March 2023 Summaries
14 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
CrowdStrike's Falcon OverWatch team has identified a sophisticated method used by adversaries to exploit self-extracting (SFX) archive files to bypass security measures and establish persistent backdoors. These SFX archives, which are typically used for legitimate file sharing, can be engineered with hidden malicious functionality, often undetected by traditional antivirus software. By abusing WinRAR's advanced setup options, adversaries can configure these archives to run commands such as PowerShell or cmd.exe with elevated privileges, effectively creating a backdoor accessible from the Windows logon screen. This technique underscores the need for proactive threat hunting and detailed examination of SFX archives to identify potential security threats, as these methods are likely to remain effective due to their low detection rates and the ability to execute commands without containing overt malware.
Mar 31, 2023
2,717 words in the original blog post.
CrowdStrike's recent updates highlight its continued leadership in cybersecurity, as evidenced by its recognition as a leader in the 2025 IDC MarketScape reports for both Worldwide Incident Response Services and Exposure Management. The company is actively enhancing its security capabilities through strategic acquisitions, such as the planned acquisition of Onum, aimed at transforming data utilization within the Agentic Security Operations Center (SOC). CrowdStrike's Falcon platform is at the forefront of modern cybersecurity solutions, offering advanced protection against threats like the 3CXDesktopApp intrusion campaign by utilizing behavior-based indicators of attack and compromise. Additionally, CrowdStrike's commitment to innovation is underscored by its integration of artificial intelligence in threat detection and response, as well as its partnerships with major industry players, including a collaboration with Microsoft to harmonize cyber threat attribution.
Mar 29, 2023
2,074 words in the original blog post.
CrowdStrike has formed a strategic alliance with Dell Technologies to enhance cybersecurity accessibility and effectiveness, emphasizing the need for streamlined and cost-effective solutions that cater to diverse customer profiles and consumption models. This collaboration aims to simplify the purchasing and deployment of cybersecurity tools, addressing issues like product complexity and rising costs associated with traditional approaches. CrowdStrike's Falcon platform, available through Dell's global channels, offers consolidated security options designed to meet compliance and security needs across various industries, including small businesses and large enterprises. This partnership underscores the importance of integrating leading technologies and expert teams to provide robust defenses against modern cyber threats, as evidenced by CrowdStrike's repeated recognition as a leader in the cybersecurity space.
Mar 23, 2023
1,937 words in the original blog post.
CrowdStrike's blog highlights its innovative use of artificial intelligence and deep learning to enhance cybersecurity measures, particularly through the Falcon platform. The platform utilizes similarity search techniques to detect malware by analyzing PowerShell scripts for shared characteristics with known threats, drawing from the computer vision field to improve detection accuracy. By leveraging deep-learning-based feature descriptors and approximate nearest neighbor search, CrowdStrike can efficiently identify new malware variants, even as AI tools like ChatGPT potentially facilitate the generation of malicious code. This approach allows threat researchers to quickly respond to emerging threats and maintain high-quality intelligence reports, solidifying CrowdStrike's leadership in the cybersecurity industry.
Mar 23, 2023
3,284 words in the original blog post.
CrowdStrike's latest advancements focus on enhancing identity security through its Falcon platform, which integrates endpoint and identity protection to counter modern cyber threats. The platform introduces new capabilities such as honeytokens to divert adversaries, duplicate password detection to prevent credential stuffing attacks, and extended protocol coverage for detecting suspicious activities over Server Message Block (SMB). These innovations aim to provide comprehensive protection against identity-based attacks by allowing security teams to gain insights into adversary tactics and improve Active Directory security. The company emphasizes the importance of a unified security solution to protect against various attack vectors, including malware-free and identity-driven threats, while offering resources like Active Directory Risk Reviews to help organizations reduce their attack surface.
Mar 20, 2023
2,091 words in the original blog post.
CrowdStrike's report highlights the evolving tactics of eCrime adversaries in leveraging Microsoft OneNote documents to deliver malicious payloads, with a significant increase in such activities observed since early 2023. They detail how adversaries initially exploited Microsoft Office macro vulnerabilities before adapting to use OneNote files embedded with HTML Application (.HTA), Command (.CMD), and JavaScript Encoded (.JSE) files. These files execute embedded scripts to download second-stage payloads like QakBot, known for delivering additional malware such as Cobalt Strike. Despite Microsoft's efforts to patch vulnerabilities, adversaries continue to find new ways to achieve code execution, prompting CrowdStrike to recommend network defenders to baseline OneNote usage, block suspicious file types, and install endpoint detection systems like CrowdStrike Falcon. The report underscores the need for continuous adaptation and vigilance in cybersecurity practices to counteract the innovative tactics employed by threat actors.
Mar 17, 2023
3,106 words in the original blog post.
In early 2023, CrowdStrike identified the first Dero cryptojacking campaign targeting Kubernetes infrastructure, leveraging Dero's privacy-focused cryptocurrency features to appeal to cryptojacking groups. The campaign exploited Kubernetes clusters with anonymous access enabled, using a Docker image hosted on Docker Hub to deploy a "pause" binary for mining. Concurrently, a modified Monero cryptojacking campaign was detected, which targeted the same Kubernetes vulnerabilities and actively removed Dero-related processes to mine Monero instead. CrowdStrike's Falcon platform plays a critical role in defending against such sophisticated cryptojacking operations, using advanced machine learning and behavior-based indicators to detect and mitigate threats in real-time. The campaigns illustrate the ongoing battle between cryptojacking groups exploiting misconfigured Kubernetes environments, emphasizing the need for robust cloud-native application protection capabilities.
