May 2022 Summaries
17 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
CrowdStrike's comprehensive cybersecurity approach emphasizes adversary-focused strategies, tracking over 180 global threat actors across categories like cybercrime, nation-state, and hacktivist adversaries. The company's methodology involves detailed attribution processes, where adversaries are identified by their motivations, tools, and tactics, enabling defenders to understand the "who, how, and why" behind cyberattacks. This understanding allows security teams to focus their resources effectively, apply proactive measures, and streamline their responses to threats. CrowdStrike leverages its extensive data collection and analysis capabilities through the Falcon platform to identify activity clusters and enhance threat intelligence, which in turn informs a more unified and strategic defense against sophisticated cyber threats. By promoting an adversary-centric perspective, CrowdStrike helps organizations increase the effectiveness of their cybersecurity efforts, facilitating communication and collaboration across security teams and operational silos.
May 31, 2022
2,283 words in the original blog post.
The text provides an overview of CrowdStrike's recent activities and achievements in cybersecurity as of September 2025, highlighting the company's leadership position in various industry reports and its efforts to address emerging threats and vulnerabilities. Notably, CrowdStrike was recognized as a leader in The Forrester Wave™ for Managed Detection and Response Services in Europe and the 2025 IDC MarketScape for multiple categories, including Exposure Management and Incident Response Services. The company is actively enhancing its AI security services and cloud detection capabilities, as well as advancing its cybersecurity machine learning models to combat evasive malware. Additionally, CrowdStrike emphasizes the evolving nature of data protection threats under GDPR, advocating for robust defenses such as XDR, zero trust, and log management to meet compliance requirements amidst changing cyber threat landscapes.
May 27, 2022
2,120 words in the original blog post.
CrowdStrike is at the forefront of cybersecurity, employing advanced technologies and strategic collaborations to enhance data protection and threat intelligence. Recent initiatives include the launch of Threat AI, an innovative agentic threat intelligence system, and collaborations with AI leaders to secure artificial intelligence across enterprises. The company is also advancing identity security with three new innovations and has unveiled unified data protection measures to prevent GenAI data leaks. Additionally, CrowdStrike's OverWatch service continues to provide 24/7 threat hunting, identifying malicious activities such as JScript exploitations, and offering tailored responses to protect customer environments. The company has been recognized as a leader in various industry assessments and continues to expand its security services to address evolving cyber threats effectively.
May 26, 2022
2,374 words in the original blog post.
CrowdStrike is a leading provider in the cybersecurity industry, particularly in cloud-delivered protection, threat intelligence, and endpoint security. The company’s comprehensive intelligence collection strategy, which includes data from a variety of sources such as the dark web, open-source intelligence, and malware samples, differentiates it from its competitors by offering unique insights into cyber threats. CrowdStrike’s approach focuses on profiling adversaries to help organizations proactively defend against potential attacks. Their offerings are designed to cater to a wide range of customers, from those new to threat intelligence to advanced global enterprises, by providing customizable solutions that integrate seamlessly into existing workflows. The company has been recognized as a leader in various industry analyses, including the 2022 SPARK Matrix for Digital Threat Intelligence Management, due to its technological excellence and customer impact. CrowdStrike’s Falcon Intelligence platform is central to its strategy, providing enriched threat intelligence to enhance decision-making and threat response capabilities for its users.
May 26, 2022
2,429 words in the original blog post.
CrowdStrike's blog highlights the evolving threat landscape, emphasizing the complexities of endpoint detection and response (EDR) in dealing with adversaries like DecisiveArchitect, which targets telecommunications companies and other sectors using sophisticated tactics across Linux and Solaris systems. The adversary employs a custom implant known as JustForFun, leveraging command-line spoofing and the LD_PRELOAD technique to evade detection and achieve persistence, often exploiting vulnerabilities like CVE-2019-3010 for privilege escalation. CrowdStrike's approach to countering such threats involves utilizing advanced EDR technology with machine learning to detect anomalies, alongside behavioral-based hunting methods to identify and mitigate the implant's presence. The blog underscores the importance of continuous vigilance and adaptation in cybersecurity strategies, given the persistent and evolving nature of threats such as DecisiveArchitect.
May 25, 2022
2,953 words in the original blog post.
CrowdStrike has been acknowledged as a leader in multiple cybersecurity sectors, including being named a leader in The Forrester Wave™ for Managed Detection and Response Services in Europe and the IDC MarketScape for Worldwide Incident Response Services in 2025. The company is at the forefront of advancing cybersecurity measures, particularly in the realm of AI and machine learning, with initiatives like EMBER2024, which focuses on enhancing cybersecurity ML models against evasive malware. CrowdStrike's efforts in securing AI at machine speed aim to protect an expanding attack surface, and their Falcon platform plays a crucial role in defending Linux systems against evolving threats such as Mirai malware variants. The company continues to innovate across various domains, including cloud security, threat intelligence, endpoint security, and identity protection, cementing its position as a key player in the cybersecurity landscape.
