Surprisingly Useful AI Article Enhancements
CrowdStrike has launched SafeMind, a family of purpose-built security models and agent harnesses developed by its Cyber Superintelligence Lab, designed to run natively in the CrowdStrike Falcon platform.
The system, unveiled at the company’s Fal.Con 2026 conference in Las Vegas, was built using Nvidia Nemotron open models with CoreWeave providing AI cloud infrastructure for training and inference.
SafeMind consists of two distinct models – one offensive, one defensive – operating inside a closed-loop system where the two continuously challenge each other, with the aim of improving detection and response over successive cycles.
CEO and Founder, George Kurtz, told attendees the system was designed to close a gap between attackers and defenders.
“The real gap that I saw was that the attackers had frontier AI, and the defenders didn’t,” Kurtz told the crowd. “And that changes now.”
Two models, one loop
SafeMind ships with two models trained on data from CrowdStrike’s Falcon sensor telemetry, threat intelligence, Falcon Complete managed detection and response event annotations and 15 years of incident response fieldwork.
Red Tempest is the offensive model, built for advanced attack scenarios and designed to emulate AI adversaries. Blue Solano is the defensive model, built to deploy measures that defenders use in production environments.
The system’s harnesses tie both models together in a co-evolving loop. An offensive red-team agent finds an exploit path, a defensive blue-team agent closes it, and the findings are fed back into the system to block future attacks. The loop continues until no further viable attack path remains.
The harnesses also work with third-party frontier and open-source models, giving users the option to bring their own models while using CrowdStrike’s harnesses for orchestration.
“SafeMind brings offensive and defensive models together in a system trained on CrowdStrike’s unique cyber data,” Kurtz explained. “It finds weaknesses, strengthens protection and gets smarter with every cycle.”
Nvidia’s role
Nvidia’s Founder and CEO, Jensen Huang, appeared at the conference to announce the collaboration, describing the challenge as fundamentally compute-intensive.
“Cybersecurity in the age of AI will be a continuous contest between adversaries using AI to scale attacks and defenders using AI to expand detection and response,” Huang told the crowd of 10,000 security professionals. “Cyber defence will be among the most compute-intensive applications of AI.”
CrowdStrike built SafeMind’s defensive model using Nvidia’s Nemotron open models, post-trained with CrowdStrike’s own cyber data and threat intelligence. Specifically, Nvidia Nemotron 3 Ultra orchestrates the defensive agent harness, while a fine-tuned Nemotron 3 Super powers SafeMind’s rule-generation sub-agent.
The open-model approach meant CrowdStrike’s security teams could post-train on their own threat data without sending it to an external provider, and could customise the AI to their own environment – something not possible with a closed frontier model.
“Your decade and a half of security data that we can train on – we can take a frontier model and make it incredibly good at cybersecurity,” Huang remarked to Kurtz during the keynote.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Huang also described the relationship between the harness and the model in mechanical terms.
“The harness is essentially the exoskeleton of the large language model,” he explained. “The large language model is the brain. The exoskeleton turns it into an agent – and this exoskeleton doesn’t have to be the same shape and capability for every domain.”
Testing against a digital twin
Nvidia and CrowdStrike evaluated the SafeMind system in an isolated environment modelled on Nvidia’s own accelerated computing infrastructure, creating what amounts to a digital twin of Nvidia’s network.
Nvidia security experts reviewed the environment and threat paths for realism. The same environment supported every attack run, detection test and evaluation metric, enabling consistent comparisons across configurations.
In the testing loop, an offensive red-team agent harness ran reconnaissance, assault and compromise sub-agents executing attack paths inside the test environment. The blue-agent harness monitored via Falcon sensors, generated detection candidates, validated them and promoted them to the live detection engine.
“The basic framework of SafeMind – an adversarial model acting on a digital twin of the environment, with a defender model in a continuous cat-and-mouse loop, eventually learning how to secure itself – this basic framework applies to robotics, edge computing, enterprise computing and just about everything,” Huang observed.
Building the specialised defensive agent
The technical work underpinning SafeMind’s defensive capabilities involved several layers of specialisation.
To create the detection-writing expert, CrowdStrike used Nemotron 3 Super as the base for its NL2LogScale model, applying continual pretraining on cybersecurity knowledge, supervised fine-tuning and reinforcement learning with verifiable rewards. The fine-tuning used 9,349 detection-generation and multistep repair examples spanning 59 programmatically generated error types.
The defensive harness combined six mechanisms to ensure detection quality: a schema knowledge base, telemetry grounding, specialised detection authoring, artifact linting, detection replay and independent review. Failed checks returned structured feedback for correction and another attempt, encoding practices normally applied through manual detection-engineering review.
