AI Business

CrowdStrike's AI Defense Lab Takes On Machine-Speed Threats

At its Fal.Con conference, CrowdStrike unveiled SafeMind, a pair of AI security models built to match the speed of AI-powered attacks that now breach organizations in seconds rather than minutes.

·9 min read
Four insights you might have missed from theCUBE’s coverage of CrowdStrike’s Fal.Con
Four insights you might have missed from theCUBE’s coverage of CrowdStrike’s Fal.Con

Attackers leveraging artificial intelligence can now penetrate corporate networks in mere seconds, leaving defenders with virtually no time to mount a response. This challenge formed the centerpiece of remarks delivered by George Kurtz, CrowdStrike Holdings Inc.'s president, chief executive officer and founder, during the company's Fal.Con event. According to theCUBE Research analyst Dave Vellante, the measure of time between initial compromise and lateral movement—known as "breakout time"—has compressed dramatically year after year.

Every year at this conference, George steps up and says breakout time has gone from two minutes to 72 seconds, down to 30 seconds. And now he's like, it's done. It's just runtime. There is no breakout time.

Dave Vellante, theCUBE Research

CrowdStrike's "2026 Global Threat Report" documented an average eCrime breakout time of just 29 minutes, with the fastest intrusion completing in only 27 seconds, according to Michael Sentonas, president of CrowdStrike. He emphasized the unprecedented velocity of modern threats.

https://www.youtube.com/embed/eF7B0XE9cCc?feature=oembed

I've never seen anything like it. I've never seen anything move so fast. That's all happening on one side. On the other side … I think it's fascinating. It's so exciting. There's so much possibility. There's so much we can do. Unfortunately, the benefit we get is also the benefit the attacker gets. That's kind of that challenge that we have right now.

Michael Sentonas, CrowdStrike

SafeMind: AI Models Built for Defense

To address this acceleration, CrowdStrike introduced SafeMind at Fal.Con, a collection of purpose-built security models developed in collaboration with Nvidia Corp. The initiative represents the first major output from CrowdStrike's Cyber Superintelligence Lab, which the company describes as a frontier AI research organization dedicated to staying ahead of AI-driven threats.

What we did is we created bespoke models that were built for defenders. Obviously we have an offensive model as well, which is needed. What we wanted to do was to give choice to customers.

George Kurtz, CrowdStrike

https://www.youtube.com/embed/0hS7Lk3Huws?feature=oembed

Insight #1: Red and Blue Teaming at Machine Speed

SafeMind equips defenders with AI tools comparable to those wielded by attackers. The platform comprises two distinct models: Red Tempest and Blue Solano, both trained on CrowdStrike incident data and built atop Nvidia's Nemotron family of models. Daniel Bernard, chief business officer of CrowdStrike, explained the rationale for developing security-specific AI.

Frontier models have done a fantastic job bringing AI innovation to the market at large. It's really benefited the adversary. It's time for the defenders to have something, and it's time for security to have its own model. It turned into a set of models, a model family, and that's where SafeMind was born.

Daniel Bernard, CrowdStrike

Red Tempest scans a digital replica of a customer's infrastructure to identify potential attack vectors. Blue Solano then remediates discovered vulnerabilities. Justin Boitano, vice president and general manager of enterprise computing at Nvidia, described the iterative process.

The digital twin describes the environment of the actual world. You run the red agent through the environment and you'll find different ways in to exfiltrate data. Then the blue agent will come in and write rules that would have detected or prevented the red attack agent from getting through. That iterative loop basically hardens the environment.

Justin Boitano, Nvidia

Insight #2: Agentic Adversaries Operating at Machine Velocity

https://www.youtube.com/embed/G_32SXOVbXE?feature=oembed

Speed has emerged as the defining challenge for security teams confronting AI-driven intrusions. Adam Meyers, senior vice president of intelligence at CrowdStrike, highlighted the proliferation of autonomous threat actors.

The stat that's most interesting is we had something like 26 agentic adversaries that we were tracking in the last 30 days. That's more than we were tracking in the year before that.

Adam Meyers, CrowdStrike

These autonomous agents operate far faster than human attackers. Meyers recounted a specific incident involving VAULT PANDA, which executed over 1,100 commands in under an hour while learning in real time. The implications are stark: entire intrusion campaigns now unfold within minutes.

In 58 minutes, VAULT PANDA had conducted 1,100 commands. It was an agent that was doing it, and we were watching it learn in real time. When I talk about breakout time from our global threat report, we were talking this year about 29 minutes on average, 27 seconds was the fastest. I'm talking about an entire intrusion operation conducted in minutes from start to finish.

Adam Meyers, CrowdStrike

https://www.youtube.com/embed/XdYWIwBq-nM?feature=oembed

Box Inc. leverages CrowdStrike technology to shield clients from both human and autonomous intruders. Heather Ceylan, Box's chief information security officer, emphasized how AI agents have fundamentally altered the threat landscape.

Attack surface is the same, but it's not just humans who are the attackers anymore. It's agents and they move at machine speed. So everything got faster. Our detections need to be faster, our visibility needs to be real time.

