Sunnyvale, CA, USA
2011
  |  By Brett Shaw
We are proud to announce that Frost & Sullivan has named CrowdStrike as the strongest overall leader in the Frost Radar: Cloud Workload Protection Platforms, 2026. CrowdStrike earned the highest scores in Innovation and Growth among 18 companies benchmarked from a field of more than 45 qualified participants. Today’s cloud attacks are designed to hide in plain sight.
  |  By Nathan Danneman
Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space.
  |  By Erez Goldberg
VMware ESX systems are a recurring target in ransomware campaigns. Threat groups including SCATTERED SPIDER, BlackBasta, Royal (aka BlackSuit), Akira, and the ESX-focused ransomware as a service (RaaS) platform shinysp1d3r have demonstrated that once an adversary reaches the hypervisor layer, they can rapidly encrypt virtual machines, disable logging, and cripple an entire data center.
At CrowdStrike, we conduct extensive red-team testing of agentic systems using diverse models, tools, and adversarial evaluation harnesses designed to probe for containment failures. To date, none of our offensive agents have escaped their intended sandbox boundaries.
  |  By Counter Adversary Operations
The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them. Our frontline intelligence in this year’s report underscores this shift.
  |  By David Keller
Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can expose sensitive information outside of approved workflows, and most of it happens where traditional endpoint, network, and data loss prevention (DLP) security controls can't see the prompt or the tool call.
  |  By Dana Raveh
Every change in a cloud environment creates new security decisions. A new infrastructure as code (IaC) template needs to be validated. Cloud permissions need to be reviewed. An application release introduces new cloud interactions. A Kubernetes cluster needs protection before it goes into production. Individually, these are routine tasks. Together, they create growing operational friction that makes cloud security harder to scale.
  |  By Paola Miranda
Organizations face a relentless stream of emerging threats, from zero-day exploits to rapidly evolving adversary tactics. They need protection that keeps pace with this changing landscape without adding operational complexity. The key challenge here is turning threat intelligence into production-ready detections before attackers can gain an advantage.
  |  By Bartley Richardson
AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders need the ability to inspect, test, adapt, and secure the systems they depend on.
  |  By Karan Sondhi
On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, which transforms federal vulnerability management by shifting agencies from static CVSS-based patching to a dynamic, risk-based model. This supersedes BOD 19-02 and BOD 22-01. Agencies must now prioritize remediation using four key factors: public asset exposure, KEV catalog status, exploit automatability, and technical impact (partial vs. total control).
  |  By CrowdStrike
Breaches don’t always start with malware. Increasingly, adversaries simply log in with valid credentials and when those credentials come with standing privileges, attackers inherit that access instantly. In this Lightboard Lab, learn how CrowdStrike is rethinking traditional privileged access with Modern Privileged Access. See how continuous evaluation of identity, device trust, security risk and business context can eliminate standing privileges and help ensure the right person gets the right access, in the right context, right when they need it.
  |  By CrowdStrike
In this Demo Drill Down, learn how Manual Sensor Scan enables teams to create targeted Python-based checks for pre-CVE vulnerabilities, supply chain risks, proprietary software, and other environment-specific conditions. See how built-in helper functions simplify custom detection logic and how identified findings are brought directly into Falcon Exposure Management for investigation, prioritization, and remediation.
  |  By CrowdStrike
AI has moved beyond the browser. It now runs in the terminal, the IDE, and desktop apps with your users' full privileges, where most security tools can't see it. In the AI era, the endpoint is where AI executes. This video shows how CrowdStrike Falcon AI Detection and Response (AIDR) extends the Falcon sensor you already run to the AI interaction layer. One sensor and one browser extension deliver visibility and control over every AI interaction on the endpoint and in the browser, from the Falcon console you already use.
  |  By CrowdStrike
AI is changing the threat landscape and the pace defenders have to keep up with. Adam Meyers, Head of Counter Adversary Operations at CrowdStrike, joined Yahoo Finance to unpack key findings from the latest CrowdStrike Threat Hunting Report, including: Watch the full interview for Adam’s take on how AI is reshaping adversary activity and what defenders need to know.
  |  By CrowdStrike
The CrowdStrike 2026 Threat Hunting Report is now live! The report sheds light on how our threat hunters and analysts hunt and defend against the world’s most sophisticated adversaries. It’s packed with stories from the front lines and trends that define the modern threat landscape.
  |  By CrowdStrike
