CrowdStrike Incident Response teams leverage Falcon Identity Threat Detection (ITD) for Microsoft Active Directory (AD) and Azure AD account authentication visibility, credential hygiene and multifactor authentication implementation Falcon ITD is integrated into the CrowdStrike Falcon® platform and provides alerts, dashboards and custom templates to identify compromised … [Read more...] about How CrowdStrike Supercharges IR with Identity Threat Detection
CrowdStrike
How CrowdStrike Prevents Volume Shadow Tampering by LockBit
ECrime activities dominate the threat landscape, with ransomware as the main driver Ransomware operators constantly refine their code and the efficacy of their operations CrowdStrike uses improved behavior-based detections to prevent ransomware from tampering with Volume Shadow Copies Volume Shadow Copy Service (VSS) backup protection nullifies attackers’ deletion attempts, … [Read more...] about How CrowdStrike Prevents Volume Shadow Tampering by LockBit
CrowdStrike Falcon Platform Receives 12th AAA Rating from SE Labs
The CrowdStrike Falcon® platform receives new AAA rating from SE Labs, one of the most prestigious independent third-party testing institutions Falcon achieves AAA rating, scoring 99% total accuracy and 100% legitimate accuracy This marks the Falcon platform’s 12th AAA rating from SE Labs since March 2018 CrowdStrike remains committed to transparency and our mission to stop … [Read more...] about CrowdStrike Falcon Platform Receives 12th AAA Rating from SE Labs
How CrowdStrike Intelligence Uses Fuzzing to Hunt for Bugs
One useful method in a security researcher’s toolbox for discovering new bugs in software is called “fuzz testing,” or just “fuzzing.” Fuzzing is an automatic software testing approach where the software that is to be tested (the target) is automatically fed with input data and its behavior during execution is analyzed and checked for any errors. For the CrowdStrike … [Read more...] about How CrowdStrike Intelligence Uses Fuzzing to Hunt for Bugs
How CrowdStrike Supports the ICS/OT Landscape With Rockwell
CrowdStrike and Rockwell Automation have announced a partnership to help joint customers secure the expanded threat surface of the industrial control systems (ICS) and operational technology (OT) controlling our energy, manufacturing our goods and operating our medical equipment. This has been a greenfield area for security due to the real-time nature of these systems and the … [Read more...] about How CrowdStrike Supports the ICS/OT Landscape With Rockwell
Customers, Conviction, Speed: A Conversation With George Kurtz, CEO and Co-Founder at CrowdStrike
“When we think about Humio, it’s not just about stopping breaches, right? It’s about having companies run better, their IT systems performing better, having better customer interactions, because customers are delighted by the performance of the systems.” — George Kurtz, CEO & Co-Founder, CrowdStrike The Falcon Platform + Humio: The future of XDR Q: As part of the … [Read more...] about Customers, Conviction, Speed: A Conversation With George Kurtz, CEO and Co-Founder at CrowdStrike
CrowdStrike Expands Technical Integrations for Healthcare
The Healthcare Security Crisis The FBI has released many warnings of ongoing ransomware attacks targeting U.S. healthcare and first-responder networks over the last three years, with ransomware families being updated with new names as hackers exchange sophisticated hacker-for-hire code and models to exploit vulnerable healthcare facilities. From penalties and Health Insurance … [Read more...] about CrowdStrike Expands Technical Integrations for Healthcare
Microsoft Warns CrowdStrike of Hackers Targeting Azure Cloud Customers
New evidence amidst the ongoing probe into the espionage campaign targeting SolarWinds has uncovered an unsuccessful attempt to compromise cybersecurity firm Crowdstrike and access the company's email. The hacking endeavor was reported to the company by Microsoft's Threat Intelligence Center on December 15, which identified a third-party reseller's Microsoft Azure account to be … [Read more...] about Microsoft Warns CrowdStrike of Hackers Targeting Azure Cloud Customers
How to Setup the CrowdStrike Falcon SIEM Connector
Introduction The Falcon SIEM Connector provides users a turnkey, SIEM-consumable data stream. The Falcon SIEM Connector: Transforms Crowdstrike API data into a format that a SIEM can consume Maintains the connection to the CrowdStrike Event Streaming API and your SIEM Manages the data-stream pointer to prevent data loss Prerequisites Before using the Falcon SIEM Connector, … [Read more...] about How to Setup the CrowdStrike Falcon SIEM Connector
How to Import IOCs Into the CrowdStrike Falcon Platform
Introduction As part of the CrowdStrike API, the “Custom IOC APIs” allows you to retrieve, upload, update, search, and delete custom Indicators of Compromise (IOCs) that you want CrowdStrike to identify. With the ability to upload IOCs to the endpoints can automatically detect and prevent attacks identified by the indicators provided from a threat feed. Prerequisites To get … [Read more...] about How to Import IOCs Into the CrowdStrike Falcon Platform