SoS Logo

CrowdStrike: Frontier AI for Cybersecurity

How CrowdStrike gave us meaningful advancements in cybersecurity-focused AI and why this has the ingredients to work at scale.

Sep 24
Public Companies
crowdstrike-frontier-ai-for-cybersecurity

Sometimes you know in the moment that you're part of something special.

I’ve experienced a World Series, Super Bowl, Rose Bowl, Final Four, weddings, college and (most recently) pre-school graduations, plus all kinds of other life events.

CrowdStrike's Fal.Con conference earlier this month was right up there with all of them. It was electric, like cybersecurity's Lollapalooza. My sense is that everyone there felt the same.

I think the world changed in a meaningful way that week because of SafeMind and Guardian, the AI security headliners CrowdStrike announced. In hindsight, their timing couldn't have been better.

The debate over frontier AI safety, alignment, and pacing intensified beyond imagination in the days since then. You already knew that — it's impossible to miss.

I like to draw upon timeless wisdom in situations like this. Charlie Munger's concept of Lollapalooza effects explain the current frenzy in psychological terms.

His point was about the outsized consequences of several forces reinforcing one another. That's a pretty useful way to think about today's moment in AI. Among many forces, we have increasingly capable models, pressure to adopt them, and both humans and agents misusing them.

He also warned that Lollapalooza effects "can make you rich, or they can kill you."

Let me rephrase that slightly: AI can make you rich, or it can kill you.

Munger's thoughts on Lollapalooza effects sound eerily familiar to the moment we're in right now.

Leaders like Sam Altman and Dario Amodei both recognize the simultaneous upside and danger of AI. The question is how we can maximize the upside and minimize the downside. That's the actionable part.

In Dario Amodei's "The Adolescence of Technology" article (linked above), he says something especially relevant to our discussion here:

The offense-defense balance may be more tractable in cyber, where there is at least some hope that defense could keep up with (and even ideally outpace) AI attack if we invest in it properly.

Investment in defenses helps determine which future we get.

I fully agree with George Kurtz: there’s no going back. The threats are already here, and we need frontier AI for cybersecurity now.

That's the context for why I think CrowdStrike's AI announcements matter so much. They put the people, research, data, products, and partnerships together to give defenders the best tools we’ve ever had.

Let’s start by talking about what they announced.

SafeMind and Guardian: Frontier AI for defenders and agents

CrowdStrike’s two major AI announcements from Fal.Con were SafeMind and Falcon Guardian.

SafeMind addresses AI for security: models and harnesses that help defenders carry out security work. Guardian addresses security for AI: visibility and controls over the agents organizations put to work.

CrowdStrike’s broader objectives here are using AI to strengthen defense and strengthening security so organizations can use AI. SafeMind and Guardian address those distinct needs within the same foundational strategy.

SafeMind combines models and harnesses to execute the tasks defenders need done: testing security controls, developing protections, and carrying out remediation.

It pairs offensive models (Red Tempest) with defensive models (Blue Solano), specialized harnesses, and controlled cyber environments for testing. These are actually families of models and purpose-built harnesses, not just a single model.

Red Tempest pursues attack objectives through multiple stages, including exploitation, privilege escalation, lateral movement, and persistence. An orchestrator delegates specialized work to agents over extended tasks. Blue Solano uses the resulting offensive traces and telemetry to create detections, patches, and remediations.

After the defensive model hardens the environment, the offensive model receives both the changed environment and an explanation of the defensive changes, then attempts to overcome them. Repeating this process is what CrowdStrike calls adversarial coevolution. It gives the system new security scenarios to work through as the defenses change.

SafeMind can produce prioritized findings and remediation recommendations. Additional deployed Falcon modules give it ways to carry out remediations within the platform, with more expected over time.

All of this is great, but we can’t have a proper model discussion without…evals! That’s actually the exciting part about the early benchmarks on SafeMind. The early benchmarks give us an idea about what this kind of focus and specialization can produce.

CrowdStrike's models performed very, very well across task performance with speed and cost.

In one offensive test, CrowdStrike tested three model configurations to execute an attack objective: a closed frontier model at approximately $96, an open model at $62, and Red Tempest in its specialized harness at $21.

On the defensive side, CrowdStrike reported a cost difference of $10 per detection with an off-the-shelf frontier configuration versus $0.03 for Blue Solano.

There’s a lot more work to do on cybersecurity-focused evaluations, but these results start to show us how engineering the models and harnesses together could make a difference. Evals like these matter a lot because effectiveness and the cost of repeated use (especially compared to general purpose models) are going to drive whether defenders choose to use them over other alternatives.