AI adoption is expanding into agents, developer workflows, and browser-based experiences, creating new blind spots where security teams need visibility, context, and control. See how CrowdStrike Falcon extends AI security coverage across Microsoft Copilot Studio, Claude Code, and the Falcon Browser Extension. Learn how Falcon helps security teams evaluate agent tool use, enforce allow or block policy decisions, inspect prompts and responses for risks like prompt injection, sensitive data, and malicious content, and enrich investigations with endpoint identity context from the Falcon sensor.
  |  By CrowdStrike
AI is moving beyond browser tabs and SaaS apps into agents, local models, MCP servers, IDE extensions, and AI development frameworks running directly on the endpoint. These tools can access files, source code, credentials, and enterprise data with user-level privileges, creating new blind spots for security and IT teams. In this demo, see how CrowdStrike Falcon helps close the endpoint AI visibility gap by discovering, governing, and defending AI usage across the enterprise.
  |  By CrowdStrike
AI is changing how work gets done. It is also creating a new attack surface. Join CrowdStrike President Michael Sentonas for a first look at CrowdStrike’s vision for securing the agentic enterprise and defining AIDR, the emerging category for detecting, investigating, and responding to threats targeting and originating from AI systems, agents, and autonomous workflows. In this virtual event, you’ll learn.
  |  By CrowdStrike
Securing the browser is no longer optional, but not every approach delivers the same level of protection, flexibility, or user experience. Remote browser isolation, VDI, dedicated secure browsers, and browser extensions can each address part of the problem. But they may also introduce latency, force users into unfamiliar workflows, create patching gaps, or lack visibility into the browser runtime where sessions, tokens, data, and attacks converge.
  |  By CrowdStrike
Work no longer happens inside a clearly defined perimeter. It happens in the browser, where users access SaaS applications, private resources, sensitive data, and AI tools from managed devices, personal devices, and contractor environments.
  |  By CrowdStrike
Visibility in the cloud is an important but difficult problem to tackle. It differs among cloud providers, and each one has its own positive and negative aspects. This guide covers some of the logging and visibility options that Amazon Web Services (AWS) and Google Cloud Platform (GCP) offer, and highlights their blind spots and how to eliminate them.
  |  By CrowdStrike
Since a majority of the breaches are credential based, securing your multi-directory identity store - Microsoft Active Directory (AD) and Azure AD - is critical to protecting your organization from adversaries launching ransomware and supply chain attacks. Your security and IAM teams are concerned about securing AD and maintaining AD hygiene - and they need to be in sync, for example, to ensure that legacy and deprecated protocols like NTLMv1 are not being used and that the right security controls are in place to prevent breaches in real time.
  |  By CrowdStrike
You have to secure your workforce identities immediately, to protect your organization from modern attacks like ransomware and supply chain threats. Your environment could be just Microsoft Active Directory (AD), or a hybrid identity store with AD and Azure AD, and it's important to have a holistic view of the directories and a frictionless approach to securing them. If you're considering Microsoft to secure your identities and identity store (AD and Azure Active Directory), you should ask these five questions.
  |  By CrowdStrike
Learn about how to strengthen and modernize your agency's security protection, detection and remediation with Zero Trust. This white paper explains the unique risk factors federal agencies face, what a superior Zero Trust framework includes, and how cloud and endpoint security can help modernize federal security from the endpoint to the application.
  |  By CrowdStrike
Cloud adoption remains a key driver for digital transformation and growth for today's businesses, helping them deliver applications and services to customers with the speed and scalability that only the cloud can provide. Enabling them to do so safely is a critical objective for any enterprise IT security team.
  |  By CrowdStrike
Network segmentation has been around for a while and is one of the core elements in the NIST SP 800-207 Zero Trust framework. Although network segmentation reduces the attack surface, this strategy does not protect against adversary techniques and tactics in the identity phases in the kill chain. The method of segmentation that provides the most risk reduction, at reduced cost and operational complexity, is identity segmentation.

CrowdStrike protects the people, processes and technologies that drive modern enterprise. A single agent solution to stop breaches, ransomware, and cyber attacks—powered by world-class security expertise and deep industry experience.

Many of the world’s largest organizations already put their trust in CrowdStrike, including three of the 10 largest global companies by revenue, five of the 10 largest financial institutions, three of the top 10 health care providers, and three of the top 10 energy companies.

A Radical New Approach Proven To Stop Breaches:

  • Cloud Native: Eliminates complexity and simplifies deployment to drive down operational costs.
  • AI Powered: Harnesses the power of big data and artificial intelligence to empower your team with instant visibility.
  • Single Agent: Delivers everything you need to stop breaches — providing maximum effectiveness on day one.

One platform. Every industry. Superior protection.