Home / Companies / Crowdstrike / Blog / December 2022

December 2022 Summaries

19 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
The text outlines various achievements and updates from CrowdStrike in 2025, highlighting its recognition as a leader in several IDC MarketScape reports, including those for worldwide incident response services and exposure management. Additionally, CrowdStrike's acquisition of Onum aims to enhance data-driven capabilities for its Agentic SOC. The narrative also delves into the persistent cybersecurity threat posed by DLL hijacking, illustrating four methods used by adversaries and how CrowdStrike's Falcon OverWatch threat hunters actively counter these techniques. The company emphasizes its proactive threat hunting strategies, leveraging global data to identify and mitigate malicious activities, and invites readers to explore its services through a free trial.
Dec 30, 2022 2,961 words in the original blog post.
The blog post details the comprehensive strategies and techniques involved in enterprise-level incident response and recovery, particularly in the context of ransomware attacks, using the CrowdStrike Falcon platform and insights from MOXFIVE's experience. It emphasizes the importance of a well-defined containment and recovery plan, which includes blocking attacker access, resetting compromised credentials, and restoring business operations to their pre-incident state. The post also highlights the significance of having viable server backups, understanding IT assets, and testing recovery processes to ensure preparedness in the face of cyber threats. Additionally, it discusses the integration of critical technology controls, such as multifactor authentication and unique local administrator passwords, to enhance security posture. Overall, the article serves as a guide for organizations to effectively manage and mitigate the impact of significant cybersecurity incidents.
Dec 29, 2022 3,947 words in the original blog post.
The text provides an in-depth overview of CrowdStrike's approach to enterprise remediation following cyberattacks, emphasizing collaboration with MOXFIVE. It highlights the importance of a structured incident management team, skilled incident managers, and precise measurement metrics to manage and communicate during crises. The blog stresses using collaboration technology and a single source of truth to streamline recovery efforts and minimize business disruptions. CrowdStrike's intelligence-led rapid recovery approach and MOXFIVE's remediation expertise are positioned as critical in restoring compromised systems and maintaining business resilience. The text also references CrowdStrike's broader cybersecurity initiatives and achievements, including advancements in AI security and its leadership position in various industry reports.
Dec 27, 2022 2,374 words in the original blog post.
CrowdStrike's extensive range of cybersecurity solutions is highlighted through its innovative approaches in areas such as log management, AI security, cloud workload protection, and identity security. The Falcon LogScale platform offers a modern log management solution that emphasizes real-time search, advanced data compression, and low total cost of ownership, making it a scalable option for enterprises looking to log data efficiently. CrowdStrike is recognized as a leader in various cybersecurity sectors, including endpoint protection and cloud security, and actively collaborates with AI leaders to enhance security across enterprises. The company is also involved in strategic acquisitions, such as Pangea and Onum, to bolster its position in the emerging agentic security operations center (SOC) landscape.
Dec 21, 2022 2,101 words in the original blog post.
The text provides a comprehensive overview of CrowdStrike's recent advancements and recognitions in the realm of cybersecurity, highlighting its role as a leader in threat intelligence and endpoint protection. Notably, CrowdStrike has introduced new innovations such as the Threat AI system and next-generation identity security measures, alongside collaborations with AI leaders to enhance enterprise security. The company's strategic approach includes leveraging high-fidelity data collected via its Falcon platform, which is instrumental in tracking global adversaries and providing unique, actionable intelligence to its clients. These efforts are supported by a robust framework that integrates intelligence into the security operations center, enhancing the detection and response capabilities of organizations across various sectors. CrowdStrike's continuous innovation and commitment to providing top-tier threat intelligence have been recognized by industry leaders, underscoring its position as a pivotal player in the cybersecurity landscape.
Dec 20, 2022 2,031 words in the original blog post.
