CrowdStrike Cautiously Expands Its Agent-Based Red-Team Capabilities

Do not say Falcon AIDR anymore, call it Falcon Guardian.

CrowdStrike has just formalized this rebranding. It accompanies it with several functional enhancements, notably in shadow AI discovery, access control, and the junctions with telemetry. The AI gateway component remains in beta. Its general availability is planned for the fourth quarter.

Junctions are also being established with CrowdStrike’s Falcon Adversary OverWatch (managed threat hunting) and Falcon Complete (MDR) services. The former can now leverage the Falcon Guardian context. The latter will be able to do the same by the end of September.

NVIDIA enters the agentization of the QuiltWorks project…

Another new brand: Falcon IQ. It brings—with NVIDIA Nemotron models—a layered agential layer to the QuiltWorks project.

Read also: QuiltWorks project: CrowdStrike builds a coalition to plug the AI-induced gaps

Launched in April 2026, QuiltWorks leverages OpenAI and Anthropic models for vulnerability identification, with Falcon as the backbone. It brings together partners offering remediation services (and cyber insurance).

Falcon IQ is also expected to automate both the validation and prioritization of vulnerabilities and the production of remediation playbooks.

… and in CrowdStrike’s AI Lab

NVIDIA is also involved with CrowdStrike’s Cyber Superintelligence Lab (invested $100 million over five years). Its first fruit is SafeMind. It is a family of models and harnesses that, when combined, form an “attack-defense agentic system.” In other words, automated red team testing.

© NVIDIA

NVIDIA has supplied defense-oriented material. Specifically, Nemotron 3 Ultra to train the orchestrator and Nemotron 3 Super to generate detection rules.

CrowdStrike offers little detail on the practical availability of SafeMind. The entire suite is expected to run within the Falcon platform. There will be autonomous access to the different models and harnesses as part of QuiltWorks, with a form of entry selection—“trusted access.”

CrowdStrike lands on Google Cloud and in Gemini Enterprise

Rather than leveraging Google’s LLMs, CrowdStrike is establishing on its own cloud. It has deployed the Falcon platform there, at least for the United States. This complements hosting on AWS (commercial regions plus GovCloud) and the “sovereign” options announced at the start of 2026 in India, Saudi Arabia, and the United Arab Emirates (data localization on-site, while maintaining access to telemetry and threat intelligence).

Falcon is also slated to arrive on Snowflake, where prepaid credits can be used to purchase it on the marketplace. CrowdStrike promises, among other things:

  • Federated search, to query Snowflake data from Falcon
  • Ingestion of Snowflake data into the SIEM
  • Routing of telemetry to Snowflake

In the Google Cloud ecosystem, a connection is established with the Agent Gateway. CrowdStrike also integrates three components in Gemini Enterprise: its “agentive analyst” Charlotte AI, the Falcon MCP server (officially still in preview), and Falcon Shield at the agent registry level.

Read also: Double acquisition for CrowdStrike: Zero Trust in the background

Which, CrowdStrike notes, opens to 12 more partners: Abnormal AI, Artemis Security, AttackIQ, ExtraHop, HackerOne, Horizon3, Netskope, Picus Security, Rubrik, SafeBreach, Terra Security and Zscaler, directly connected to the Falcon SIEM.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.