CrowdStrike Threat AI leads threat intelligence into the agentic era
CrowdStrike has announced Threat AI, an agentic threat intelligence system built to automate complex, time-consuming intelligence workflows and accelerate outcomes. As part of CrowdStrike's new Agentic Security Workforce, Threat AI delivers mission-ready agents that reason across threat data, hunt adversaries proactively, and take decisive action across the kill chain.
“Adversaries are weaponising AI to accelerate every stage of attacks – what once took months can now happen in seconds, collapsing the defender’s window of response. Intelligence must evolve beyond informing defenders to actively countering threats at the speed of AI,” said Adam Meyers, head of Counter Adversary Operations at CrowdStrike.
“Threat AI is the intelligence arm of CrowdStrike’s vision to equip every security analyst with mission-ready agents that eliminate high-friction tasks better suited for machines, ushering in a new era of threat intelligence.”
CrowdStrike tracks more than 265 of the world’s most sophisticated nation-state, e-crime and hacktivist groups. Embedded inside CrowdStrike’s Threat Intelligence & Hunting modules and informed by years of real-world decisions from CrowdStrike Counter Adversary Operations’ (CAO) team of elite threat hunters and intelligence experts, Threat AI automates complex workflows and surfaces actionable recommendations. The initial agents include:
- Malware Analysis Agent: Automates one of the most time-consuming and complex analyst workflows: reversing, classifying, and comparing malware. In seconds, the agent can analyse files, identify code similarities, provide instant attribution, and generate YARA rules, delivering actionable insights and scaling defenses across entire malware families.
- Hunt Agent: Automates proactive, expert-level threat hunting continuously across the environment. The agent executes queries, proactively scans for emerging threats, surfaces critical findings, and delivers clear insights and next-step recommendations.
Additional agents for triage, correlation, and exposure mapping are planned. Each agent will be orchestrated so the output of one strengthens the others.
CrowdStrike is also introducing a new Chrome extension that brings CrowdStrike adversary intelligence directly into analysts’ web browsers. Analysts can access CrowdStrike's intelligence while conducting external research, gaining immediate context for investigations and speeding response times with actionable insights, all in the same workflow.
*YARA stands for yet another recursive acronym. YARA is a tool for malware research.
Comments
Post a Comment