Heather Ceylan, Box

The proliferation of AI across enterprises without proper governance frameworks has created additional complexity. Cristian Rodriguez, field chief technology officer of the Americas at CrowdStrike, noted that organizations are struggling to manage their AI deployments.

They're calling us saying, we have a problem, the AI sprawl is real, we know it's in our SaaS apps, we know it's on our endpoints, we know it's in our cloud instances. [They are saying] help us get our arms around visibility and governance programs and control, because we've bitten off a little more than we can chew.

Cristian Rodriguez, CrowdStrike

https://www.youtube.com/embed/do-m7W3iGrE?feature=oembed

Insight #3: AI Reshaping Data Loss Prevention

Endpoint security remains central to enterprise data protection strategies. On-device AI can prevent incidents where employees inadvertently expose sensitive data to chatbots or other AI systems. Todd Cramer, senior director of business development and security ecosystem at Intel Corp., highlighted a new capability.

This year, we have Falcon data security from CrowdStrike announcing their first AI model that runs on an Intel NPU on a Dell device. It's the right time in the use case, because we've got all these AI assistants, chatbots. What's the first thing CISOs are worried about? Data.

Todd Cramer, Intel

Dell Technologies is developing hardware telemetry solutions that provide comprehensive visibility across the entire technology stack. Lori Zwilling, senior director of software product management at Dell Technologies Inc., described the scope of this visibility.

https://www.youtube.com/embed/9Xwwu7aWVXA?feature=oembed

Not only are analysts seeing the endpoint behavior, but they also can see what's happening with AI models, the data, the inferencing, the actual containers, the compute that's powering the AI for the enterprise. We're talking about full-stack AI security now.

Lori Zwilling, Dell Technologies

Traditional data loss prevention tools have struggled with scale and accuracy. Jazz Inc., winner of the 2026 Cybersecurity Startup Accelerator from CrowdStrike and Amazon Web Services Inc., has developed an AI-based approach that learns business context surrounding risky data movements. Ido Livneh, co-founder and chief executive officer of Jazz, explained the departure from legacy methods.

We didn't build yet another pattern match or another rule-based system. We completely upturned the whole challenge with our approach, which is building an investigator, a context-first, business-first investigator that understands your business, understands not only what is happening with the data flows, but why it's happening, the intent, and solving it through that.

Ido Livneh, Jazz

CJ Moses, chief information security officer and vice president of security engineering at Amazon, noted that AI enables DLP solutions to handle the volume of data that traditional tools could not.

https://www.youtube.com/embed/eMoV0gGTlpY?feature=oembed

In my experience, DLP providers have never done what DLP actually, the acronym, stands for. They've never done the data loss prevention. With basically AI now being a thing that actually will allow you to be able to deal with the large scale of the information and how they've implemented was kind of game changing for us.

CJ Moses, Amazon

Insight #4: Ecosystem and Partnership Strategy

CrowdStrike is positioning SafeMind as the inaugural achievement of its Cyber Superintelligence Lab, which aims to automate security tasks at the speed required to counter modern threats. Kurtz articulated the lab's vision of achieving autonomous defense operations.

https://www.youtube.com/embed/SimnTGmj4DA?feature=oembed

Part of why we started the Cyber Superintelligence Lab is to be able to build these sort[s] of technologies so that we can get to a level of automation where the car drives itself. Maybe the human has to be in the loop, and if something's really critical, fine. If you can automate the most mundane task and you can do it with the speed at which the adversary is moving, that's going to be critical.

George Kurtz, CrowdStrike

Bartley Richardson, chief AI and autonomous systems officer at CrowdStrike, framed the lab's broader mission as democratizing defensive capabilities across the industry.

https://www.youtube.com/embed/FTAOHqN6GZE?feature=oembed

The real remit of the lab is the commoditization of defense capabilities. It is [turning] the best offense into that disproportionately advantaged defender-like capability. How are we improving other areas in the industry itself? What can we contribute back?

Bartley Richardson, CrowdStrike

Strategic partnerships will prove essential to this mission. CrowdStrike's Project QuiltWorks brings together technology companies, law firms, consultancies and other organizations to identify and remediate vulnerabilities surfaced by AI models. Amanda Adams, senior vice president of global alliances at CrowdStrike, described the initiative's tooling.

QuiltWorks is a coalition of folks and partners who join us; they leverage our platform. We announced yesterday Falcon IQ, and this is a tool built on AWS that allows a partner to essentially drive an assessment and highlight the opportunities, the priorities. It's using AI to accelerate the time from discovery to remediation down to minutes.

Amanda Adams, CrowdStrike

CrowdStrike's relationship with Amazon Web Services has deepened as both organizations have evolved their technological capabilities. Mona Chadha, director of strategic partnerships and category growth at Amazon Web Services Inc., reflected on a decade of collaboration.

https://www.youtube.com/embed/zVHic9q2sMw?feature=oembed

https://www.youtube.com/embed/videoseries?list=PLK5JkEj2_qlo

Over the decade, what we continued to do was build innovations together. We've evolved from machine learning to generative AI to now agentic and building these agents. There's a lot of opportunity there, but there [are] also a lot of threats.

Mona Chadha, Amazon Web Services