Mar 15, 2023
3,051 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity sectors, including Managed Detection and Response Services in Europe and Exposure Management, as highlighted by the Forrester Wave and IDC MarketScape reports for 2025. The company has been actively involved in addressing vulnerabilities through its Falcon Platform, which analyzes endpoint events globally, and has played a critical role in mitigating risks associated with critical vulnerabilities disclosed during Patch Tuesday updates. CrowdStrike's initiatives also extend to training cybersecurity ML models against evasive malware and tailoring adversary intelligence to customer environments. The company emphasizes the importance of a holistic cybersecurity approach, recommending regular review and improvement of security postures, and offers various solutions to enhance vulnerability management and identity protection. Additionally, CrowdStrike has made strides in AI security and cloud protection, leveraging innovations to strengthen defenses across diverse environments.
Mar 14, 2023
2,243 words in the original blog post.
CrowdStrike, a leader in cybersecurity solutions, has unveiled several significant advancements and initiatives aimed at enhancing data protection and threat intelligence capabilities. Among its recent developments, CrowdStrike introduced "Threat AI," the first agentic threat intelligence system, and advanced its identity security offerings with three new innovations. The company also announced measures to prevent GenAI data leaks through unified data protection and showcased its enhanced Falcon Cloud Security for safeguarding AI development. Additionally, CrowdStrike's Falcon platform, which integrates advanced threat intelligence, continues to redefine vulnerability management and incident response. The company has been recognized as a leader in various industry reports, reflecting its robust position in managed detection and response services and exposure management.
Mar 09, 2023
1,975 words in the original blog post.
The text highlights CrowdStrike's prominent position in the cybersecurity industry, emphasizing its consistent recognition as a leader in various independent evaluations and market reports. It discusses CrowdStrike's achievements, including being named a leader in the Forrester Wave™ for Managed Detection and Response Services in Europe, the IDC MarketScape for Worldwide Incident Response Services, and the GigaOm Radar for SaaS Security Posture Management. The company is commended for its advanced use of machine learning and artificial intelligence to enhance threat detection and prevention, reflecting its commitment to innovation and public collaboration through initiatives like the MITRE Engenuity Center for Threat-Informed Defense. CrowdStrike's Falcon platform is praised for its comprehensive security capabilities, achieving top scores in independent tests such as AV-TEST and SE Labs, and earning accolades from customer review sites for its endpoint protection solutions. The company's efforts in threat hunting, cloud security, and advancing AI models against malware are also underscored, demonstrating its dedication to maintaining a proactive defense against evolving cyber threats.
Mar 08, 2023
2,519 words in the original blog post.
The text provides a comprehensive overview of CrowdStrike's recent advancements and initiatives in cybersecurity, particularly highlighting their efforts in AI and cloud security, next-gen identity protection, and threat intelligence. Notably, CrowdStrike introduced Threat AI, the first agentic threat intelligence system, and enhanced their Falcon Cloud Security to prevent container escape attempts. They also addressed GenAI data leaks with unified data protection and made strides in identity security through key innovations. The Falcon OverWatch team has identified critical insights on living-off-the-land binaries (LOLBins), emphasizing the need for proactive threat hunting. Additionally, CrowdStrike's leadership in various sectors is underscored by their recognition as a leader in 2025 IDC MarketScape and their strategic acquisitions aimed at securing enterprise AI use and development.
Mar 07, 2023
1,590 words in the original blog post.
CrowdStrike has released a free tool named tf2rust, designed to help data scientists convert TensorFlow machine learning models into Rust code, thus optimizing performance and memory usage for deep learning models. The tool aims to enhance the deployment of ML models in resource-constrained environments by reducing computational costs and memory requirements, which are often challenges in deploying neural networks on devices like smartphones and laptops. The tf2rust tool allows for leaner builds without the dependency complexities of traditional frameworks, decreasing the attack surface and improving security. It also supports various neural layers and provides a command-line interface for ease of use. CrowdStrike encourages feedback and contributions from the community to further improve the tool, which is accessible on GitHub.
Mar 03, 2023
3,003 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple cybersecurity domains, including Managed Detection and Response Services in Europe, according to The Forrester Wave™ for Q3 2025, and in Worldwide Incident Response Services by IDC MarketScape for 2025. The company has also been acknowledged for its strength in endpoint security, with the CrowdStrike Falcon® Pro for Mac receiving the AV-TEST Best MacOS Security Product for Business award for 2022, due to its exemplary performance in detecting and protecting against macOS threats. Additionally, CrowdStrike is advancing its cybersecurity solutions by integrating AI and machine learning to enhance threat detection and response capabilities, as seen in their development of AI-powered threat detection and cloud detection services. Their commitment to rigorous third-party testing and continuous improvement is highlighted by their participation in various evaluations and awards, reinforcing their standing as a next-generation security platform provider.
Mar 02, 2023
2,023 words in the original blog post.
In September 2025, CrowdStrike was prominently featured in several cybersecurity developments, including the disclosure of two zero-day vulnerabilities and eight critical vulnerabilities among 84 Common Vulnerabilities and Exposures (CVEs) during the September Patch Tuesday. The company was also recognized as a leader in The Forrester Wave™ for Managed Detection and Response Services in Europe and the IDC MarketScape for Cloud Native Application Protection Platforms (CNAPP). CrowdStrike's advancements in AI and machine learning were highlighted with the EMBER2024 project, which aims to train cybersecurity models against evasive malware. Additionally, CrowdStrike announced its acquisition of Onum to enhance data-driven security operations, and its Falcon platform continued to be acknowledged for its endpoint protection capabilities, securing its position as a leader in the Gartner Magic Quadrant for Endpoint Protection Platforms. These recognitions underscore CrowdStrike's ongoing commitment to advancing cybersecurity technologies and its role in shaping the industry's future.
Mar 02, 2023
2,033 words in the original blog post.