February 2024 Summaries
15 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
ALPHA SPIDER, the group behind Alphv ransomware-as-a-service (RaaS), has been observed by CrowdStrike using innovative and varied techniques in ransomware operations over the past year. Affiliates of ALPHA SPIDER have exploited vulnerabilities such as NTFS Alternate Data Streams and network configuration tampering to evade detection and gain persistence within targeted networks. They have also been noted for their ability to perform attacks with speed, leveraging dual-purpose tools and legitimate user accounts to conduct malicious activities. Despite their sophisticated methods, these affiliates often lack rigorous operational security measures, which provides defenders opportunities to detect and mitigate threats. CrowdStrike's investigations have highlighted their persistent efforts to exfiltrate data using multiple methods and tools, underscoring the need for robust endpoint protection and timely incident response to counteract their activities effectively.
Feb 29, 2024
3,129 words in the original blog post.
The State of Wyoming has embraced the CrowdStrike Falcon XDR platform to enhance its cybersecurity measures amid a growing business environment and increased cyber risks. Initially, the state's Enterprise Technology Services (ETS) sought a modern solution to replace outdated antivirus software that failed to detect threats effectively. The CrowdStrike platform was chosen for its AI-powered detection capabilities and seamless deployment, leading to a successful transformation of Wyoming's endpoint security. This transition included the adoption of CrowdStrike Falcon Complete for 24/7 managed detection and response, providing a significant boost to the state's internal cybersecurity team. The consolidation of cybersecurity tools under the Falcon platform not only improved the state's ability to thwart identity-related attacks but also offered cost savings and operational efficiencies. With seven years of breach-free security performance, Wyoming is now working with CrowdStrike to extend protections statewide, aiming to integrate cybersecurity efforts across various government levels to safeguard citizen data and digital infrastructure.
Feb 28, 2024
1,960 words in the original blog post.
CrowdStrike is leveraging advancements in AI and hardware innovations, particularly through collaboration with Intel, to enhance cybersecurity measures, specifically in endpoint security. By integrating Intel's neural processing unit (NPU) in Core Ultra processors, CrowdStrike aims to efficiently deploy AI models directly on endpoints, reducing the need for cloud-based analysis and minimizing CPU usage. This breakthrough allows for real-time detection of malicious scripts and fileless malware, which constitute a significant portion of cyberattacks. The enhanced capability enables more dynamic decision-making on data upload to the cloud, optimizing resource allocation and reducing network traffic. This collaboration exemplifies how AI-driven solutions can transform endpoint security, opening up new possibilities for advanced cybersecurity applications.
Feb 27, 2024
2,452 words in the original blog post.
CrowdStrike highlights the benefits of cybersecurity consolidation through its Falcon XDR platform, as shared by panelists from Ciena, Cox Automotive, and Sunbelt Rentals in a recent virtual discussion. The consolidation addresses the complexities and inefficiencies of managing multiple security tools by integrating existing systems, ultimately leading to improved operational efficiency, reduced costs, and enhanced security outcomes. Panelists emphasized the importance of strategic partnerships with technology providers like Okta and Zscaler, which facilitate seamless integration and provide a more streamlined approach to threat intelligence sharing. The discussion revealed that this consolidation approach not only simplifies security management but also reduces the need for additional headcount, demonstrating a reliance on technology to manage growth and complexity effectively. The panelists praised the Falcon platform's ability to enhance visibility, decrease response times, and provide a more cohesive ecosystem for cybersecurity, ultimately leading to a more robust and efficient security posture for their organizations.
Feb 26, 2024
2,103 words in the original blog post.
The blog post from CrowdStrike provides an in-depth analysis of various eCrime malware families targeting Latin America, with updates on key malware strains such as Mispadu, Kiron, Caiman, Culebra, Salve, and Astaroth. These malware families have been actively evolving throughout 2023, with new components and obfuscation methods to enhance their defense evasion capabilities. The post highlights the use of CAPTCHAs and other anti-analysis techniques, suggesting a knowledge exchange among developers. It also discusses the connections between the Mispadu and Astaroth malware, indicating possible shared origins or techniques. The post concludes with recommendations for avoiding eCrime commodity malware infections, emphasizing caution with emails from untrusted sources and ensuring software is downloaded from legitimate sources, along with the importance of browser settings that enable download protection.
