CrowdStrike Unveils Coordinated Multi-Agent Investigations Across Five Domains
CrowdStrike has announced coordinated multi-agent investigations on a shared context layer, with customers setting autonomy levels from human-in-the-loop approval to fully autonomous execution. According to the company, AI agents now run attacks across several systems simultaneously, necessitating a corresponding shift in investigation methods.
Multi-Agent Investigations Across Five Domains:
CrowdStrike’s multi-agent investigations cover endpoint, identity, SaaS, cloud, and network domains.
NIS2 Directive and 24-Hour Early Warning:
In Europe, the NIS2 directive mandates that essential and important entities file an early warning within 24 hours of becoming aware of a significant incident, with a full notification required within 72 hours. This directive holds management bodies personally accountable for cybersecurity risk-management measures, regardless of automation levels.
Speed and Trust:
Michael Sentonas, CrowdStrike’s president, emphasizes the importance of trust in security operations centers (SOCs). He argues that while agents can run faster, the speed doesn’t absolve management bodies of responsibility. The NIS2 directive underscores this point by placing accountability directly on those who approve cybersecurity measures, regardless of automation.
Challenges and Implications:
Competition in the market is intense, with Databricks’ acquisition of Panther Labs challenging established players like Splunk and CrowdStrike. As autonomy levels increase, so does the potential cost of failures, highlighting the need for human oversight even in automated systems.