Big Tech

CrowdStrike's SafeMind and the Race to Automate Defense Against AI Threats

At its Fal.Con conference, CrowdStrike unveiled SafeMind, a family of AI security models built with Nvidia, as attackers using AI agents have compressed intrusion timelines to seconds. The company is positioning automation and ecosystem partnerships as the path to defending at machine speed.

8 min read
Four insights you might have missed from theCUBE’s coverage of CrowdStrike’s Fal.Con

Artificial intelligence has fundamentally altered the threat landscape for enterprise security. Attackers leveraging AI can now breach an organization and move laterally within it in mere seconds, leaving defenders with virtually no time to mount a response. This acceleration of the attack timeline dominated discussions at CrowdStrike Holdings Inc.'s Fal.Con event, where the company's president, chief executive officer and founder George Kurtz outlined the company's strategy for fighting back against AI-driven threats.

The compression of what security researchers call "breakout time"—the interval between initial compromise and lateral movement—has been dramatic. According to theCUBE Research's Dave Vellante, Kurtz has tracked this metric year after year at Fal.Con, watching it shrink from two minutes to 72 seconds, then to 30 seconds. "And now he's like, it's done. It's just runtime. There is no breakout time," Vellante observed.

https://www.youtube.com/embed/eF7B0XE9cCc?feature=oembed

CrowdStrike's "2026 Global Threat Report" documented an average eCrime breakout time of 29 minutes, with the fastest recorded attack completing in just 27 seconds, according to Michael Sentonas, president of CrowdStrike. "I've never seen anything like it. I've never seen anything move so fast," Sentonas said. "That's all happening on one side. On the other side … I think it's fascinating. It's so exciting. There's so much possibility. There's so much we can do. Unfortunately, the benefit we get is also the benefit the attacker gets. That's kind of that challenge that we have right now."

To address this challenge, CrowdStrike introduced SafeMind at Fal.Con, a collection of security-focused AI models developed in collaboration with Nvidia Corp. The initiative represents the first major output from CrowdStrike's Cyber Superintelligence Lab, which the company describes as a frontier AI research organization dedicated to staying ahead of AI-driven threats. "What we did is we created bespoke models that were built for defenders," Kurtz explained. "Obviously we have an offensive model as well, which is needed. What we wanted to do was to give choice to customers."

https://www.youtube.com/embed/0hS7Lk3Huws?feature=oembed

Red and Blue Teaming at Scale

SafeMind consists of two distinct AI models: Red Tempest and Blue Solano, both trained on CrowdStrike incident data and built atop Nvidia's Nemotron family of models. The dual-model approach reflects CrowdStrike's belief that defenders need access to the same advanced capabilities that attackers possess. Daniel Bernard, chief business officer of CrowdStrike, noted that frontier AI models have primarily benefited adversaries. "It's time for the defenders to have something, and it's time for security to have its own model," he said.

Red Tempest operates by scanning a digital representation of a customer's environment to identify potential attack pathways. Blue Solano then identifies and remediates the vulnerabilities that Red Tempest discovers. Justin Boitano, vice president and general manager of enterprise computing at Nvidia, described the iterative process: "The digital twin describes the environment of the actual world. You run the red agent through the environment and you'll find different ways in to exfiltrate data. Then the blue agent will come in and write rules that would have detected or prevented the red attack agent from getting through. That iterative loop basically hardens the environment."

https://www.youtube.com/embed/G_32SXOVbXE?feature=oembed

The Speed of Agentic Threats

The emergence of autonomous AI agents as attack vectors has accelerated the threat timeline beyond what human attackers can achieve. Adam Meyers, senior vice president of intelligence at CrowdStrike, highlighted the scale of this shift. "The stat that's most interesting is we had something like 26 agentic adversaries that we were tracking in the last 30 days," he said. "That's more than we were tracking in the year before that."

One documented case illustrated the velocity of agentic attacks. "In 58 minutes, VAULT PANDA had conducted 1,100 commands. It was an agent that was doing it, and we were watching it learn in real time," Meyers recounted. "When I talk about breakout time from our global threat report, we were talking this year about 29 minutes on average, 27 seconds was the fastest. I'm talking about an entire intrusion operation conducted in minutes from start to finish."

https://www.youtube.com/embed/XdYWIwBq-nM?feature=oembed

Organizations deploying AI agents across their infrastructure without adequate governance have compounded the problem. Cristian Rodriguez, field chief technology officer of the Americas at CrowdStrike, described the challenge: "They're calling us saying, we have a problem, the AI sprawl is real, we know it's in our SaaS apps, we know it's on our endpoints, we know it's in our cloud instances. [They are saying] help us get our arms around visibility and governance programs and control, because we've bitten off a little more than we can chew."