CrowdStrike's recent initiatives highlight its commitment to advancing cybersecurity through various innovative strategies and technologies. The company has unveiled several major developments, such as the introduction of an agentic threat intelligence system named Threat AI and enhancements in next-generation identity security with three key innovations. To combat emerging threats, CrowdStrike continues to enhance its Falcon Cloud Security, which now includes capabilities for preventing container escape attempts and tracing attack paths to sensitive data. Additionally, CrowdStrike's unified data protection aims to prevent GenAI data leaks, and the company has been recognized as a leader in the 2025 IDC MarketScape for CNAPP. Notably, CrowdStrike's research led to the discovery of a new exploit method named OWASSRF, which bypasses Microsoft mitigations for ProxyNotShell, highlighting the ongoing evolution of threat landscapes and the company's proactive measures to address them.
Dec 20, 2022 2,403 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity domains, including incident response services and exposure management, according to several 2025 IDC MarketScape reports. The company is making strategic moves to enhance its capabilities, such as acquiring Onum to improve how data powers its Agentic SOC, and integrating AI to defend against evolving threats at machine speed. CrowdStrike's Falcon platform has been pivotal in protecting against sophisticated threats like GuLoader, which employs advanced anti-analysis techniques and multistage deployment strategies to avoid detection. The platform uses behavior-based detection to identify and prevent potential threats early in the attack chain. Additionally, CrowdStrike is actively involved in threat hunting and intelligence, tailoring adversary intelligence to customer environments, and supporting various sectors, including public and small businesses, with its comprehensive cybersecurity solutions.
Dec 19, 2022 3,511 words in the original blog post.
CrowdStrike Falcon Surface is a comprehensive external attack surface management (EASM) technology that provides a detailed, real-time view of an organization's internet-exposed assets, leveraging CrowdStrike's adversary intelligence to prioritize and mitigate risks effectively. As cyber threats evolve with the expansion of digital transformation, hybrid work, and IoT, Falcon Surface offers a proactive approach to cybersecurity by identifying and managing internet-facing assets, including those of third-party vendors and subsidiaries, to prevent breaches and reduce risk. It utilizes a 24/7 scanning engine to map and index billions of assets globally, offering actionable insights for security teams to address vulnerabilities swiftly. Integrated within the CrowdStrike Falcon platform, Falcon Surface combines threat intelligence, vulnerability management, and IT hygiene to enhance an organization's security posture, providing a holistic view and enabling proactive defenses against modern threats in a cloud-first environment.
Dec 15, 2022 2,237 words in the original blog post.
CrowdStrike is at the forefront of cybersecurity innovation, offering a range of solutions designed to tackle the evolving threats posed by cybercriminals in the eCrime ecosystem. Their Falcon Intelligence Recon solution enhances security teams' ability to identify and mitigate digital risks by providing global threat awareness, understanding organizational threat profiles, and enabling refined searches and continuous monitoring of underground forums. The company continuously tracks and reports on sophisticated ransomware operators and data extortionists, while also expanding their capabilities to address challenges such as credential theft and the quick adaptation of adversaries to new vulnerabilities. With new features like advanced historical searching and monitoring for exposed sensitive data, CrowdStrike empowers security teams to proactively adjust controls and stay ahead of imminent threats. They support their clients with insights into the criminal ecosystem, allowing for proactive security measures and comprehensive monitoring efforts to counteract the fast-changing dynamics of cyber threats.
Dec 15, 2022 2,024 words in the original blog post.
CrowdStrike emphasizes the critical role of threat hunting in cybersecurity, highlighting its managed threat hunting service, Falcon OverWatch, which provides 24/7 coverage to detect novel threats that evade automated systems. The service is praised for augmenting security teams by offsetting full-time equivalent threat hunters, thereby saving significant costs and allowing teams to focus on high-priority issues. Falcon OverWatch excels in leveraging proprietary technology and human expertise to sift through millions of hunting leads, facilitating quick and efficient detection of potential threats. This managed service not only enhances organizational security posture but also contributes to building trust with consumers and partners, as it demonstrates a commitment to data protection. CrowdStrike's collaborative approach, validated by customer experiences, underscores the value of integrating threat hunting into security strategies to stay ahead of evolving threats, thereby safeguarding organizational reputation and fostering consumer confidence.