May 20, 2022
2,095 words in the original blog post.
CrowdStrike, a prominent cybersecurity firm, is actively enhancing its services and collaborations to address evolving threats in cloud and application security, AI, and endpoint protection. The company has recently been recognized as a leader in several industry reports, including The Forrester Wave and IDC MarketScape, for its managed detection and response services. CrowdStrike is extending its cloud security capabilities through partnerships, such as with Red Hat, to offer comprehensive protection for workloads and containers in hybrid cloud environments using its Falcon Cloud Workload Protection platform. This collaboration aims to provide organizations with improved security visibility and threat detection across their cloud ecosystems. Additionally, CrowdStrike is advancing its machine learning models to combat evasive malware and is continuously innovating in AI-driven threat detection and response, positioning itself as a key player in the cybersecurity landscape with a focus on protecting both enterprise and small business environments.
May 19, 2022
1,759 words in the original blog post.
CrowdStrike has been recognized as an Overall Leader in the 2022 KuppingerCole Leadership Compass for the Endpoint Protection, Detection, and Response (EPDR) market, highlighting its strong position in product, innovation, and market leadership. The report applauds the CrowdStrike Falcon platform for its comprehensive, cloud-native management and advanced deep learning detection algorithms, along with its customizable interfaces for threat investigation and hunting. CrowdStrike's leadership extends to the emerging Extended Detection and Response (XDR) market, leveraging its EPDR expertise to provide a robust foundation for XDR strategies that integrate endpoint data with additional non-endpoint data to enhance detection across domains. The recognition underscores CrowdStrike's commitment to innovation, evidenced by its strong market position, financial strength, and the wide range of IT management and security tool integrations available through the CrowdStrike Store. The company's approach, emphasizing both automated and human-centric threat detection, positions it favorably to address evolving cybersecurity challenges.
May 16, 2022
1,943 words in the original blog post.
CrowdStrike is highlighted for its leadership and innovation in the cybersecurity sector, particularly in managed detection and response services, incident response, and cloud security. The company has been recognized as a leader in several industry reports, including The Forrester Wave and IDC MarketScape, and has been noted for its advancements in AI and machine learning to combat the evolving threat landscape. CrowdStrike's threat intelligence provides insights into eCrime monetization, emphasizing the importance of understanding ransomware strategies and cryptocurrency use in cybercrime. The company's diverse cybersecurity solutions, such as the Falcon platform, aim to protect against sophisticated threats across various sectors, including small businesses and the public sector, through a layered security approach and zero-trust principles.
May 13, 2022
2,100 words in the original blog post.
CrowdStrike has been consistently recognized as a leader in the cybersecurity industry, with accolades from Forrester Wave, IDC MarketScape, and GigaOm Radar for its managed detection and response, incident response, and security management services. The company is advancing its capabilities by integrating AI and machine learning into its cybersecurity solutions to address the growing complexity of modern threats, such as evasive malware and vulnerabilities in cloud environments. Its Falcon platform is noted for its ability to detect and prevent sophisticated threats at machine speed, while Falcon Spotlight aids organizations in prioritizing and managing vulnerabilities efficiently. CrowdStrike's commitment to innovation is also reflected in its partnerships and acquisitions, such as the alliance with Microsoft for cyber threat attribution and the acquisition of Onum to enhance its data-powered security operations. Additionally, CrowdStrike emphasizes the importance of a robust patching strategy, especially as adversaries become more sophisticated, and offers tools like Falcon Spotlight ExPRT.AI to help organizations proactively manage vulnerabilities.
May 12, 2022
2,312 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple cybersecurity evaluations, including The Forrester Wave™ for Managed Detection and Response Services in Europe and the IDC MarketScape for Worldwide Incident Response Services in 2025. The company's Falcon platform has consistently demonstrated high performance in independent tests, achieving maximum scores for protection, performance, and usability against MacOS threats in AV-TEST evaluations. CrowdStrike emphasizes transparency by participating in third-party evaluations and is committed to advancing cybersecurity through innovations in AI, cloud security, and endpoint protection. Their efforts extend to tailored adversary intelligence for customers, AI-powered threat detection, and proactive approaches to threat hunting. Additionally, CrowdStrike is involved in initiatives like the EMBER2024 for improving machine learning models against malware and works to enhance security across various domains, including cloud environments and small businesses.
May 12, 2022
1,791 words in the original blog post.