Falcon Guardian addresses security for AI. It secures the AI agents organizations are adopting at runtime. It connects prompt-level activity with endpoint telemetry to show what agents were instructed to do, what they actually did, plus other runtime controls.

It draws on capabilities across Falcon, combining prompt and tool activity with runtime evidence such as processes, file access, and network connections. Discovery, context, and enforcement give security teams ways to support AI and agent adoption while maintaining oversight of its actions.

The ecosystem announcements matter too (more on this later). CrowdStrike expanded Project QuiltWorks, its existing coalition for addressing frontier AI risk. QuiltWorks also serves as the trusted access route for access to standalone SafeMind models and harnesses outside the Falcon platform.

They announced a lot, and there’s so much more for us to get into.¹ To fully understand the significance of CrowdStrike’s announcements and the state of frontier AI for cybersecurity today, we should take a quick look back at where we’ve been.

We’ve had the pieces, but making them work together is the hard part

We've already seen examples of a few different components needed to make AI for defenders possible. Cybersecurity-specific models were some of the earliest. We’ve had iterations of those for years now, and we’re going to keep seeing more.

The chart below is a highlighted set of cybersecurity-focused models that have been released since 2023. Not all models are created equal. Some of these were experimental or narrowly focused, but each played a part in moving the state of AI for defenders forward.

Models are only part of the story, though. If we’ve learned anything from the advancements in coding agents, the harness and various components within it also matter a lot.

Since the early models, the landscape of cybersecurity-focused AI security tools has steadily been broadening beyond models to include harnesses and agents performing security work across different domains.

We now have domain-specific agents for security operations, identity, vulnerability management, application security, and other areas of cybersecurity. Most combine general-purpose models with security data, tools, and workflows. A few have even included specialized cybersecurity models.

We haven’t seen a multi-domain cybersecurity model and harness break through into mainstream use yet, though. That’s much easier said than done, partly because there are a few key components that all have to work for this to meet the high bar of cybersecurity leaders and practitioners.

I think SafeMind is going to be the first cybersecurity-specific AI to work at a broad scale. Guardian can play a similar role in securing AI adoption.

What stood out to me from my discussions at Fal.Con was the emphasis on building something practical for security practitioners to use. This wasn't just a lab experiment. SafeMind is grounded in real security workflows and trained to reason based on how cybersecurity professionals actually do their jobs. That practical grounding is an important part of why I think this can work.

I want to go even deeper, though. Let me tell you how CrowdStrike did it and why I think it has the ingredients to work this time.

CrowdStrike is one of the only companies capable of building something like this

I believe CrowdStrike is one of the few companies that could have pulled off something like SafeMind.

This isn’t just about the model — as we discussed earlier, that’s been done. I’m talking about the comprehensiveness of the whole effort: the AI research capability, operational experience, data, platform, and partnerships needed both to build the technology and to make it useful at scale.²

I’m not arguing that CrowdStrike has to be the best at every individual component, or that any one of them guarantees success. The part they deserve a lot of credit for is their ability to execute across all of the dimensions required to make the entire effort possible. This is CrowdStrike’s superpower.

The central question around CrowdStrike’s AI strategy is this: which capabilities are necessary to make cybersecurity-focused AI useful for defenders?

These are the capabilities I think matter the most and what CrowdStrike has done to bring them into reality.

Team and research capability

The story starts with people. George Kurtz made CrowdStrike’s ambition for people very clear in his opening keynote: “We’re bringing the best AI talent in the world to CrowdStrike.”

That’s the tone at the top — a commitment to investing in people and building a culture where frontier AI-grade work for cybersecurity can happen. The hiring, the establishment of the Cyber Superintelligence Lab, and what the team has delivered so far put substance behind their commitment.

This should tell you a lot: CrowdStrike waited until it had something to show before formally announcing the lab. “The lab is not the announcement,” as Kurtz said. The emphasis is on producing security capabilities that defenders can use. George Kurtz described the lab as the factory. SafeMind is one of its first outputs.

The investment in the lab gives CrowdStrike’s commitment an organizational home. Establishing and resourcing an applied research lab is a serious, non-trivial investment across people, product, strategy, culture, and more.

From a leadership standpoint, what stood out from meeting Bartley Richardson was his unique combination of experience in AI and cybersecurity. You just don’t find senior technical leaders with depth on both sides walking down the street. His experience, including his work at NVIDIA, brings a unique combination of skills and leadership to the lab.