Dec 14, 2022 2,691 words in the original blog post.
The text highlights the ongoing cybersecurity advancements and strategic initiatives undertaken by CrowdStrike as of September 2025, emphasizing innovations across various domains such as identity security, AI integration, and cloud protection. It underscores CrowdStrike's efforts in addressing GenAI data leaks and enhancing identity security with three key innovations, alongside notable achievements like the introduction of Threat AI, the first agentic threat intelligence system. Additionally, the text details the company's leadership recognition in managing detection response services, exposure management, and SaaS security posture, while also focusing on the architectural limitations and risks associated with Microsoft Active Directory, offering solutions through their Active Directory Risk Review. The narrative further illustrates the importance of proactive measures and comprehensive protection strategies to mitigate the risks posed by legacy systems and underscores the company's commitment to securing AI applications, protecting sensitive data, and optimizing security operations for enterprises and small businesses alike.
Dec 14, 2022 2,066 words in the original blog post.
The text provides an overview of CrowdStrike's recent developments and achievements in the cybersecurity domain, particularly emphasizing advancements tailored for the AI era. It highlights CrowdStrike's leadership recognition in cloud workload protection and exposure management, alongside innovations in identity security and agentic threat intelligence systems. The document also discusses the company's strategic acquisitions aimed at enhancing security for enterprise AI use and development, as well as significant improvements in machine learning model training. Additionally, it underscores the importance of a proactive threat detection and prevention approach through tools like Falcon Cloud Security and Falcon Next-Gen SIEM, which are designed to address modern cybersecurity challenges.
Dec 14, 2022 2,124 words in the original blog post.
The blog post from CrowdStrike emphasizes the importance of prioritizing vulnerabilities to enhance cybersecurity through their tool, Falcon Spotlight. It discusses the challenges organizations face in managing a vast number of vulnerabilities and highlights the effectiveness of automation and single-pane-of-glass solutions in overcoming these obstacles. The post describes how Falcon Spotlight's ExPRT.AI model uses threat intelligence to assess vulnerability criticality and adapt over time, thus reducing the workload by providing a more accurate picture of critical threats. Additionally, it stresses the need for organizations to prioritize assets based on their importance to the business and vulnerability to attacks, suggesting that a focused approach on high-value targets and known exploited vulnerabilities can significantly enhance security. The blog also underscores the importance of a tailored vulnerability management strategy that aligns with business goals and risk prioritization, advocating for a start-small approach to develop a comfortable process for organizations.
Dec 13, 2022 3,013 words in the original blog post.
CrowdStrike is widely recognized as a leader in cybersecurity, offering the Falcon platform, which provides comprehensive protection across various domains including endpoint detection and response (EDR), cloud security, and identity protection. The platform is celebrated for its cloud-native, single lightweight agent approach, making it efficient and cost-effective for infrastructure and maintenance. CrowdStrike's success and innovation in areas like AI, cloud security, and next-generation SIEM have garnered accolades from industry analysts and customers alike. With over 20,000 customers globally, the company is praised for its ability to effectively protect organizations from modern threats such as ransomware and data leaks. The positive feedback from customers, highlighted in industry events like Fal.Con, underscores the platform's reliability and effectiveness in addressing cybersecurity challenges. CrowdStrike continues to evolve its offerings, integrating advanced threat intelligence and machine learning capabilities, which solidify its position as a market leader in cybersecurity solutions.
Dec 13, 2022 1,933 words in the original blog post.
CrowdStrike has been recognized as a leader in several key cybersecurity areas, notably in the Forrester Wave™ for Managed Detection and Response Services in Europe for Q3 2025 and the 2025 IDC MarketScape for Worldwide Incident Response Services. The company is advancing its cybersecurity capabilities with projects like EMBER2024, aimed at improving machine learning models against evasive malware, and strengthening its AI security to combat a growing attack surface. CrowdStrike's strategic moves include acquiring Onum to enhance data-driven security operations and partnering with Microsoft to improve cyber threat attribution. The company is also addressing the global cybersecurity workforce shortage by leveraging managed security service providers and global system integrators while expanding its technological ecosystem through the Falcon platform to provide comprehensive protection across various domains.
