Engineering & Tech
EMBER2024: Advancing the Training of Cybersecurity ML Models Against Evasive Malware
CrowdStrike data scientists are members of a team of cybersecurity researchers that recently released EMBER2024, an update to EMBER, the popular open source malware benchmark dataset originally releas[…]
Falcon Platform Prevents COOKIE SPIDER’s SHAMOS Delivery on macOS
Between June and August 2025, the CrowdStrike Falcon® platform successfully blocked a sophisticated malware campaign that attempted to compromise over 300 customer environments. The campaign deployed […]
CrowdStrike’s Approach to Better Machine Learning Evaluation Using Strategic Data Splitting
“Leakage” in machine learning (ML) occurs when data that an ML model should not learn on is included at training time, often in unexpected ways. This can cause overconfidence in ML model training resu[…]
CrowdStrike Researchers Develop Custom XGBoost Objective to Improve ML Model Release Stability
Extreme Gradient Boosting (XGBoost) is a valuable tool for training machine learning (ML) classifiers, which often come with the problem of surprise false positives (FPs) and false negatives (FNs). Su[…]
Byte Back: Next-Generation Malware Classification Using Binary Transformers
CrowdStrike researchers have developed a next-gen method to train byte-based Transformer blocks that help models “understand” malware files rather than rely on detecting the presence of markers During[…]
Leveraging CrowdStrike Falcon Against Attacks Targeting Okta Environments
As more organizations move to software-as-a-service (SaaS), remote access to applications and data is concentrated among a smaller set of identity providers. These identity providers, such as Okta, mu[…]
Tech Analysis: Channel File May Contain Null Bytes
Key Points CrowdStrike has observed instances internally and in the field in which the content of one or more channel files on disk is all zeroes. This has been observed in the context of a channel fi[…]
EMBERSim: A Large-Scale Databank for Boosting Similarity Search in Malware Analysis
Binary code similarity (BCS) is an important part of training machine learning (ML) models to effectively analyze vast amounts of cybersecurity telemetry. However, BCS has historically focused on find[…]
CrowdStrike Falcon Next-Gen SIEM Unveils Advanced Detection of Ransomware Targeting VMware ESXi Environments
CrowdStrike Falcon® Next-Gen SIEM enables companies to search, investigate and hunt down threats, including detection of advanced ransomware targeting VMware ESXi Initial access to the ESXi infrastruc[…]
CrowdStrike’s Advanced Memory Scanning Stops Threat Actor Using BRc4 at Telecommunications Customer
CrowdStrike’s Advanced Memory Scanning detected BRc4 execution in the wild. CrowdStrike has integrated new indicators of attack (IOAs) for modern endpoint detection and response (EDR) evasion techniqu[…]
- 1
- 2
- 3
- 4
- ...
- 9
- >