The CrowdStrike Falcon® OverWatch™ team has discovered a sophisticated post-exploitation framework named IceApple, which is primarily used for intelligence collection in long-term campaigns and has been observed in various sectors, including technology, academia, and government. This .NET-based framework, capable of running under Internet Information Services (IIS) web applications, employs 18 distinct modules for tasks such as discovery, credential harvesting, and data exfiltration. Notably, IceApple prioritizes maintaining a low forensic footprint and uses in-memory-only techniques to evade detection. While the intrusions align with China-nexus, state-sponsored activities, CrowdStrike has not yet attributed IceApple to a specific threat actor. The discovery of IceApple by OverWatch was facilitated by the team's expertise in identifying anomalies and their proactive threat-hunting efforts, which include developing detections for reflective .NET assembly loads. These efforts underscore the importance of agile defense mechanisms in countering evolving cyber threats.
May 11, 2022
1,862 words in the original blog post.
The text highlights CrowdStrike's prominence in the cybersecurity industry, emphasizing its recognition as a leader in various reports such as The Forrester Wave™ and IDC MarketScape for its managed detection and response services. CrowdStrike's initiatives include the advancement of cybersecurity machine learning models to combat evasive malware and its strategic partnership with the MITRE Engenuity Center for Threat-Informed Defense to prioritize adversary attack techniques. The company actively contributes to research that enhances the understanding of adversary tactics, techniques, and procedures (TTPs), while its Falcon platform is noted for its ability to detect and defend against a wide range of cyber threats across different environments. Additionally, the text discusses CrowdStrike's efforts in integrating advanced AI security services and strengthening partnerships to improve cybersecurity resilience and defense mechanisms.
May 10, 2022
2,249 words in the original blog post.
The blog post from CrowdStrike delves into the intricacies of macOS malware, focusing on the challenges and methodologies involved in detecting and analyzing these threats. It highlights the prevalence of ransomware, backdoors, and trojans within the macOS ecosystem, emphasizing the sophisticated tactics used by malware developers to evade detection, such as file-type masking and anti-debugging techniques. CrowdStrike researchers consistently work to enhance their Falcon® platform's automated detection capabilities by understanding the behavior and persistence mechanisms of these threats. Through deep analysis, they aim to improve protection for their customers against the myriad of threats targeting macOS systems. The blog underscores the importance of continuous research and innovation in cybersecurity to address evolving malware tactics effectively.
May 06, 2022
2,478 words in the original blog post.
CrowdStrike's blog highlights the capabilities of its Falcon OverWatch managed threat hunting service, which operates continuously to identify and mitigate cybersecurity threats. Utilizing advanced tools and human expertise, OverWatch swiftly detects and analyzes malicious activities, providing organizations with detailed insights and context-rich notifications to inform timely responses. This service excels in identifying and correlating suspicious behaviors using patented cardinality-based detection tools, while also benefiting from human analysis to uncover novel adversary tactics. The integration of Falcon Fusion further enhances response capabilities by automating workflows and enabling real-time threat containment. The blog underscores the importance of combining technology with human expertise in effectively countering sophisticated cyber threats, as demonstrated in the MITRE Engenuity ATT&CK Enterprise Evaluation against adversaries like WIZARD SPIDER.
May 05, 2022
2,175 words in the original blog post.
In 2022, compromised Docker Engine honeypots were utilized in a pro-Ukrainian denial-of-service (DoS) attack, targeting websites in Russia, Belarus, and Lithuania across various sectors, including government and military. The attack involved two Docker images, "abagayev/stop-russia" and "erikmnkl/stoppropaganda," both downloaded extensively but with an unknown number originating from compromised sources. These images leveraged Go-based tools to execute the attacks, with their target lists reportedly overlapping with those shared by the Ukraine IT Army (UIA), which had previously called for DDoS attacks against Russian targets. CrowdStrike's Falcon platform provided protection against these threats through its cloud-based machine learning models, detecting and terminating malicious processes. The assessment, based on high-quality intelligence, suggests these actions were automated and very likely supported pro-Ukrainian efforts, highlighting potential retaliatory risks for organizations inadvertently involved.
May 04, 2022
2,032 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple cybersecurity sectors, including the Forrester Wave™ for Managed Detection and Response Services in Europe and the IDC MarketScape for Worldwide Incident Response Services in 2025. The company is advancing the training of cybersecurity models against evasive malware through initiatives like EMBER2024 and is employing AI to address the expanding attack surface. CrowdStrike's Falcon platform offers comprehensive solutions for cloud security, endpoint security, and workload protection, with features designed to prevent container escape attempts and trace attack paths to sensitive data. The platform's capabilities are enhanced by real-time detection and response to threats, including zero-day vulnerabilities. Furthermore, CrowdStrike is expanding its reach by integrating with advanced technologies like ChatGPT Enterprise Compliance API and collaborating with major industry players such as Microsoft.
May 03, 2022
1,872 words in the original blog post.