November 2023 Summaries
14 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
CrowdStrike has made significant strides in cybersecurity by securing multiple accolades at AWS re:Invent 2023, including the Public Sector Partner of the Year, emphasizing its role in cloud-based solutions for various sectors. As a launch partner for AWS Built-in, CrowdStrike has achieved competencies in the security category and container environments, showcasing its integration with AWS services to automate and enhance cloud security deployment. Their Falcon Cloud Security leverages both agent-based and agentless detection to provide comprehensive visibility and protection for cloud assets, addressing risks such as misconfigurations and software vulnerabilities. This approach enables businesses to deploy security solutions rapidly and efficiently, aligning with AWS's security standards and addressing the evolving threat landscape in cloud environments.
Nov 30, 2023
2,185 words in the original blog post.
CrowdStrike's blog highlights its recognition as a leader in various cybersecurity domains, notably in the Forrester Wave for Managed Detection and Response Services and IDC MarketScape for Worldwide Incident Response Services in 2025. The blog emphasizes the company's continuous efforts to advance cybersecurity measures through innovative AI and machine learning applications, including the EMBER2024 initiative to improve cybersecurity ML models against evasive malware. It discusses the impact of the U.S. Executive Order on AI, emphasizing the document's balanced approach to innovation and security and its implications for industry best practices. CrowdStrike's commitment to AI-driven cybersecurity solutions, particularly through its Falcon platform, is underscored as a means to enhance threat detection and response capabilities. The blog also touches on the company's involvement in public policy discussions and its strategic moves, such as acquiring Onum, to bolster its security operations.
Nov 21, 2023
2,187 words in the original blog post.
The blog post discusses the significance of security automation in enhancing cybersecurity operations, particularly through the use of CrowdStrike's Falcon Fusion platform. The increasing sophistication and speed of cyberattacks necessitate the adoption of automated workflows to improve the efficiency and accuracy of security teams. By integrating various security tools into a single platform, Falcon Fusion allows for streamlined incident response and threat investigation, reducing the complexity of managing multiple tools and alleviating analyst burnout. The platform's no-code interface and pre-built playbooks enable security teams to quickly develop and implement automated processes, ultimately aiming to decrease the mean time to respond (MTTR) to threats. This approach emphasizes the need for well-defined security processes to maximize the benefits of automation in protecting organizations against adversaries.
Nov 20, 2023
2,040 words in the original blog post.
CrowdStrike's unified, AI-native Falcon platform offers comprehensive endpoint and identity security solutions to combat modern cyber threats, particularly those involving the misuse of legitimate credentials. The platform emphasizes the importance of integrating endpoint and identity protection to prevent identity-based attacks, which are increasingly prevalent due to the rise in remote work and supply chain vulnerabilities. By using a single agent that provides complete visibility into user behavior and risk-based responses, the Falcon platform enables organizations to effectively detect and respond to threats in real-time. The platform's unified approach, combining endpoint telemetry with identity intelligence and threat data, enhances security operations center efficiency and provides robust defense against adversaries. CrowdStrike's solutions have been recognized as leading in various industry reports, underscoring their effectiveness and innovation in cybersecurity.
Nov 17, 2023
2,250 words in the original blog post.
The blog post discusses the distinctions and security measures associated with custom-developed software and commercial off-the-shelf (COTS) software. Custom-developed software is proprietary and created in-house to meet specific business needs, with security beginning at the design phase and continuing through agile development, using tools like software composition analysis and static application security testing to detect vulnerabilities. Conversely, COTS software is commercially available without access to its source code, requiring organizations to conduct thorough security reviews of vendors and manage user access and data transfers diligently. The post emphasizes the importance of application security posture management (ASPM) in both contexts to maintain visibility and manage risks effectively. CrowdStrike provides tools like Falcon Cloud Security and Falcon Data Protection to aid in securing both types of software by offering insights into software usage and preventing data loss.
Nov 17, 2023
2,550 words in the original blog post.
CrowdStrike's blog discusses the increased threat posed by access brokers during the holiday season, highlighting their role in the eCrime ecosystem by selling victim access to other cybercriminals. The blog explains that these brokers exploit seasonal staffing changes and distractions to launch social engineering campaigns, harvest credentials, and facilitate ransomware attacks. CrowdStrike observed a 147% rise in access broker advertisements from mid-2022 to mid-2023, indicating their growing prevalence. To combat these threats, organizations are advised to strengthen identity protection, enhance cloud security, and invest in threat intelligence to understand adversaries better. The blog underscores the importance of preparedness through regular security exercises and monitoring for suspicious activity to mitigate risks associated with access brokers, ensuring a secure holiday season.
Nov 16, 2023
2,642 words in the original blog post.
CrowdStrike has made significant advancements in cybersecurity, emphasizing the protection of AI development and data security. The company recently introduced the Falcon Cloud Security to prevent container escape attempts and improve runtime capabilities, as well as a unified data protection strategy to curb data leaks from generative AI. Notably, CrowdStrike has launched Threat AI, the first agentic threat intelligence system, and advanced identity security through three key innovations. Additionally, they have been recognized as a leader in various cybersecurity sectors, including exposure management and managed detection and response services. The firm continues to enhance its offerings with acquisitions aimed at securing AI use and enterprise data, while also addressing the evolving threat landscape through comprehensive threat hunting and vulnerability management strategies.
