Amol Kulkarni, chief product and engineering officer at CrowdStrike. Source: CrowdStrike

SAN FRANCISCO – CrowdStrike announced plans to expand its CrowdXDR Alliance and Falcon extended detection and response (XDR) platform during the RSA Conference. The move came on the heels of its CFO Burt Podbere stating that the security vendor expects to continue to gain market share in the endpoint and XDR space from VMware Carbon Black during its latest earnings call.

When asked about the implication of Broadcom’s VMware acquisition, Podbere expressed that they were “quite excited.”

“When you look at the shared donor that Symantec has imparted on us, we were happy to see Carbon Black and VMware be acquired,” he said during CrowdStrike’s first fiscal quarter of 2023 earnings call.

Broadcom paid $10.7 billion for Symantec’s enterprise security business in 2019, but months after, it sold Symantec’s Cyber Security Services unit to Accenture in early 2020.

VMware is Broadcom’s latest purchase target. The global chip giant announced plans to acquire VMware for approximately $61 billion in cash and stock in late May. The deal received a less than stellar reaction from many industry observers, and CrowdStrike found some Carbon Black customers also have concerns over this deal.

“So we’ve continued to replace Carbon Black over the last few years,” Podbere touted. “And after the acquisition [was announced], we certainly had a lot of customer interest in what that means for Carbon Black customers, in particular, how CrowdStrike can help them in a long-term relationship.”

Looking ahead, “we’ll see how it all plays out. But given what we’ve seen in the past with Symantec, we’re pretty positive,” he added.

VMware bought the cloud-based endpoint security platform Carbon Black in 2019, which now is under VMware’s networking and security business group.

For XDR, VMware also works with partners like Proofpoint, Splunk, and Okta to build an open XDR ecosystem, and announced that it has joined the XDR Alliance ahead of the RSA Conference.

CrowdStrike’s ‘Open and Native’ XDR Approach

The XDR Alliance is a cybersecurity partnership committed to building an inclusive and collaborative XDR framework and architecture. With similar missions, CrowdStrike created its own CrowdXDR Alliance last October to define “the standard for what XDR technology should be,” CTO Michael Sentonas said in an earlier interview.

“A key difference between CrowdXDR and other XDR alliance efforts is we started with a common schema and that's what we are normalizing it too, that's how we are enabling our teams to be able to build detections, but also enabling customers to write their own detections,” Amol Kulkarni, chief product and engineering officer at CrowdStrike, told SDxCentral.

The common schema allows data exchange across all different domains that “reduces the friction in terms of ingesting new datasets and correlating them,” he added. Plus, the CrowdXDR Alliance also looks to build a common vocabulary emerging for XDR detections as well as response actions.

The newest members of this alliance are Menlo Security, Ping Identity, and Vectra AI.

“CrowdStrike continues to bring together the best of both open and native approaches to XDR,” CrowdStrike CTO Michael Sentonas said in a statement.

XDR commonly combines elements of security information and event management (SIEM), security orchestration, automation, response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.

CrowdStrike’s Falcon XDR is built on its EDR platform and cloud log management and observability technology from its Humio acquisition, and it offers the rest either natively or through partnerships. For example, the platform integrates with CrowdStrike’s Falcon Fusion SOAR platform integration and partners with ServiceNow for automated ticket creation.

The vendor furthers the integration to automate Falcon Fusion SOAR workflows directly from a Falcon XDR detection.

“The new announcement is not about having SOAR in the platform that we already released. What we're doing here is XDR is leveraging Falcon Fusion for all of the response capabilities,” Kulkarni explained. “So we added a bunch of response capabilities for XDR and that is using the SOAR capabilities.”

Read all of SDxCentral's RSA Conference 2022 coverage here.