Dec 09, 2022 1,574 words in the original blog post.
CrowdStrike's Falcon Complete Hub, a managed detection and response (MDR) solution, significantly enhances identity protection by addressing modern security challenges, particularly those involving compromised credentials, which account for nearly 80% of cyberattacks. This comprehensive platform integrates endpoint and identity security, offering real-time automated responses and a unified interface that improves the efficiency of security operations centers (SOC). A local government CISO in Washington, D.C. highlighted the transformative impact of Falcon Complete, emphasizing its ability to provide immediate value through real-time identity risk metrics, proactive identity analysis, and powerful policies that protect against identity-based attacks. The platform allows for seamless incident correlation between endpoint and identity activities, thus revolutionizing the way SOCs operate and enhancing overall security posture.
Dec 07, 2022 2,228 words in the original blog post.
CrowdStrike's latest advancements highlight its leadership in cybersecurity, particularly through its Falcon platform, which combines cutting-edge technology with human expertise to effectively detect, prevent, and respond to cyber threats. The platform's capabilities were demonstrated in the 2022 MITRE ATT&CK Evaluations for Security Managed Services Providers, where CrowdStrike achieved 99% detection coverage, showcasing its proficiency in identifying adversary techniques and ensuring rapid response through its Falcon Complete and Falcon OverWatch teams. The evaluation emphasized CrowdStrike's ability to integrate threat intelligence and human-led managed detection and response (MDR) to deliver superior protection and insight, albeit without testing its full prevention and remediation capabilities, which are standard components of Falcon Complete. Moreover, CrowdStrike's ongoing innovations span areas like AI security, cloud security, next-gen identity protection, and exposure management, further cementing its position as a frontrunner in the cybersecurity industry.
Dec 07, 2022 2,752 words in the original blog post.
CrowdStrike has been actively investigating a persistent intrusion campaign targeting telecommunications and business process outsourcing (BPO) companies, with a focus on gaining unauthorized access to mobile carrier networks and performing SIM swapping activities. The attacks typically begin with social engineering tactics, such as impersonating IT personnel through phone calls and messages to direct victims to credential-harvesting sites or to install remote monitoring and management (RMM) tools. This campaign, attributed with low confidence to the SCATTERED SPIDER eCrime adversary, showcases the adversary's persistence and adaptability, as they often implement additional persistence mechanisms like VPN access and multiple RMM tools if initial mitigation measures are slow. CrowdStrike emphasizes the importance of secure identity-based security measures, such as multifactor authentication (MFA) and robust authentication restrictions, to effectively combat these threats. The report highlights the use of various RMM tools by the adversary to maintain access, and the importance of swift containment and mitigation actions to disrupt their activities.
Dec 01, 2022 3,977 words in the original blog post.
CrowdStrike's cybersecurity platform continues to gain recognition for its robust protection capabilities and industry leadership, evidenced by its consistent top performance across various evaluations and its strategic advancements in AI and cloud security. Notably, the CrowdStrike Falcon platform achieved a perfect score in the AV-TEST macOS evaluations for three consecutive times in 2022, distinguishing itself as the only security vendor to do so. The platform employs a layered approach, utilizing both on-sensor and cloud-based machine learning to detect and protect against macOS malware without false positives, thereby maintaining high usability without disruption. Furthermore, CrowdStrike's commitment to transparency and rigorous third-party evaluations, such as the MITRE ATT&CK and AV-Comparatives, underscores its dedication to continuous improvement and innovation in defending against evolving cyber threats. The company's strategic initiatives include enhancing machine learning models to better withstand evasive malware and integrating AI capabilities to secure expanding attack surfaces, reinforcing its position as a leader in managed detection and response services in Europe and beyond.
Dec 01, 2022 1,902 words in the original blog post.