Feb 22, 2024
4,803 words in the original blog post.
CrowdStrike's 2024 Global Threat Report highlights the evolving landscape of cybersecurity threats, emphasizing the increasing speed and sophistication of adversaries' tactics. The report notes a significant reduction in eCrime breakout times, with an average of just 62 minutes in 2023, and a shift towards malware-free attacks, relying heavily on credential phishing and social engineering. Identity-based intrusions, particularly in cloud environments, surged by 75%, underscoring the importance of protecting identities to prevent breaches. CrowdStrike has expanded its adversary tracking to include over 230 groups, with 34 new ones identified in 2023. The report also explores the potential for generative AI to democratize cyberattacks and the threat of nation-state actors disrupting global elections through misinformation. CrowdStrike introduces new products under the Falcon Adversary Modules to enhance threat detection and response, leveraging AI-powered threat intelligence to combat adversaries more effectively. The report concludes with a call for understanding adversary tactics to better protect organizations against modern threats.
Feb 21, 2024
1,869 words in the original blog post.
CrowdStrike is recognized as a leader in cybersecurity, particularly for its advanced protection of macOS devices against a wide range of threats, including malware and ransomware. It has garnered accolades such as the AV-Comparatives Approved Mac Security Product award for its Falcon Pro for Mac, which demonstrated 100% protection without performance drawbacks during testing. The company's commitment to the Mac community is further emphasized through its sponsorship of the Mac Admins Foundation, which supports a global network of IT professionals specializing in Apple hardware and software. This sponsorship aligns with CrowdStrike's ethos of innovation and collaboration, as both the company and the community strive to enhance security and technological advancement. Additionally, CrowdStrike's ongoing research and participation in third-party testing underscore its dedication to safeguarding against evolving cyber threats, making it a trusted partner for businesses utilizing macOS in their operations.
Feb 15, 2024
1,720 words in the original blog post.
CrowdStrike has been recognized as a leader in several key areas of cybersecurity, including Managed Detection and Response Services in Europe and Worldwide Incident Response Services, according to reports from Forrester and IDC MarketScape in 2025. The company is advancing its cybersecurity capabilities through innovative approaches such as AI-native threat detection and integration with Dell's SafeGuard and Response portfolio, enhancing visibility and security for devices running ChromeOS, Linux, macOS, and Windows. CrowdStrike's Falcon platform provides comprehensive cross-platform coverage, enabling organizations to address modern security challenges associated with hybrid and remote work environments by leveraging AI-powered detection, response capabilities, and seamless integration without impacting device performance. The collaboration with Dell aims to simplify and consolidate the security stack, offering superior protection and speed to meet evolving workplace security needs while maintaining effective threat detection and response capabilities.
Feb 14, 2024
1,514 words in the original blog post.
CrowdStrike's recent developments and recognitions highlight its leadership in cybersecurity, particularly through its Falcon platform. The company has been acknowledged as a frontrunner in vulnerability management by IDC MarketScape and Gartner's "Voice of the Customer" for its proactive and efficient Falcon Exposure Management tool, which simplifies deployment and minimizes maintenance compared to legacy systems. CrowdStrike's security innovations include advancements in AI, cloud security, and identity protection, as well as the introduction of Threat AI, an agentic threat intelligence system. The company's commitment to addressing complex challenges in cybersecurity is further demonstrated by its strategic acquisitions to enhance AI security and its comprehensive approach to data protection, as seen in its efforts to prevent GenAI data leaks.
Feb 14, 2024
2,029 words in the original blog post.
CrowdStrike is making significant advancements in cybersecurity, particularly in the AI era, by introducing innovative solutions across various domains such as cloud workload protection, identity security, and exposure management. The company has been recognized as a leader in multiple categories, including the Frost Radar for Cloud Workload Protection Platforms and the IDC MarketScape for Exposure Management. Their Falcon platform is pivotal in managing vulnerabilities and improving security posture through comprehensive endpoint data analysis and protection against diverse cyber threats, including zero-day vulnerabilities. CrowdStrike continues to enhance its offerings with strategic acquisitions and partnerships, aiming to secure AI development and deployment across enterprises. The company also emphasizes the importance of adapting cybersecurity strategies to address evolving threats and vulnerabilities in the digital landscape.
