CrowdStrike
– CrowdStrike

CrowdStrike unleashed a flurry of updates to its Falcon security platform, including new cloud security posture management and extending zero trust assessment to endpoints.

The security vendor will also host its virtual Fal.Con this week, and more than 20,000 people registered to attend the event, said CrowdStrike CTO Mike Sentonas.

“One of the big announcements that we’re making this week is really talking about the fact that transitioning to the cloud is not optional,” he said in an interview with SDxCentral. “What we are trying to do is get people to understand that they have to change how they think about security, and in particular how they think about cloud security.”

To this end, one of the big roll-outs centers on cloud security posture management (CSPM) and a new module called Falcon Horizon. CrowdStrike developed the CSPM capabilities in-house, and it automates security cloud management throughout the application development lifecycle for any cloud.

Falcon Horizon also provides continuous discovery and visibility of assets across private, public, hybrid, and multi-cloud environments, as well as real-time monitoring of cloud resources to detect misconfigurations and fix these vulnerabilities.

“The goal is to provide visibility and control across multi-cloud to give you full monitoring of cloud resources, even down to being able to do things like threat hunting in ephemeral workloads,” Sentonas said. “So if something that comes up for a couple of minutes is torn down and destroyed, you’ve still got the ability to do hunting and forensics.”

CrowdStrike also offers Cloud Security Assessment services to analyze their cloud environments and identify potential misconfiguration issues as well as the best methods to mitigate and resolve them.

Falcon zero trust assessment

Another new capability called Falcon Zero Trust Assessment (ZTA) extends real-time security posture assessments across all endpoints. It also enforces conditional access based on device health and performs compliance checks to mitigate risks.

ZTA uses zero-trust and conditional access technology Crowdstrike acquired from Preempt Security when it bought that vendor for $96 million last month.

Additionally, CrowdStrike partnered with identity provider Okta and cloud security vendors Akamai, Cloudflare, Google Cloud, Netskope, and Zscaler to boost conditional access based on risk profiles, which CrowdStrike says will stop threats in real time.

Falcon forensics

A third new service called Falcon Forensics provides forensic triage analysis for CrowdStrike’s incident response partners that enterprises call in after they’ve been breached or suffered another critical security incident.

“Falcon Forensics gives incident responders the visibility and automation that they need to handle security incidents based on the technology and the methodologies that we have developed,” Sentonas said.

Advanced threat hunting

CrowdStrike also updated its Falcon platform to simplify threat hunting and provide a unified view of threat activity for security teams by integrating third-party threat intelligence data with Falcon detections. Organizations can enable the third-party app in the CrowdStrike Store to leverage outside threat intelligence feeds from partners, including PassiveTotal, Sixgill, DomainTools, OPSWAT, and other[s] to provide additional context during a threat investigation, which helps speed triage and remediation.

“These vendors have their own unique value propositions, and what we bring together is all of that information and get rid of the time required to integrate that for the end user,” Sentonas said. “It allows customers to get visibility of sophisticated adversaries from these multiple threat feeds and correlate them with the endpoint, so that they get contextualized threat intelligence without having to do any other work.”