Tag: CrowdStrike

CrowdStrike Breaks Speed Record in MITRE ATT&CK® Evaluation

BENGALURU, India. June 21, 2024 – CrowdStrike set a new speed benchmark for cybersecurity threat detection, identifying and alerting on a sophisticated eCrime adversary attack in just four minutes during the closed-book MITRE Engenuity’s ATT&CK® Evaluations: Managed Services-Round 2. CrowdStrike Falcon® Complete MDR operates at the speed of the adversary, detecting the security incident six to 11 times faster than competitive vendors, while scoring the highest in detection coverage.

Michael Sentonas

MITRE’s closed book evaluation emulated a real-world eCrime attack without giving the vendors prior knowledge of the threat scenario – creating the most accurate assessment of a vendor’s capabilities. In this scenario, prevention capabilities of the Falcon agent were not permitted and the Falcon platform was operating in detect-only mode, meaning no automated actions could be taken to kill processes. In this rigorous setting, CrowdStrike reported 42 out of the 43 adversary techniques. MITRE recorded CrowdStrike’s mean-time-to-detect (MTTD) – the average time between when a specific attack activity was performed and an email alert regarding that activity was received – at a record-breaking four minutes, setting a new benchmark for speed in threat detection.

“Stopping breaches requires security teams to operate at the speed of the adversary. The Falcon platform’s unique cloud-born, AI-native architecture with one intelligent sensor delivers the best analyst experience and the fastest, most effective cybersecurity outcomes in the industry,” said Michael Sentonas, President of CrowdStrike. “Multiple platforms and stitched-together solutions are hard to use, create operational complexity, and slow security teams down when speed matters most. This is evident in testing scenarios and even more so in real-world environments. The powerful combination of CrowdStrike’s elite team of experts, the Falcon platform, and our knowledge of the adversary is unmatched in delivering the speed and efficacy needed to stop breaches.”

Mandiant Opens Managed Defense Beta Program to CrowdStrike and SentinelOne Customers

Mandiant, Inc. (NASDAQ: MNDT) today introduced a new beta program for its managed detection and response (MDR) service – Mandiant® Managed Defense. Open to select CrowdStrike Falcon and SentinelOne Singularity Endpoint customers, the beta program offers 24/7 access to Mandiant cyber security experts for alert monitoring, prioritization and investigation as well as the opportunity for participants to provide valuable feedback prior to the general availability launches later this year.

“Today’s global threat landscape requires the cyber security community to come together to protect and defend organizations against increasingly sophisticated and persistent threats,” said Dave Baumgartner, EVP, Managed Solutions at Mandiant. “Elite partners like SentinelOne and CrowdStrike enable us to evolve our Managed Defense service and deliver highly adaptable and intelligence-led solutions that allow organizations to maximize current technology investments and strengthen their cyber defenses.”

Mandiant Managed Defense is a MDR service driven by Mandiant frontline expertise and nation-state grade threat intelligence. Mandiant’s experienced defenders hunt across endpoints, network, email, cloud and operational technology infrastructure to quickly find and investigate impactful events. The service empowers organizations to reduce attacker dwell-time and use proven tactics to quickly respond to attacks that could impact business operations.

The beta program is designed to provide participants access to:

Around-the-clock alert monitoring from Mandiant Managed Defense global security operations centers (SOCs).
Alert triage and investigation by Mandiant experts who can quickly identify, investigate, scope and contain incidents.
Visibility into active or past breaches through continuous human-led threat hunting adapted in real time to changes in attacker behavior and mapped to the MITRE ATT&CK® framework.
Early insight into adversary activity through Mandiant’s frontline knowledge of critical IOCs and headline breach activity.
Ability to resolve incidents rapidly without the added cost of full incident response.
Ongoing assessments and recommendations informed by relevant intelligence and a deep understanding of customers’ unique IT environments.

“Our alliance with Mandiant represents a milestone partnership for the cyber security industry by putting the needs of our customers first,” said Shawn Henry, CrowdStrike Chief Security Officer and President of CrowdStrike Services. “Our mission is to stop breaches and now we are providing customers another opportunity to have protection from the world’s most advanced CrowdStrike cloud native platform.”

“Our strategy of partnering with leading technology and service providers – like Mandiant – enables enterprises to maximize usage of the Singularity XDR platform,” said Nicholas Warner, President, Security at SentinelOne. “We don’t compete with our partners – we jointly build game-changing solutions and businesses together. The joint solution enables organizations to minimize risk with the technology of SentinelOne and services of Mandiant.”

As part of the evolution of its vendor independent stance, Mandiant added endpoint market leaders SentinelOne and CrowdStrike to its growing list of strategic technology partners in early 2022. Today’s announcement marks the next phase of its go-to-market and operational journey with both companies. Putting customer needs first furthers the shared mission of these organizations to make every organization secure from cyber threats. Additionally, the integration of leading technologies from strategic partners like CrowdStrike and SentinelOne provides greater opportunities for organizations to choose Mandiant Managed Defense when they are considering a MDR service.