Home / Companies / Crowdstrike / Blog / October 2022

October 2022 Summaries

21 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
CrowdStrike's recent updates highlight its leadership in managed detection and response services, as noted in the Forrester Wave report for Q3 2025. The company has been recognized for its advancements in AI security, cloud protection, and endpoint security, while also being a leader in IDC MarketScape for exposure management. The September 2025 Patch Tuesday revealed two publicly disclosed zero-days and eight critical vulnerabilities among 84 CVEs, emphasizing the importance of proactive vulnerability management. CrowdStrike's solutions, like Falcon Spotlight, are designed to automatically detect and manage vulnerabilities such as those found in OpenSSL, ensuring comprehensive protection across various environments. The company also focuses on AI and machine learning to enhance cybersecurity measures against evolving threats and has expanded its services with new AI security offerings to improve security operations center (SOC) readiness.
Oct 28, 2022 1,708 words in the original blog post.
CrowdStrike is actively enhancing its cybersecurity capabilities through a blend of artificial intelligence (AI) and machine learning (ML), emphasizing the integration of human expertise in its processes. The company highlights its advanced machine learning cycle, which involves six critical phases: data collection and labeling, feature engineering, model training, deployment, expert analysis, and ongoing learning and retraining. This comprehensive approach ensures high detection efficacy, balancing speed with accuracy to minimize false positives. CrowdStrike's commitment to innovation is reflected in its continuous AI and ML advancements, which are designed to tackle the ever-evolving threat landscape. The company has been recognized as a leader in various industry assessments, emphasizing its position as a front-runner in endpoint protection, cloud security, and exposure management. Additionally, CrowdStrike's acquisition of Onum aims to transform data use within its agentic Security Operations Center (SOC), further solidifying its role in the cybersecurity sector.
Oct 27, 2022 2,723 words in the original blog post.
CrowdStrike's latest advancements focus on enhancing cybersecurity through a series of innovative solutions and strategic acquisitions aimed at improving data protection, identity security, and threat detection. The company has launched several new tools, including Falcon Insight XDR and Falcon LogScale, which work together to offer comprehensive monitoring, detection, and response capabilities by leveraging advanced analytics and rich threat intelligence. These tools are designed to address complex security challenges by integrating with existing IT ecosystems to enhance observability and streamline workflows. Additionally, CrowdStrike has expanded its partnerships and alliances, such as the CrowdXDR Alliance, to provide a unified defense against sophisticated cyber threats across multiple domains. The company is also recognized as a leader in various industry reports, underscoring its commitment to driving innovation in cybersecurity and maintaining a cutting-edge approach to protecting enterprise environments.
Oct 27, 2022 2,357 words in the original blog post.
CrowdStrike has uncovered a cryptojacking campaign dubbed "Kiss-a-dog," which targets vulnerable Docker and Kubernetes infrastructure by using an obscure domain and various techniques to mine cryptocurrency while evading detection. The campaign involves container escape, removal of cloud monitoring services, and the use of traditional kernel rootkits like Diamorphine and Libprocesshider to hide malicious activity. Attackers employ popular mining software like XMRig, disguised as legitimate processes, and utilize anonymous pool servers to conceal wallet addresses. Additionally, they leverage network-scanning tools to seek out more vulnerable instances and use Redis as a backdoor for further exploitation. This campaign highlights the persistent threat to cloud environments, emphasizing the need for robust security measures like those provided by CrowdStrike's Falcon platform, which offers both agentless and agent-based capabilities to detect and prevent such breaches.
Oct 26, 2022 2,873 words in the original blog post.
CrowdStrike emphasizes the importance of cybersecurity in elections, highlighting the persistent and evolving threats posed by various adversaries who aim to disrupt democratic processes. The document outlines several key threats, including breaches, misinformation and disinformation campaigns, supply-chain attacks, and broader security challenges, such as physical intimidation. CrowdStrike advocates for a comprehensive security approach that involves understanding the threat landscape, employing risk-informed defenses, building capacity to detect and respond to threats, and fostering collaboration across the election ecosystem. Through partnerships and resources like its Cybersecurity and Election Security Resource Center, CrowdStrike aims to strengthen the resilience of election security by encouraging stakeholders to adopt best practices and leverage managed security services. The ongoing efforts by governments and organizations to invest in and support election security are acknowledged, though the text underscores that further action is needed to address the real and emboldened threats facing elections globally.
Oct 26, 2022 2,779 words in the original blog post.
