CrowdStrike recently revealed its new adversary-focus cloud native application protection platform (CNAPP) capabilities and emphasized the need to think like attackers to safeguard the cloud environments.  

“We believe CrowdStrike's adversary-focus approach is necessary and unique in the industry,” Amol Kulkarni, chief product and engineering officer at CrowdStrike, told SDxCentral. “That deep integration and leverage of CrowdStrike’s leading threat intelligence is going to be super helpful in terms of staying one step ahead of adversaries.”

CrowdStrike has been tracking actor groups, their tactics, techniques, and procedures (TTPs), and targets, Kulkarni said. “And it is absolutely critical that cloud security products do the same because the same actors are attacking the cloud environments.”

Applied the same philosophy as its endpoint security services, the vendor incorporated threat intelligence natively into its cloud security products and enabled threat hunting for cloud environments, he added.

CrowdStrike Combines Agent-Based and Agentless Security Services

The latest additions to CrowdStrike’s cloud security portfolio include a centralized dashboard to unify insights from both its Falcon Horizon cloud security posture management (CSPM) and Falcon cloud workload protection (CWP) modules.

Falcon Horizon offers an agentless option while Falcon CWP is an agent-based service. “What sets CrowdStrike apart from other vendors in the market is that we offer agent-based and agentless solutions, which provides organizations with comprehensive visibility, detection, and remediation capabilities to secure their cloud infrastructure,” Kulkarni touted.

The vendor treats cloud as another workload to protect under the same Falcon platform, but the key difference is the addition of the agentless capabilities,” he added.

“What is different for cloud is you have to also participate with the cloud vendors and build that shared responsibility model, so you have to track what is happening from a control plane perspective, from a configuration perspective, and that's you can do that in an agentless way by consuming the logs and activity information from the cloud providers,” Kulkarni explained.

Fighting Alert Fatigue

Additionally, CrowdStrike's new unified console also aims to address the alerts fatigue security teams are having because a central view can help reduce the time to detect, respond, and remediate threats.

Many security teams cannot keep up with streams of alerts, “so it is very important to have actionable alerts that are really true positive, very low false-positive rates, and add to that is the ability to remediate,” Kulkarni said, adding that this one of the reasons why CrowdStrike also announced an automated remediation workflow for Amazon Web Services (AWS), extending Falcon Horizon’s existing capabilities for Microsoft Azure and Google Cloud. 

The expanded service for the three public cloud providers uses CrowdStrike’s security orchestration, automation, and response (SOAR) framework Falcon Fusion to automate the remediation. 

“Having one platform that covers your assets wherever they are, but also that works with you on your digital transformation journey is important,” Kulkarni concluded. “And that's what we aimed to provide all of our products under a single platform.”