Feb 13, 2024
2,193 words in the original blog post.
The CrowdStrike blog post outlines the company's leadership in cybersecurity, emphasizing its recognition as a leader in multiple industry reports and its commitment to advancing security technology. CrowdStrike is highlighted as a leader in The Forrester Wave and IDC MarketScape reports for managed detection and response services and incident response services, respectively. The blog also discusses the challenges of securing cloud-native applications, noting that a significant portion of major code changes fail to undergo full security reviews, which increases vulnerability risks. Despite the use of multiple security tools, organizations struggle with prioritizing application vulnerabilities and gaining visibility into applications and APIs. The post emphasizes the need for improved efficiency and automation in application security to counter modern threats and describes CrowdStrike's acquisition of Bionic to enhance its cloud-native application protection platform (CNAPP). Additionally, the blog underscores the complexity of modern applications and the necessity for a comprehensive approach to application security, with insights drawn from the CrowdStrike 2024 State of Application Security Report.
Feb 12, 2024
1,808 words in the original blog post.
The text discusses CrowdStrike's strategies and achievements in enhancing cybersecurity for business-critical applications, highlighting its recognition as a leader in various industry reports, such as the 2025 IDC MarketScape for Worldwide Incident Response Services and Exposure Management. It emphasizes the importance of protecting sensitive data within applications, suggesting measures like secure digital infrastructure, restricted access permissions, and proactive monitoring for suspicious activities. Moreover, CrowdStrike's acquisition of Onum aims to transform data usage in security operations centers (SOCs), and its AI-native Falcon platform offers comprehensive protection, including cloud misconfiguration detection and runtime protection. The text also mentions the significance of improving security testing in the software development pipeline and maintaining a constant measurement of production risk posture to safeguard against vulnerabilities and cyber threats.
Feb 09, 2024
2,562 words in the original blog post.
CrowdStrike has been recognized as a leader in several categories by the IDC MarketScape and GigaOm Radar in 2025, highlighting its prominence in incident response, exposure management, and SaaS security posture management. The company has also announced the acquisition of Onum to enhance data-driven capabilities for its agentic security operations center (SOC). In addition, CrowdStrike's latest research delves into the sophisticated evasion techniques of the HijackLoader malware, which employs advanced methods like process hollowing and transacted hollowing to bypass security measures. The company's Falcon platform continues to offer robust malware detection through machine learning and behavior-based detection capabilities, with a focus on AI-powered threat detection and endpoint protection. CrowdStrike's strategic advancements and recognitions underscore its commitment to providing comprehensive cybersecurity solutions across various sectors, including cloud and application security, public sector, and small business protection.
Feb 07, 2024
3,671 words in the original blog post.
CrowdStrike's blog post delves into the potential security risks and abuse of Microsoft Azure's cross-tenant synchronization (CTS) feature, introduced in May 2023. This feature facilitates the automation of user/group management across different tenants, allowing seamless access to various applications. However, adversaries can exploit CTS by acquiring specific roles and privileges, enabling lateral movement between tenants or establishing persistent backdoors. The post outlines two primary attack paths: lateral movement and identity backdoor creation, detailing how attackers can misuse CTS for unauthorized access and persistence in compromised tenants. CrowdStrike Falcon Cloud Security offers tools to detect and mitigate such vulnerabilities, providing indicators of attack and best practice recommendations to secure Azure environments. These recommendations include monitoring external identities, securing CTA policies, and maintaining vigilance over administrator roles to prevent potential abuse.
Feb 05, 2024
3,372 words in the original blog post.
CrowdStrike is recognized as a leader in the managed detection and response services sector, according to The Forrester Wave™ report for Europe in Q3 2025, and in the 2025 IDC MarketScape for worldwide incident response services. The company is actively advancing the cybersecurity landscape through initiatives like EMBER2024, which focuses on training machine learning models to counter evasive malware, and developing AI-powered threat detection capabilities. CrowdStrike's acquisition of Bionic in 2023 has enhanced its application security posture management (ASPM) offerings, providing comprehensive risk visibility across cloud infrastructures and applications. The company's commitment to innovation is evident in its integration of AI and machine learning to defend against an expanding array of cyber threats, ensuring robust protection for organizations' digital ecosystems.
Feb 02, 2024
1,791 words in the original blog post.