CrowdStrike's Falcon platform has demonstrated exceptional capabilities in protecting against ransomware, achieving a 100% protection accuracy with zero false positives in SE Labs' first-ever endpoint detection and response (EDR) ransomware evaluation. This recognition underscores the platform's industry leadership in automated ransomware detection and blocking, offering comprehensive protection against both known and unknown ransomware variants. The testing involved 270 ransomware samples, including sophisticated attacks that mimic real-world scenarios, and confirmed the Falcon platform's effectiveness in providing deep insight into threat chains without generating false positives. This high accuracy not only ensures robust protection but also reduces operational disruptions, allowing organizations to focus resources on addressing actual threats. The Falcon platform's success in these evaluations reflects its practical application in real-world environments, reassuring users of its reliability in safeguarding against modern cybersecurity threats.
Oct 25, 2022 2,332 words in the original blog post.
CrowdStrike is actively advancing the cybersecurity landscape through a series of strategic innovations and collaborations, with a strong emphasis on AI, cloud security, and identity protection. Recent developments include the introduction of Falcon Cloud Security to prevent GenAI data leaks and enhance runtime capabilities, alongside the launch of Threat AI, the first agentic threat intelligence system. The company has also made significant strides in identity security with three key innovations and solidified its leadership in managed detection and response services, as recognized by The Forrester Wave™. Further demonstrating its commitment to cybersecurity, CrowdStrike has become a Research Partner with MITRE Engenuity's Center for Threat-Informed Defense, focusing on leveraging its adversary-focused expertise to bolster defenses against sophisticated cyber threats. Additionally, CrowdStrike's Falcon platform continues to set industry standards in cybersecurity by utilizing advanced machine learning and AI to preemptively counteract known and emerging threats.
Oct 21, 2022 1,595 words in the original blog post.
The text provides a comprehensive overview of CrowdStrike's advancements and achievements in cybersecurity, highlighting its leadership in various arenas and the innovative measures it employs to combat evolving threats. Notably, CrowdStrike has been recognized as a leader in Managed Detection and Response Services and exposure management, showcasing its strong presence in the European cybersecurity market. The company continues to innovate with developments like the Falcon Complete Hub and the EMBER2024 project aimed at enhancing machine learning models against evasive malware. CrowdStrike's approach to cybersecurity includes the use of AI and machine learning across various platforms to ensure robust threat detection and response capabilities, alongside collaborations with major entities like Microsoft to enhance threat attribution. The text also emphasizes the company's role in pioneering solutions for cloud security and next-generation SIEM, demonstrating its commitment to protecting enterprises across different domains, including small businesses and the public sector.
Oct 21, 2022 4,262 words in the original blog post.
CrowdStrike has made significant advancements in cybersecurity by introducing various innovations and collaborations aimed at enhancing data protection, vulnerability management, and identity security. The company announced several key developments, including the launch of Threat AI, an agentic threat intelligence system, and new technologies for next-gen identity security with three key innovations. It also addressed GenAI data leaks with a unified data protection approach and redefined vulnerability management through risk-based patching. CrowdStrike's integration with Google Chrome's Enterprise Connectors Framework is designed to improve security insights and reporting, bolstering the capabilities of the CrowdStrike Falcon platform. These efforts, alongside strategic acquisitions and partnerships, underscore CrowdStrike's commitment to leading in the agentic security era and providing comprehensive protection across various domains.
Oct 20, 2022 1,525 words in the original blog post.
CrowdStrike, a leader in cybersecurity solutions, emphasizes its role in advancing cloud and application security through its Falcon platform, which integrates agent-based and agentless application security to provide comprehensive Cloud Native Application Protection Platform (CNAPP) capabilities. The platform supports DevOps by offering cloud workload protection, cloud security posture management, and cloud infrastructure entitlement management, enabling faster and more secure application deployment. At KubeCon + CloudNativeCon North America 2022, CrowdStrike showcased these capabilities alongside its Falcon LogScale technology, which enhances log management and observability. This approach allows organizations to streamline IT operations and improve security while reducing costs. Additionally, CrowdStrike continues to innovate in areas such as AI, threat intelligence, and identity security, addressing the evolving cybersecurity landscape and fortifying enterprise defenses against modern threats.
Oct 19, 2022 1,741 words in the original blog post.
