CrowdStrike introduced its cloud threat hunting service during AWS re:Inforce conference, which is led by the vendor’s OverWatch threat hunting team, to target advanced threats originating and operating in the cloud environments.

The OverWatch team has been proactively hunting threats and continuously uncovering the hidden threads, Param Singh, VP of Falcon OverWatch at CrowdStrike, told SDxCentral. As more threat actors follow organizations moving to the cloud, the team takes the same search methodology to the cloud-native application protection platform (CNAPP).

There are around 154 security and IT professionals with more than 300 years of experience collectively in the team, who understand the geopolitical situation and are responsible for threat hunting, data analysis, along with suspicious and anomalous behaviors and novel attacker tradecraft investigation.

“We are human-based, and I take a lot of pride in that,” Singh said. And “we are [operating] 24x7x365, and that's what makes us unique in this industry where we are doing actual threat hunting rather than threat detection.”

He argues that automated programs, similar to the security information and event management (SIEM) tools, are merely threat detection services. “When you say threat hunting, it means human-driven, human-less threat hunting is threat detection.”

“Threat hunting comes into play when some human analyst who has vast years of experience looks at all these needles in the haystack and tells whether this is a new pattern,” Singh noted.

Machine-led, automated products can handle known threats at the endpoint level. But for those unknown, net new threats and false negatives in the alerting system, only advanced and skilled threat hunters are able to see its pattern and provide a holistic picture, Singh argues.

Telemetry is Key

CrowdStrike’s human-driven cloud threat hunting services monitor and alert adversary activities across multi-cloud infrastructure for Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and other cloud providers, 

It also hunts zero-days and hands-on-keyboard activities, while providing cloud-based indicators of attack (IOAs), the vendor claims.

Those capabilities are based on the telemetry from more than 1.5 billion containers. “As the developers are using different technology, we have to increase our sophistication and increase our telemetry along with that advancements,” Singh said.

CrowdStrike collects telemetry data from containers and all the workload that the customers are running, and takes it back into its threat intelligence systems. The vendor then converts that information into a threat graph for threat hunters to determine if it’s a true positive alert with the help of the indicators of attack or misconfigurations, he added.

“We stop breaches across the board. And we are becoming the single point where you can go and see the CNAAP data, see your operating systems, see your on-premise systems, everything in a single console. And you will see the threat actors that we are blocking and the malicious threats that we have blocked over there,” Singh concluded.