CrowdStrike introduced an artificial intelligence (AI)-powered indicators of attack (IoAs) to its Falcon platform during this year’s Black Hat conference, which are trained on rich threat intelligence and synthesized insights with the vendor’s threat hunting team, its executives claim.

The security vendor introduced its original IoA over a decade ago to stop breaches based on a series of adversary behavior, irrespective of easily changed indicators such as the individual malware variants.

“CrowdStrike pioneered the concept of using IoAs within EDR,” Brian Trombley, VP of product management and endpoint security at CrowdStrike, wrote in an email to SDxCentral. “Instead of assessing whether a given file should be treated as malicious, IoAs look at the overall behavior on the endpoint, wherein a malicious actor may use legitimate tools in performing an attack. Attacks are much harder to hide when you’re looking at the full behavior versus assessing the merits of an individual file.”

CrowdStrike’s newly introduced cloud threat hunting service uses these cloud-based IoAs along with indicators of misconfigurations to help threat hunters to figure out whether an alert is a true-positive one and detect security incidents more quickly, according to Param Singh, VP of Falcon OverWatch at CrowdStrike.

While the IoAs were historically crafted and tuned by threat hunters, and CrowdStrike has used machine learning (ML) for threat detection and prevention, this time, it incorporates AI capabilities with the IoA, “such that IoAs are now a collaboration between our expert humans and machines,” Trombley said. 

The AI-powered IoA is also designed to detect new classes of attacks and emerging techniques more quickly. CrowdStrike claims it has already identified over 20 novel adversary patterns that have been validated by human experts and used on the Falcon platform for automated detection and prevention. 

CrowdStrike Trains AI With Threat Intelligence, Human-led Expertise

CrowdStrike’s Security Cloud data fabric collects over one trillion security events per day from its customer base, which “gives us incredible visibility into the threat landscape,” Trombley said.

“We correlate this telemetry using ML and our IoAs to deliver detection and prevention for all of our customers,” he added. “The more customers we support, the more insight into the threat landscape we gain, allowing us to stop breaches in an ever more effective manner.”

The new AI-powered IoA is built on the Security Cloud and existing threat detection and response capabilities. Facing sophisticated and well-resourced adversaries requires the fusion of AI-powered analytics and human expertise from the threat hunters and researchers, Trombley pointed out. 

As CrowdStrike’s Falcon OverWatch analysts use IoAs for threat hunting, the vendor learned lessons from the team, “where we use a combination of AI to find the ‘seeds’ of an attack from the massive volume of signal we receive on a daily basis, then apply human expertise on this filtered data,” he noted. 

“With these new AI-powered IoAs, we are bringing the power of cloud-native scale and compute to creation of IoAs, all at machine speed, while maintaining the precision of our experts reviewing and approving them before they are delivered to our customers,” Trombley said.