CrowdStrike's recent updates highlight its comprehensive approach to cloud security and identity protection, focusing on its Falcon Cloud Security platform, which integrates cloud infrastructure entitlement management (CIEM) capabilities. This platform is designed to address identity-based threats across multi-cloud environments, such as AWS and Azure, by unifying visibility and enforcing least-privilege access. As cloud environments become increasingly complex, CrowdStrike emphasizes the importance of managing cloud identities and entitlements to prevent misconfigurations and security breaches. The platform offers a single dashboard for monitoring assets, identities, and security configurations, aiding security teams in maintaining a robust security posture. Additionally, the platform's capabilities are enhanced by the CrowdStrike Threat Graph®, which provides real-time protection and enriched threat intelligence to accelerate incident response and mitigate risks across hybrid environments. CrowdStrike's integration of agent-based and agentless protection within its CNAPP offering ensures comprehensive security coverage, while the Falcon platform's advanced analytics and visualization tools empower organizations to optimize their cloud security implementations effectively.
Oct 18, 2022 2,025 words in the original blog post.
CrowdStrike, a prominent cybersecurity firm, has been recognized as a leader in various industry reports, including the 2025 IDC MarketScape for Worldwide Incident Response Services and Exposure Management, as well as the 2025 Gartner Magic Quadrant for Endpoint Protection Platforms. The company is advancing its cybersecurity offerings by acquiring Onum to enhance the capabilities of its Agentic Security Operations Center (SOC), and integrating artificial intelligence to defend against evolving cyber threats at machine speed. CrowdStrike emphasizes the importance of cybersecurity for small and medium-sized businesses (SMBs), highlighting the growing threat landscape they face, particularly from social engineering and identity-based attacks. As a response, CrowdStrike offers solutions like multifactor authentication, regular data backups, and up-to-date software as essential practices to strengthen defenses. Additionally, the company is offering discounts on its products and services to help SMBs bolster their security posture amidst these challenges.
Oct 17, 2022 1,831 words in the original blog post.
The text provides an analysis of wiper malware, detailing their methods and objectives, which differ from ransomware by aiming to irretrievably destroy data rather than extort money. It highlights various wiper families and their techniques, such as deleting volume shadow copies, altering boot configurations, and using third-party drivers to enhance effectiveness while remaining undetected. The blog also discusses the CrowdStrike Falcon platform, which employs machine learning and behavior-based detection to provide comprehensive threat detection and continuous monitoring, thereby reducing the time needed to identify and mitigate threats. Additionally, the text emphasizes the importance of cybersecurity measures and provides insights into CrowdStrike's position and innovations within the cybersecurity industry.
Oct 14, 2022 3,011 words in the original blog post.
CrowdStrike has been recognized as a leader in several cybersecurity sectors, such as the Forrester Wave™ for Managed Detection and Response Services in Europe, the 2025 IDC MarketScape for Worldwide Incident Response Services, and the 2025 GigaOm Radar for SaaS Security Posture Management. The company is actively involved in advancing cybersecurity measures, particularly through initiatives like EMBER2024, which focuses on enhancing machine learning models to combat evasive malware, and by integrating AI to defend against expanding attack surfaces. Additionally, CrowdStrike is addressing cloud security challenges by utilizing Agentic AI for cloud detection and response and has been acknowledged for its innovative contributions to endpoint security and extended detection and response (XDR). Their Falcon platform is instrumental in providing real-time defense and mitigations against sophisticated breaches, while the company also emphasizes the importance of a comprehensive cybersecurity strategy in the absence of available patches for certain vulnerabilities. Furthermore, CrowdStrike continues to support small businesses by enhancing mobile protection and cybersecurity awareness programs, and it collaborates with major entities like Microsoft to improve cyber threat attribution and security posture management across various environments.
Oct 13, 2022 2,427 words in the original blog post.
CrowdStrike has partnered with MITRE’s Center for Threat-Informed Defense to enhance cloud security by identifying adversarial tactics, techniques, and procedures (TTPs) across Azure and GCP environments. The collaboration resulted in a blueprint documenting 14 key cloud analytics that help reduce alert noise and swiftly detect abnormal behavior, thereby improving threat detection and response times. The CrowdStrike Falcon platform integrates both agent-based and agentless protection to secure cloud environments through real-time analytics and machine learning, addressing the challenges of evolving adversarial TTPs and the complexities of cloud log data. This partnership and the resulting insights aim to advance public cloud security and support organizations in managing multi-cloud and hybrid environments efficiently.
Oct 13, 2022 2,284 words in the original blog post.