The scale of their investment in people is also mind-blowing. CrowdStrike shared that they have 270 PhDs, more than 500 threat researchers, and hundreds of AI researchers across the company. Those are total company figures, not just the headcount of the new lab, but they give you a sense of the resources they’re putting behind this effort.³

Their commitment also shows up in how the work is organized. The AI lab develops models and harnesses. The product organization builds the customer-facing products that put those capabilities to use.

The collaboration also extends to the teams doing security work in the field. Threat hunting informs detections, while professional services and managed detection and response contribute operational experience and labeled data. Threat intelligence adds knowledge of adversaries and their tools.

The scale and diversity of CrowdStrike’s products and services make it possible to connect the people developing AI and products, the people investigating and responding to attacks, the partner ecosystem helping to implement and operate solutions in the field, and customers who use the products every day.

Operational data and security expertise

CrowdStrike has an almost unfathomable amount of data it can use to train and improve its models and harnesses. They recently disclosed the platform's scale at more than one exabyte stored, over seven trillion events analyzed daily, and roughly 14 petabytes ingested daily.⁴

The value starts with what the data captures: real security work, including complex attacks in large organizations. The data gives context about things like investigations, vulnerabilities, adversary behavior, and outcomes. So, exactly the kinds of problems defenders need models and harnesses to handle.

There was also an element of good fortune. Years of diligent annotation CrowdStrike’s researchers and analysts spent identifying threats, documenting what happened, and attaching intelligence gave the data meaning before any AI-related use cases entered the picture. That data that later turned out to be super useful for training models.

The breadth of CrowdStrike’s products and services adds another dimension that’s hard for smaller companies to replicate. Product, AI research, and threat intelligence bring different kinds of data and expertise to the work, alongside incident response and managed security services. Product telemetry captures activity across customer environments. Investigations and intelligence supply context about attacks. AI development adds execution traces from models and agents performing tasks.

All of these different sources provide varied scenarios and useful inputs for training models, improving their harnesses, and putting them into practice. You can’t just simulate the data CrowdStrike has in a lab. It comes from years of extensive, hard-earned experience in the field — there’s no way around that.

Making CrowdStrike’s variety of data useful to AI requires judgment, though. Researchers in the Cyber Superintelligence Lab carefully select and balance the data blend for training models and building specialized harnesses. The combination of complex real-world experience, prior annotation, and the expertise to choose and use the right material for AI is what gives the data its value.

More importantly, CrowdStrike continues to create data. Its researchers and defenders generate operational records, and its harnesses and agents generate execution traces. The massive opportunity going forward is to use that experience to improve how the models and harnesses do the work.

Falcon platform

An extensive platform like Falcon and its technology partner ecosystem contributes value to the overall AI system in multiple ways. Its telemetry provides context about an organization’s environment and assets and what’s happening around them. Its integrations and controls provide ways to take action on that context.

Falcon's breadth matters because defensive work spans different parts of the environment, and the available response depends on the capabilities a customer has deployed. Much of that work is likely to happen through tools organizations already use, both including and beyond Falcon itself.

Some manual interventions and actions outside the platform are probably never going away, but an important path to repeatable automation runs through Falcon’s existing modules and workflows. Connecting models and harnesses gives AI a practical route to take action. The more Falcon capabilities an organization has deployed, the more AI can help to carry out remediation work within the platform.

This is another dimension of the practicality point I’ve been making. Having a broad platform gives models and harnesses execution and delivery capabilities that help turn the model's intelligence into useful work.

You already understand this if you’ve spent a lot of time using powerful agents⁵ — they get exponentially more useful when you integrate them with other apps and data. Similar idea for SafeMind and cybersecurity-focused workflows.

SafeMind models, harnesses, and the NVIDIA partnership

Believe it or not, all of these components were just the buildup towards the models and harnesses. I wasn’t kidding when I told you there’s a lot required to make all of this work in the real world.

During his Fal.Con keynote, Bartley Richardson repeatedly made the point that “focus is a superpower.” That’s exactly the advantage CrowdStrike has with SafeMind, especially compared to the frontier AI labs.

CrowdStrike’s sole focus is to build models and harnesses that help defenders. That’s it. No math problems, no biology, no funny cartoon images for your kids. They’re all cybersecurity, all the time.

That clear, no-nonsense objective guides what their models learn and how their harnesses operate. For example, training on tool use traces helps make models better at using the tools and workflows needed for security tasks.

The NVIDIA partnership adds an extra dimension, bringing model development capabilities together with CrowdStrike's security experience to support the Cyber Superintelligence Lab’s work.