For reinforcement learning, CrowdStrike used Nvidia NeMo Gym to validate and execute generated queries, with invalid queries receiving real engine errors and up to five repair attempts. Unresolved attempts received zero reward, while valid queries were scored on how closely their returned events matched reference queries.
What the evaluations showed
CrowdStrike’s internal evaluations painted a picture of significant gains over both frontier and open-source baselines.
Compared to leading frontier models, SafeMind delivered a 29 per cent higher detection rate, six times faster end-to-end remediation and 99 per cent cost savings on detection and remediation, according to CrowdStrike.
In backtesting against recorded attacks, Nemotron 3 Ultra with a default harness saw an average of 16.5 per cent of generated detections actually detect the recorded attack across eight independently seeded sessions. Adding the tuned harness, customised Nemotron 3 Super, domain context, tools and validation raised the mean to 41.9 per cent across six sessions – a 2.5-times improvement.
Live-fire testing proved more revealing. From the optimised open pipeline, 11 backtest-passing detections were deployed against eight unseen attacks. Five of the 11 open detections (45 per cent) detected at least one attack, compared with 10 out of 35 frontier detections (29 per cent). The open pipeline averaged 2.6 detections per detection, compared with 1.1 for the frontier system.
After further validation for behavioural grounding, multiple signals and absence of environment-specific strings, three open detections qualified as “gold” and covered all eight attacks. No frontier detections qualified as gold.
The companies noted the evaluation covered one scenario family and small detection sets, meaning cross-scenario generalisation remains untested. Limited benign traffic also means the noise test does not represent production false-positive performance.
Chief AI and Autonomous Systems Officer, Dr. Bartley Richardson, described SafeMind as a foundation for future development.
“With the models and harnesses together in a co-evolving agentic system, defenders can now act at machine speed,” Richardson added. “This is the foundation for the next decade of AI security.”
Falcon IQ and Project QuiltWorks
Alongside SafeMind, CrowdStrike also launched Falcon IQ, a platform designed to operationalise its Project QuiltWorks program through agentic workflow automation.
Project QuiltWorks is powered by frontier models from OpenAI and Anthropic, along with open Nemotron models from Nvidia. It unites CrowdStrike’s AI-driven vulnerability discovery and adversary-informed prioritisation with remediation services from systems integrators, cloud infrastructure from Amazon Web Services and financial protection from cyber insurance providers.
Falcon IQ uses more than 50 agents to automate workflows in assessment, prioritisation and remediation. Built on Falcon Foundry and Charlotte AI AgentWorks, CrowdStrike’s no-code agent development platform, it allows partners to build and tune custom agents for individual customer needs.
Chief Business Officer, Daniel Bernard, argued the platform changes the economics of securing frontier AI risk.
“Agents do the heavy lifting, partners scale delivery and organisations gain protection in a fraction of the time and cost,” Bernard remarked. “QuiltWorks proved the model. Falcon IQ advances it from manual to the speed of AI across the Falcon platform.”
Falcon IQ brings the entire QuiltWorks assessment process inside the Falcon platform, correlating customer telemetry, CrowdStrike threat intelligence and Falcon OverWatch findings automatically. Partners load their services catalogue directly into the platform, and agents produce actionable playbooks mapping findings to partner services.
A co-branded, customer-facing dashboard inside Falcon IQ lets QuiltWorks partners deliver findings in their own branding and language, with customers tracking progress against their remediation plan in real time.
Vice President of Enterprise AI at Nvidia, Justin Boitano, highlighted the flexibility the open models provide.
“With open Nvidia Nemotron models powering Falcon IQ, CrowdStrike and its partners can build and tune defence agents that evolve according to the unique needs of every customer,” Boitano added.
The threat landscape
The announcements arrive against a backdrop of escalating AI-enabled attacks. CrowdStrike reports that AI-enabled attacks rose 89 per cent in the past year and the fastest eCrime breakout time has reached 27 seconds.
Co-Founder and Chief Executive Officer of CoreWeave, Michael Intrator, pointed to the production demands of cybersecurity as a proving ground.
“The real test of AI is what it can do in production, at scale, when the stakes are highest. Few environments put that to the test more than cybersecurity,” Intrator commented. “We’re proud to power SafeMind across training and inference as CrowdStrike puts specialised AI to work against real-world threats.”
Huang framed the open-model approach as key to giving defenders an asymmetric advantage.
“There are many applications in the world where you must have the ability to fine-tune, to post-train – to create an AI that is super good at a particular domain,” he told the audience. “Nemotron was created for precisely that. Completely free. Incredibly fast. You have the ability to have an asymmetric advantage against whatever comes your way.”
CrowdStrike indicated that trusted access for standalone SafeMind models and harnesses will be part of the Project QuiltWorks program, while the full system will operate natively in the Falcon platform.
Last Updated on September 2, 2026 by Nick Ross



