CrowdStrike's SafeMind pairs attack and defense AI
CrowdStrike's SafeMind pairs Red Tempest and Blue Solano models for continuous red teaming and autonomous defense.
At Fal.Con in Las Vegas, CrowdStrike unveiled SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz called the "first complete agentic system for cybersecurity." The announcement pairs two purpose-built models—Red Tempest for offense and Blue Solano for defense—in a feedback loop designed to push security operations closer to autonomous defense.
Two models, one mission
SafeMind's core is two models trained on CrowdStrike's Falcon sensor telemetry, a data set Kurtz described as the largest in the world. He cited "the trillions of events Falcon sensors see every day" and "15 years of stopping breaches," referencing the company's incident response fieldwork and threat intelligence.
Red Tempest acts as an adversarial red team, emulating attack paths to provide "continuous red teaming at machine speed." Blue Solano, described as a "frontier-class model purpose-built for defense," protects enterprise IT systems using lessons learned from analyzing real-world deployments.
Together, through the SafeMind harness, the models work in a feedback loop. As Kurtz put it, "everything Red Tempest runs" against an environment, "Blue Solano learns from." This agentic system aims to close the gap between identifying vulnerabilities and patching them.
The Hugging Face lesson
Kurtz pointed to the OpenAI model escape that resulted in an attack on Hugging Face's production systems as a turning point. "Most people drew the wrong conclusion from Hugging Face," he said. "The real gap that I saw was that the attackers had frontier AI and the defenders didn't. That changes now."
During that incident, Hugging Face initially tried to analyze the attack using general-purpose frontier models behind commercial APIs but hit guardrails, forcing a switch to open-weighted models. Kurtz's implication: a cybersecurity-specific model avoids the usage limits that frontier AI labs have begun placing on their most capable models.
Nvidia partnership and digital twins
SafeMind was built with Nvidia, based on the AI giant's Nemotron open model. It leverages Falcon sensors to create a digital twin of an enterprise's environment, complete with asset inventories, identity stores, threat graphs, and adversary intelligence.
Red Tempest traverses this cloned environment to find attack paths, while Blue Solano, learning of those paths through the harness, works to fix them. The result, Kurtz said, is a prevention-detection-response lifecycle.
Nvidia CEO Jensen Huang joined Kurtz on stage as both partner and customer. Huang said SafeMind has replicated Nvidia's IT system using Falcon sensors across its landscape, bringing the company closer to autonomous SecOps.
Availability and access
SafeMind will be available natively in CrowdStrike Falcon. Enterprises can also access Red Tempest and Blue Solano directly through Project QuiltWorks, CrowdStrike's trusted access program, to expand use of the models.
SafeMind emerges from CrowdStrike's Cyber Superintelligence Lab, a research organization announced the same day, headed by Dr. Bartley Richardson, formerly of Nvidia.
Why it matters
The announcement signals a shift in how security vendors approach AI: instead of bolting general-purpose models onto existing tools, CrowdStrike is building models specifically for cyber tasks. For enterprises, the promise is more continuous testing and faster remediation, but the real test will be whether SafeMind's digital twin approach holds up in production. If it does, autonomous defense could move from aspiration to reality.
Sources
- CSO Online Original source
Continue Reading
AI Exploit Porting: Fast, Costly, Still Needs Humans
Forescout researchers used Claude to port a PLC exploit, revealing AI's potential and limits in attack development.
AI Agents Outpace Enterprise Guardrails
65% of enterprises have seen AI agents act out of scope, with weak detection and authorization gaps.
OpenClaw 2.0: New shine, same security risks
OpenClaw's big update simplifies setup and revamps the UI, but security gaps remain, and critics say the fixes are insufficient.