Nemotron was built to support specialization exactly like what CrowdStrike is doing for cybersecurity-focused models. Jensen Huang described CrowdStrike as a leading example of its intended use: adapting capable, customizable models to a domain where performance, speed, and cost matter together.

The depth of the relationship between CrowdStrike and NVIDIA is a significant part of their strategic advantage. In theory, anyone can download, use, and train Nemotron models. Competitors can replicate that part, but having the models only gets you to the starting line.

The real finish line is highly performant, accurate, and cost-effective models that excel at cybersecurity-focused task execution. It takes an extraordinary amount of compute, post-training, testing, and scaling to get there.

CrowdStrike’s direct collaboration with NVIDIA's researchers adds expertise and engineering effort on top of the models. CrowdStrike contributes its lab, domain specialization, data, compute, and more. NVIDIA contributes both the foundational model and the model-development expertise behind that approach. It takes both sides to make something like this work.

A relationship with this level of participation from a frontier AI company like NVIDIA takes more than access to download a model. It’s yet another capability CrowdStrike has cultivated alongside its own research team, data, and product portfolio.

Ecosystem

I think CrowdStrike’s ecosystem is the most underrated part of this story. Cybersecurity is very ecosystem-dependent. It's hard to get meaningful new work done, especially at this level of complexity and unfamiliarity, without both services and technology partners helping to make it happen.

CrowdStrike has spent years building a substantial ecosystem with highly engaged partners. That’s one of the main things it will take to get SafeMind and Guardian deployed in complex environments.

Project QuiltWorks is the coalition that brings together CrowdStrike’s technology with partners and customers. The ecosystem contributes to doing the work and getting cybersecurity-focused AI into the hands of customers.

The trusted access component is a big deal here, too. QuiltWorks is the path for standalone SafeMind models and harnesses. This gives partners the ability to use the models for their own specialized needs (both service delivery and applications), effectively building on and extending CrowdStrike’s foundational platform.

That alone is significant, but I think of it as a starting point. I expect many other other service offerings and technical integrations to be built over time. This feels inevitable with an ecosystem that has both the ability and the incentives to help put cybersecurity-focused AI into practice.

Steering AI’s Lollapalooza effects towards good

The uncertainty around AI is real, and so is the strain it puts on the people responsible for protecting their organizations. They face pressure to enable adoption while the capabilities, threats, and expectations keep changing.

The wider debate over AI's pace and safety will continue. The cybersecurity industry gains a voice by taking action to demonstrably shape what happens next.

Cybersecurity-focused AI research becomes more useful when it connects to tools that can act, practitioners who know the work, and partners who can help put it into practice. Models need reliable execution, outputs need a path into customer workflows, and deployments need people who are able to grow and sustain them.

That set of capabilities is the significance of what CrowdStrike is building.

It sure feels like Lollapalooza out there right now, but CrowdStrike isn’t standing still. They’ve taken decisive action and delivered a meaningful step forward to securing AI.

Just as importantly, they’re bringing a sense of calm and practicality to a problem space that often seems untenable.

This brings us back to Munger's warning about Lollapalooza effects. The same convergence that can amplify harm can also support extraordinary progress if we’re aware of the forces in play.

We can’t control every force shaping this moment. Building the defenses that allow more people to benefit from it is work we can do now.

More capable AI for defenders helps shift the balance toward people and organizations benefiting from AI. CrowdStrike's work is a gigantic step in that direction.


Footnotes

¹ AI-related announcements (unsurprisingly) got a lot of attention, but they made all kinds of other announcements across identity, endpoint, security operations, the partner ecosystem, and more.

² If you’re into the theory behind this strategy, David Teece's work on complementary assets is a helpful model for understanding the coordination of resources at scale and why inventing a technology doesn’t guarantee it’s going to be adopted. TL;DR, real world commercialization also depends on capabilities like distribution, services, partnerships, and more.

³ For context, Zenity (one of the largest early-stage AI security companies) has raised $184.5 million to date and has 268 total employees. Every company in their AI security peer group has an even smaller team.

⁴ These figures reference data across the Falcon platform (and related services) rather than the size of a training set. There’s a theoretical limit to when the amount of data used for training starts to plateau, but that’s a different discussion. Better to have a lot of data to begin with, which CrowdStrike does.

⁵ By “powerful agents,” I mean the 2026 flavors of things like Codex, Claude Code, OpenClaw, Hermes, Instinct, Muse, or pick your favorite. These agents don’t just respond to prompts. They can get a lot of work done quickly when you set them up right.

Share Article

Related Articles

SOS Logo

Cybersecurity, clarified

Strategic intelligence on the cybersecurity ecosystem, straight to your inbox.