Nov 15, 2023
1,958 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple cybersecurity categories, including the Forrester Wave™ for Managed Detection and Response Services in Europe and the IDC MarketScape for Worldwide Incident Response Services. The company has launched Falcon Go, an AI-powered cybersecurity solution tailored for small and medium-sized businesses (SMBs), addressing the high cyber risks these businesses face due to limited resources and outdated antivirus solutions. Falcon Go offers award-winning protection against ransomware and malware, leveraging machine learning and behavioral detection for a user-friendly experience. Available on Amazon Business, it allows SMBs to quickly purchase and deploy cybersecurity measures, ensuring they can effectively combat modern cyber threats without extensive technical expertise. CrowdStrike's broader initiatives include advancing machine learning models to counter evasive malware, enhancing cloud security, and integrating AI to bolster security operations.
Nov 14, 2023
1,686 words in the original blog post.
Securing the Generative AI Boom: How CoreWeave Uses CrowdStrike to Secure Its High-Performance Cloud
CoreWeave, a specialized GPU cloud provider, has implemented CrowdStrike's Falcon Cloud Security to enhance the security of its cloud infrastructure and customer workloads, as presented at Fal.Con 2023. CoreWeave needed a scalable and efficient security platform that would not hinder its high processing power, and after a successful proof of concept, it deployed the Falcon sensor across all worker nodes. This deployment provides complete visibility and protection, enabling CoreWeave to detect, investigate, and triage potential threats efficiently. The unified Falcon platform, which consolidates endpoint-to-cloud protection, helps CoreWeave respond to threats quickly, reduce complexity, and streamline processes, saving significant time in threat management. By leveraging CrowdStrike's threat intelligence, CoreWeave can understand and mitigate adversaries targeting its infrastructure, thus supporting its role in powering the generative AI boom.
Nov 13, 2023
1,905 words in the original blog post.
CrowdStrike's Intelligence team has been investigating a series of cyberattacks attributed to the Iran-linked adversary group known as IMPERIAL KITTEN, focusing on sectors such as transportation, logistics, and technology. The group's methods include strategic web compromise (SWC) operations, phishing attacks using malicious Excel documents, and leveraging public scanning tools and stolen credentials for initial access. IMPERIAL KITTEN utilizes a variety of custom and open-source malware, such as IMAPLoader and StandardKeyboard, which use email for command and control (C2) communication. Their operations also involve exploiting vulnerabilities to achieve lateral movement and data exfiltration, with a notable focus on Israeli organizations. Despite some low-confidence assessments due to reliance on single-source reporting, the group's activities demonstrate a strategic alignment with Iranian intelligence objectives, likely fulfilling requirements associated with the Islamic Revolutionary Guard Corps (IRGC).
Nov 09, 2023
3,259 words in the original blog post.
The text provides an overview of CrowdStrike's recent achievements and initiatives in cybersecurity, highlighting its recognition as a leader in various industry reports, such as The Forrester Wave™ and IDC MarketScape. It discusses the company's advancements in machine learning models for malware detection, the launch of new AI security services, and efforts to enhance cloud and endpoint security. The text also underscores the importance of making a strong business case for managed detection and response (MDR) services, emphasizing the need for clear ROI calculations and the benefits of increased threat analyst capacity, risk reduction, and platform consolidation. Additionally, it mentions the development of an ROI Calculator to assist organizations in quantifying the financial benefits of adopting MDR solutions. The narrative underscores CrowdStrike's commitment to innovation and leadership in cybersecurity, with a focus on providing robust protection and expertise across various sectors.
Nov 08, 2023
2,554 words in the original blog post.
CrowdStrike has reported a rise in attacks exploiting federated identity providers, which are outside services trusted by organizations for user authentication and identity management, typically used in single sign-on scenarios. Attackers are compromising these providers to manipulate settings, allowing unauthorized domains and users under their control to gain access to protected resources. This trend underscores the importance of monitoring identity provider configurations for unauthorized changes, as these attacks often target Microsoft Azure domains. CrowdStrike has developed detection mechanisms within its Falcon Cloud Security platform to identify suspicious activities indicative of such attacks, allowing organizations to respond quickly and prevent potential breaches. The blog emphasizes that while these attacks leverage legitimate cloud services, a timely and informed response can effectively disrupt the adversarial access and protect sensitive data.
Nov 08, 2023
3,400 words in the original blog post.
CrowdStrike has been recognized as a leader in several cybersecurity areas by the IDC MarketScape in 2025, including incident response services and exposure management. The company is enhancing its cybersecurity capabilities with strategic initiatives like acquiring Onum to transform data usage for its agentic Security Operations Center (SOC) and advancing its AI-driven tools to protect against evolving threats. CrowdStrike's Falcon platform integrates multiple security functions, such as vulnerability management and identity security, into a unified system, enabling organizations to proactively manage risks and reduce their external attack surfaces. The platform's approach emphasizes bridging the gap between security and IT teams, fostering collaboration to streamline and enhance security measures. These advancements underscore CrowdStrike's commitment to stopping breaches by leveraging AI, threat intelligence, and real-time security data.
Nov 07, 2023
2,142 words in the original blog post.
The text highlights CrowdStrike's achievements and innovations in cybersecurity, focusing on its Falcon platform's exemplary performance in the 2023 SE Labs Enterprise Advanced Security (EDR) Ransomware test, where it achieved a 100% ransomware protection rating and a 100% EDR rating. The blog emphasizes the importance of independent third-party testing as a key resource for making informed purchasing decisions by assessing cybersecurity solutions under real-world scenarios. Additionally, the text outlines CrowdStrike's continued commitment to advancements in AI, cloud security, identity protection, and threat intelligence, underscoring its leadership position in the cybersecurity industry. The Falcon platform's cloud-native architecture, combined with machine learning and artificial intelligence, is credited with effectively preventing breaches and stopping sophisticated cyber threats.
Nov 06, 2023
2,030 words in the original blog post.