Heather Ceylan, Box Inc.'s chief information security officer, emphasized the operational impact. "Attack surface is the same, but it's not just humans who are the attackers anymore," she said. "It's agents and they move at machine speed. So everything got faster. Our detections need to be faster, our visibility needs to be real time."

https://www.youtube.com/embed/do-m7W3iGrE?feature=oembed

Data Loss Prevention Reimagined

The proliferation of AI assistants and chatbots in enterprise environments has created new vectors for data exfiltration. On-device AI security models can intercept sensitive information before it leaves the endpoint—for instance, when an employee pastes proprietary data into a chatbot. Todd Cramer, senior director of business development and security ecosystem at Intel Corp., highlighted a concrete implementation: "This year, we have Falcon data security from CrowdStrike announcing their first AI model that runs on an Intel NPU on a Dell device. It's the right time in the use case, because we've got all these AI assistants, chatbots. What's the first thing CISOs are worried about? Data."

https://www.youtube.com/embed/9Xwwu7aWVXA?feature=oembed

Dell Technologies is developing hardware telemetry solutions that provide comprehensive visibility across the entire technology stack. Lori Zwilling, senior director of software product management at Dell Technologies Inc., described the scope: "Not only are analysts seeing the endpoint behavior, but they also can see what's happening with AI models, the data, the inferencing, the actual containers, the compute that's powering the AI for the enterprise. We're talking about full-stack AI security now."

Traditional data loss prevention tools have struggled to scale effectively, relying on pattern matching and rule-based systems. Jazz Inc., which won the 2026 Cybersecurity Startup Accelerator from CrowdStrike and Amazon Web Services Inc., has taken a different approach. Ido Livneh, co-founder and chief executive officer of Jazz, explained: "We didn't build yet another pattern match or another rule-based system. We completely upturned the whole challenge with our approach, which is building an investigator, a context-first, business-first investigator that understands your business, understands not only what is happening with the data flows, but why it's happening, the intent, and solving it through that."

https://www.youtube.com/embed/eMoV0gGTlpY?feature=oembed

CJ Moses, chief information security officer and vice president of security engineering at Amazon, acknowledged the historical limitations of DLP solutions. "In my experience, DLP providers have never done what DLP actually, the acronym, stands for. They've never done the data loss prevention," he said. "With basically AI now being a thing that actually will allow you to be able to deal with the large scale of the information and how they've implemented was kind of game changing for us."

Building an Ecosystem for Automated Defense

https://www.youtube.com/embed/SimnTGmj4DA?feature=oembed

CrowdStrike's Cyber Superintelligence Lab aims to develop technology that automates security tasks at the speed required to counter modern threats. Kurtz articulated the vision: "Part of why we started the Cyber Superintelligence Lab is to be able to build these sort[s] of technologies so that we can get to a level of automation where the car drives itself. Maybe the human has to be in the loop, and if something's really critical, fine. If you can automate the most mundane task and you can do it with the speed at which the adversary is moving, that's going to be critical."

https://www.youtube.com/embed/FTAOHqN6GZE?feature=oembed

Bartley Richardson, chief AI and autonomous systems officer at CrowdStrike, framed the lab's broader mission. "The real remit of the lab is the commoditization of defense capabilities. It is [turning] the best offense into that disproportionately advantaged defender-like capability," Richardson said. "How are we improving other areas in the industry itself? What can we contribute back?"

Strategic partnerships are central to this effort. CrowdStrike's Project QuiltWorks brings together technology companies, law firms, consultancies and other organizations to identify and remediate security vulnerabilities surfaced by AI models. Amanda Adams, senior vice president of global alliances at CrowdStrike, described the initiative: "QuiltWorks is a coalition of folks and partners who join us; they leverage our platform. We announced yesterday Falcon IQ, and this is a tool built on AWS that allows a partner to essentially drive an assessment and highlight the opportunities, the priorities. It's using AI to accelerate the time from discovery to remediation down to minutes."

https://www.youtube.com/embed/zVHic9q2sMw?feature=oembed

The partnership between CrowdStrike and Amazon Web Services has deepened as the technology landscape has evolved. Mona Chadha, director of strategic partnerships and category growth at Amazon Web Services Inc., reflected on the trajectory: "Over the decade, what we continued to do was build innovations together. We've evolved from machine learning to generative AI to now agentic and building these agents. There's a lot of opportunity there, but there [are] also a lot of threats."

https://www.youtube.com/embed/videoseries?list=PLK5JkEj2_qlo

Source: SiliconANGLE · Reporting supplemented by The Silicon Ledger staff.