CrowdStrike is turning AI against itself with the launch of SafeMind, a new family of cyber security models and agent harnesses designed to autonomously identify and remediate threats at machine speed.
Developed by the CrowdStrike Cyber Superintelligence Lab, SafeMind will operate natively within the Falcon platform, pairing an offensive model that searches for attack paths with a defensive model designed to shut them down.
The two models operate in a continuous loop through a set of agentic harnesses, allowing the system to test and improve its defences.
CrowdStrike said SafeMind differs from general-purpose frontier AI models by being purpose-built for cyber security and trained on Falcon sensor telemetry, threat intelligence, Falcon Complete MDR event annotations, and 15 years of incident response experience.
The initial release comprises two models: Red Tempest, an offensive red-team model designed to emulate advanced AI-powered adversaries, and Blue Solano, a defensive model designed to deploy measures used by security teams in real-world environments.
“The future of cyber security won’t be defined by AI that simply identifies threats; it will be defined by AI that defeats them,” George Kurtz, CEO and founder of CrowdStrike, said in a statement.
CrowdStrike is building the models using NVIDIA’s open Nemotron models, with NVIDIA acting as its AI design partner. CoreWeave is providing AI cloud infrastructure for SafeMind training and inference.
The system’s agentic harnesses can also work with other frontier and open-source models, giving customers flexibility over the models they use while allowing CrowdStrike to control costs. The company said this moves beyond AI systems that merely identify a security risk towards systems capable of taking action against it.
Nvidia CEO Jensen Huang said the growing use of AI by attackers and defenders would make cyber defence one of the most compute-intensive AI applications.
“Cyber security in the age of AI will be a continuous contest between adversaries using AI to scale attacks and defenders using AI to expand detection and response. Cyber defence will be among the most compute-intensive applications of AI,” Huang said.
“SafeMind combines Nvidia Nemotron open models with CrowdStrike’s deep cybersecurity expertise, trusted security data, purpose-built agent harnesses, rigorous evaluations, and safeguards – creating a frontier agentic cybersecurity stack designed to operate at machine speed. Powered by Nvidia accelerated computing, SafeMind makes AI a force multiplier for defenders.”
CrowdStrike said evaluations against leading frontier models and open-source baselines showed SafeMind delivering a 29 per cent higher detection rate, six times faster end-to-end remediation, and 99 per cent lower costs for detection and remediation.
“The real test of AI is what it can do in production, at scale, when the stakes are highest. Few environments put that to the test more than cybersecurity,” Michael Intrator, co-founder and chief executive officer at CoreWeave, said.
“We’re proud to power SafeMind across training and inference as CrowdStrike puts specialised AI to work against real-world threats.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.