CrowdStrike's blog post explores the implications of using Intel's Software Guard Extensions (SGX) for ransomware key management within trusted execution environments (TEEs), known as enclaves. Enclaves enable secure cryptographic operations by isolating code and data from the operating system, thus preventing key exposure and facilitating secure storage across reboots. Despite the potential for ransomware authors to use enclaves to safeguard cryptographic keys from forensic retrieval, the post highlights the significant complexities and limitations of this tactic, which contribute to its low prevalence in the wild. CrowdStrike's Falcon platform provides robust defense against such threats by offering comprehensive visibility into enclave usage and leveraging event telemetry to detect and neutralize malicious activities.
Oct 13, 2022 3,661 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple cybersecurity categories, including worldwide incident response services and exposure management, as highlighted in the 2025 IDC MarketScape. The company is actively expanding its capabilities by acquiring Onum to enhance data-driven strategies for the Agentic SOC. CrowdStrike's Falcon platform, which is FedRAMP-authorized, plays a critical role in helping federal agencies meet the requirements of Binding Operational Directive 23-01 by providing comprehensive asset visibility and vulnerability detection. The platform offers endpoint, mobile, and cloud security, integrating solutions like Falcon Discover and Falcon Spotlight to ensure real-time monitoring and compliance. Additionally, CrowdStrike is set to acquire Reposify to bolster its external attack surface management capabilities, further reducing risk by identifying and mitigating vulnerabilities before adversaries can exploit them.
Oct 12, 2022 2,805 words in the original blog post.
CrowdStrike, a leader in cybersecurity solutions, has been recognized in several industry reports, including The Forrester Wave and IDC MarketScape, for its Managed Detection and Response Services in Europe and Worldwide Incident Response Services. The company is advancing cybersecurity measures with initiatives like EMBER2024, which focuses on improving machine learning models against evasive malware, and has made strides in AI security to protect against the growing attack surface. CrowdStrike has achieved Red Hat OpenShift Certification, enabling comprehensive breach protection for cloud-native applications across various environments, including Azure and AWS. The Falcon platform offers integrated security tools to manage Kubernetes clusters, ensuring visibility and protection against threats while supporting DevSecOps teams in maintaining secure and compliant environments. CrowdStrike continues to expand its ecosystem, supporting multiple OpenShift implementations and providing resources for threat hunting and proactive cybersecurity measures.
Oct 12, 2022 1,645 words in the original blog post.
DirtyCred is a Linux kernel exploit technique that leverages Use After Free (UAF) or double free vulnerabilities to escalate privileges and break out of containers, posing significant security challenges. Unlike a vulnerability, DirtyCred exploits weak kernel designs and works across various kernel versions, requiring only a reliable UAF or double free bug to be effective. The exploit technique is similar to Dirty Pipe, bypassing typical kernel mitigations due to its data-only nature, making detection difficult. Researchers suggest using defense-in-depth strategies, such as upgrading kernel versions, running workloads with non-root users, limiting container capabilities, and using seccomp profiles to mitigate the risk of exploitation. CrowdStrike Falcon® Cloud Security provides tools to detect and prevent such exploits by offering comprehensive monitoring and protection for containerized environments, emphasizing the importance of proactive security measures in defending against escalating cyber threats.
Oct 10, 2022 2,391 words in the original blog post.
The text discusses various accomplishments and advancements by CrowdStrike in the field of cybersecurity throughout 2025, highlighting its recognition as a leader in multiple industry reports such as The Forrester Wave and IDC MarketScape. The company focuses on enhancing cybersecurity measures through innovations like the Falcon Long Term Repository (Falcon LTR), which facilitates cost-effective long-term data retention and advanced threat hunting capabilities. CrowdStrike's efforts in AI and machine learning, cloud security, identity protection, and threat intelligence are showcased, emphasizing its strategic acquisitions and partnerships aimed at strengthening its security operations center (SOC) capabilities. The text also underscores CrowdStrike's proactive approach to cybersecurity challenges, including addressing evasive malware and evolving threat landscapes, while maintaining a focus on compliance and efficient data management.
Oct 06, 2022 1,824 words in the original blog post.
CrowdStrike's recent initiatives emphasize its focus on enhancing cloud and application security, threat hunting, and AI-driven cybersecurity solutions to combat sophisticated threats in cloud environments. The company has introduced Falcon OverWatch Cloud Threat Hunting, which leverages advanced telemetry and threat hunting methodologies to detect and disrupt complex cloud-based threats across major platforms like AWS, Azure, and Google Cloud. Additionally, CrowdStrike has been recognized as a leader in various industry reports, highlighting its capabilities in incident response, identity security, and managed detection and response services. The text also describes specific case studies where adversaries have exploited cloud infrastructures, underscoring the importance of comprehensive threat detection and proactive security measures.
Oct 04, 2022 2,698 words in the original blog post.