Shapefin

CrowdStrike Introduces Threat AI, An Agentic System for Automated Threat Intelligence

Share It:

AUSTIN, Texas & LAS VEGAS – CrowdStrike (NASDAQ: CRWD) announced Threat AI, the industry’s first agentic threat intelligence system designed to automate complex, time-consuming intelligence workflows and accelerate security outcomes. This new system is a component of CrowdStrike’s recently introduced Agentic Security Workforce, delivering mission-ready agents that can reason across threat data, proactively hunt adversaries, and take decisive action throughout the kill chain, thereby enabling defenders to prioritize high-impact investigations while maintaining full control.

Adam Meyers, head of Counter Adversary Operations at CrowdStrike, stated, “Adversaries are weaponizing AI to accelerate every stage of attacks – what once took months can now happen in seconds, collapsing the defender’s window of response. Intelligence must evolve beyond informing defenders to actively countering threats at the speed of AI.” Meyers added that Threat AI serves as the intelligence arm of CrowdStrike’s strategy to equip every security analyst with mission-ready agents that eliminate high-friction tasks better suited for machines, ushering in a new era of threat intelligence.

CrowdStrike has a established history in adversary intelligence, tracking over 265 sophisticated nation-state, eCrime, and hacktivist groups globally. Threat AI is integrated within CrowdStrike’s Threat Intelligence & Hunting modules and is informed by years of real-world decisions from CrowdStrike Counter Adversary Operations’ (CAO) team of threat hunters and intelligence experts. It automates intricate workflows and provides actionable recommendations when analysts need them most.

Threat AI is designed to accelerate investigations and threat response, with its initial agents including the Malware Analysis Agent and the Hunt Agent. The Malware Analysis Agent automates the process of reversing, classifying, and comparing malware, a workflow that is typically time-consuming and complex for analysts. It analyzes files, identifies code similarities, provides instant attribution, and generates YARA rules in seconds, delivering actionable insights and scaling defenses across entire malware families.

The Hunt Agent automates continuous, expert-level threat hunting across an environment. This agent executes queries, proactively scans for emerging threats, rapidly surfaces critical findings, and provides clear, actionable insights alongside next-step recommendations.

The Malware Analysis and Hunt Agents represent the first offerings in a series of Threat AI agents. Additional agents focusing on triage, correlation, and exposure mapping are planned for future release. Each agent will be orchestrated to ensure that the output of one strengthens the capabilities of the others.

CrowdStrike is also introducing a new Chrome extension that brings CrowdStrike adversary intelligence directly into analysts’ web browsers. This allows analysts to access CrowdStrike’s intelligence while conducting external research, gaining immediate context for investigations and speeding response times with actionable insights, all within the same workflow.

Latest Posts