2025. The company is advancing its efforts in cybersecurity through initiatives such as EMBER2024, which focuses on training machine learning models to combat evasive malware, and the development of AI-driven solutions to address the expanding digital attack surface. Additionally, CrowdStrike is enhancing security across cloud environments and improving response strategies against threats like SCATTERED SPIDER. The company is also actively involved in bolstering small business cybersecurity, strengthening AI security services, and emphasizing the importance of patch management, as evidenced by their involvement in addressing vulnerabilities disclosed in Microsoft's Patch Tuesday updates.
Apr 14, 2022 2,433 words in the original blog post.
CrowdStrike is at the forefront of cybersecurity innovation, emphasizing the evolution of Extended Detection and Response (XDR) to address complex challenges in the information security landscape. XDR is not merely about aggregating more data but rather about resolving semantic gaps, reconciling contradictory information from diverse data sources, and efficiently performing entity resolution to provide a comprehensive view of security environments. CrowdStrike's approach includes leveraging advanced search capabilities and the use of graphs, such as the CrowdStrike Threat Graph®, to pre-join data, thereby overcoming the limitations of traditional search methods. This enables the identification and correlation of security events across multiple data sources, enhancing the detection of threats like lateral movement and phishing attacks. The company's innovations are part of a broader initiative to redefine cybersecurity practices, incorporating AI, cloud security, and next-gen identity protection to provide robust protection across diverse and evolving digital landscapes.
Apr 13, 2022 3,282 words in the original blog post.
The text provides an overview of CrowdStrike's approach to integrating artificial intelligence (AI) in cybersecurity, emphasizing the importance of human involvement for AI effectiveness. CrowdStrike's Falcon platform processes over a trillion events daily, using a combination of AI and human intelligence to analyze and classify data, with humans providing essential "ground truth" to enhance AI training. This approach allows the platform to detect and prevent novel threats without requiring updates, leveraging both supervised and unsupervised learning methods. CrowdStrike emphasizes transparency and rigorous third-party evaluations to maintain trust, and it highlights the importance of active learning, where human experts continuously provide feedback to improve AI performance. The text also underscores the significance of data volume and organization for AI efficacy, illustrating how structured data aids in forming accurate threat detection models.
Apr 08, 2022 2,928 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity domains in 2025, including incident response services, exposure management, and endpoint protection platforms, according to reports from IDC MarketScape and Gartner®. The company announced its intention to acquire Onum to enhance data capabilities within its Agentic SOC, aiming to transform cybersecurity operations. CrowdStrike's Falcon platform, known for its strong identity protection features, demonstrated its effectiveness in the MITRE Engenuity ATT&CK Evaluation by preventing breaches even when some security components were disabled during testing. The platform's advanced threat detection and response capabilities, powered by AI, enable it to tackle modern identity-based attacks, such as ransomware, by implementing a Zero Trust approach and utilizing multifactor authentication. Additionally, CrowdStrike has been proactive in integrating AI security services to boost security operation center (SOC) readiness and has maintained a strong focus on innovation across AI, cloud security, and identity protection, solidifying its position as a prominent figure in the cybersecurity landscape.
Apr 07, 2022 2,069 words in the original blog post.
CrowdStrike has been recognized as a leader in the Forrester Wave™: Endpoint Detection and Response (EDR) Providers report, underscoring its robust capabilities in endpoint security, which serves as a foundational aspect of extended detection and response (XDR) and Zero Trust strategies. The company is known for its lightweight agent and cloud-native architecture, which enables real-time monitoring and analysis of endpoint activity to thwart advanced threats effectively. This recognition highlights CrowdStrike's innovation in creating a unified platform that integrates EDR with XDR, cloud security, identity protection, and threat intelligence, providing comprehensive risk protection for enterprises. By continuously enhancing its product vision and response capabilities, CrowdStrike remains committed to improving user experience and security outcomes, making it a preferred choice for organizations seeking cutting-edge solutions to defend against increasingly sophisticated cyber threats.
Apr 06, 2022 2,240 words in the original blog post.
The text highlights CrowdStrike's leadership and advancements in cybersecurity, particularly in the areas of managed detection and response services, cloud security, and machine learning. CrowdStrike is recognized as a leader in various industry analyses, such as The Forrester Wave and IDC MarketScape, for its effective cybersecurity solutions across Europe and worldwide. The company has been innovating in AI and machine learning to enhance cybersecurity defenses, focusing on runtime protection and cloud security posture management to prevent breaches effectively. CrowdStrike's approach involves integrating threat intelligence and continuous monitoring to protect cloud environments, emphasizing the importance of runtime protection and a layered security approach. The text also notes CrowdStrike's collaborations and partnerships to enhance cybersecurity measures and the company's commitment to providing comprehensive, agentless protection across major cloud platforms like Google, AWS, and Azure.
Apr 04, 2022 2,193 words in the original blog post.
The text provides a comprehensive overview of CrowdStrike's recent advancements and recognitions in the cybersecurity domain as of 2025. It details their innovative use of machine learning techniques, such as BERT embeddings, to enhance malware detection capabilities, highlighting their commitment to leveraging natural language processing for improved cybersecurity measures. The company has been recognized as a leader in multiple industry evaluations, such as The Forrester Wave and IDC MarketScape, for their managed detection and response services and incident response services. Additionally, CrowdStrike's ongoing research into AI security and adversarial intelligence is emphasized, along with their efforts to secure AI agents across various environments. The text also notes CrowdStrike's strategic partnerships and acquisitions aimed at strengthening their service offerings and their proactive approach to adapting cutting-edge technology to protect against evolving cyber threats.
Apr 01, 2022 2,616 words in the original blog post.