CrowdStrike builds security frontier models with Nvidia and opens an AI lab
CrowdStrike Holdings Inc. today launched SafeMind, a family of artificial intelligence models and agent harnesses created with Nvidia Corp. and built for security work rather than general use.
A research organization the company also unveiled today, the Cyber Superintelligence Lab, produced them. CrowdStrike separately extended its Falcon platform across Google Cloud’s enterprise AI ecosystem, part of a run of announcements at its Fal.Con conference in Las Vegas this week.
SafeMind launches with two models. Red Tempest is the offensive one, built to emulate AI-driven adversaries and run advanced attack scenarios against an environment. Blue Solano plays defense, applying the containment measures CrowdStrike responders use on live incidents.
The harnesses run both in a closed loop that pits one model against the other so each improves, and they also drive frontier and open-source models from other providers. SafeMind will operate natively in the CrowdStrike Falcon platform, with standalone access to the models and harnesses handled through the Project QuiltWorks program the company started in April.
CrowdStrike built the models on Nvidia’s open Nemotron family and trained them on its own material. That includes Falcon sensor telemetry, threat intelligence and the event annotations Falcon Complete analysts attach to confirmed detections. CrowdStrike calls the sensor data the largest pureplay cyber dataset and edge install base in the industry. Fifteen years of incident response fieldwork went in as well. CoreWeave Inc. supplied cloud capacity for training and inference.
“The future of cybersecurity won’t be defined by AI that simply identifies threats, it will be defined by AI that defeats them,” said George Kurtz (pictured, left), founder and chief executive of CrowdStrike. “SafeMind brings offensive and defensive models together in a system trained on CrowdStrike’s unique cyber data. It finds weaknesses, strengthens protection and gets smarter with every cycle, advancing our mission to stop breaches at machine speed.”
Measured against leading frontier models and open-source baselines, CrowdStrike said SafeMind posted a 29% higher detection rate, remediated six times faster end to end, and cut detection and remediation costs by 99%. The release did not name the models it was tested against or describe the methodology behind the figures.
Nvidia is the AI design partner on the work. Cyber defense will rank “among the most compute-intensive applications of AI,” said co-founder and CEO Jensen Huang (right), describing the years ahead as a running contest between attackers scaling up with AI and defenders using it to widen detection and response. CoreWeave co-founder and CEO Michael Intrator said few environments test what AI “can do in production, at scale” as hard as security does.
The models come out of a research group CrowdStrike also announced today. Its Cyber Superintelligence Lab puts the company’s AI researchers, offensive operators and incident responders under a single charter, and Bartley Richardson, chief AI and autonomous systems officer, runs it.
The lab runs on the telemetry CrowdStrike collects from Falcon sensors deployed in customer environments, which report from endpoints, identity systems, cloud workloads, data stores and Falcon Next-Gen SIEM at trillions of events a day. Richardson called the models “the start of a new chapter for cyberdefense” and said CrowdStrike is the only company that owns the entire stack, from sensor to harness to model.
CrowdStrike is pitching the models into a market where the strongest general-purpose models are available to both sides.
“The irony is that the world’s most powerful models from OpenAI and Anthropic were not built for defenders, but attackers can effectively utilize them to identify attack vectors,” said Dave Vellante, co-founder and chief analyst at SiliconANGLE Media. “The Mythos moment and Hugging Face hack are milestone events in cybersecurity, like Stuxnet and SolarWinds before them. These events expose novel threats that general purpose frontier models weren’t designed to defend. CrowdStrike, by partnering with Nvidia, is creating a purpose-built frontier model specifically designed for defenders. It reminds me of an AI security version of the Netflix Chaos Monkey.”
CrowdStrike separately extended its Falcon platform across Google Cloud’s enterprise AI ecosystem, with four additions. Falcon Guardian, the AI detection and response product the company launched at the show, now runs through Google Agent Gateway, where it watches for prompt injection, data leakage and malicious activity in AI applications at runtime.
Falcon MCP feeds CrowdStrike threat intelligence and detections into Gemini Enterprise workflows. Charlotte AI brings natural-language investigation and response into the same environment. And Falcon Shield covers Google Cloud’s Agent Registry, where security teams find and govern the agents running in their software-as-a-service estate.
Daniel Bernard, chief business officer at CrowdStrike, said organizations “shouldn’t have to choose between accelerating AI adoption and reducing risk.” Google Cloud is separately hosting the Falcon platform on regional infrastructure, an arrangement announced Monday at the conference for customers that need their security stack in a specific location. Brian Goldstein, vice president of strategic AI and independent software vendors at Google Cloud, described enterprise AI as “a new operating layer for the enterprise.”
Two partner announcements landed alongside the CrowdStrike news at Fal.Con.
Data resilience company Rubrik Inc. and CrowdStrike said they will run a full identity recovery workflow through Charlotte Agentic SOAR, tying CrowdStrike’s Falcon Next-Gen Identity Security to Rubrik Identity Resilience. CrowdStrike detects and contains the activity. Rubrik then correlates the detection against identity logs and backup data, reverses malicious Active Directory changes, removes attacker files or triggers a full forest recovery. The companies said the sequence cuts recovery from days to hours.
Anneka Gupta, chief product officer at Rubrik, said relying on human reaction time is “risky and obsolete” when a breach unfolds in milliseconds. Research from the company’s Zero Labs unit found that 90% of information technology and security leaders rate identity-based attacks the single largest threat to their organizations.
Fortanix Inc. is working a different part of the problem. The data security company said it will pair its Confidential AI product with Falcon so that AI workloads run inside hardware-isolated memory while CrowdStrike watches for attacks around them. Prompts, model weights, enterprise data and inference outputs stay encrypted in use under that arrangement, which puts them out of reach of cloud operators and privileged administrators as well as intruders.
The CrowdStrike work follows an on-premises confidential AI platform Fortanix built with Nvidia, released last October for regulated industries. Securing AI takes more than blocking attacks, Chief Product Officer Anuj Jaiswal said, because the data and models have to be protected while they are running.
Photo: CrowdStrike/X
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.