Please welcome President of CrowdStrike, Michael Sentonas. Morning, Stockholm. Welcome to day two. I hope everyone had a great first day yesterday. I hope you all got a chance to head over to the expo hall or got a chance to walk around. I kind of realized that this AI thing is a bit of a big deal, huh? There is a lot of AI everywhere, and it is obviously something that I am going to be talking a lot about. Here is the thing, there is a reason why AI is dominating every conversation, and there is a reason why you are seeing it all over social media. We are watching the biggest technology transformation of our generation unfold right in front of our eyes. Every major shift in technology forces a security transformation. Cloud did it. Mobile did it. The internet did it. AI will dwarf them all. That creates an extraordinary opportunity for businesses, an opportunity for defenders, for all of us. Unfortunately, it creates incredible opportunity for the adversary. You heard this yesterday. I believe we crossed the line. In the last few weeks, we have seen something fundamentally change. Agents have escaped evaluation environments. They have discovered vulnerabilities. They have moved across systems. They have compromised infrastructure they were never supposed to touch. We crossed a line. It is a big thing to say, but I think it is the right thing to say. We have seen AI agents pursue an objective, encounter an obstacle, change their approach, and keep going straight through. Adam is going to talk to you a lot today about how we are seeing AI used to orchestrate attacks against real-world targets. Think about what has changed. The software we use has become an actor. For decades, software did what we programmed it to do. Now, software can decide how to accomplish a goal. It has moved from execution to agency. Think about that concept. That changes cybersecurity. The question is no longer can AI conduct a sophisticated cyber attack? We know it can. We have seen that. We have talked about it. The question now really becomes what happens when millions of AI agents can act, and sometimes together, at machine speed on both sides? Software has agency. Think about that concept. Are we, as defenders, ready for that? Because this is bigger than cybersecurity. Every company, every employee, every developer, every attacker is using AI. There is not a person in this room that is online that is not using AI. But AI is different from every computing revolution that came before it. The PC changed where we compute. The internet changed how we connect, how we communicate. Mobile changed where we work. Cloud changed where applications run. AI changes who or what can act, and that changes something more fundamental. AI changes how we trust. A couple of big topics for the morning here. It also changes just everything about how we think about what we have spent years protecting. Applications, devices, identities, infrastructure, data, those things all still matter. Of course, they do. They always will. AI is changing every one of them. There is not a single thing on that slide that is not being changed. Many of you are already writing code with AI. Your coworkers are using enterprise and public models. You are deploying agents with access to your systems and your data. They are touching your identity. Cloud workloads are more dynamic than ever, and human and non-human identities are multiplying faster than anyone can govern them. Here is the thing, AI is part of the enterprise. The business is driving it. The business is wanting it. Everybody is adopting it. The enterprise is not simply using AI anymore. AI is part of the enterprise. Once AI becomes part of the enterprise, it becomes part of what we have to defend. We all understand that, but it is also now changing how we defend. The speed of innovation, the speed of exploitation, we are going to talk a lot more about that in Adam's session. Those two numbers coming closer together. While we are thinking about regulation, we are thinking about privacy, you have AI lawyers. The adversary does not care. They are not waiting. They are using it for reconnaissance, for vulnerability research, exploit development, social engineering. The agent breakout that we discussed yesterday, think about that. This is not what AI might do in the future. This is not pondering about what is going to happen at Black Hat in five years. This is what it did on its own. That debate is now over. The question is not whether AI changes cybersecurity. It is about who uses it better, and it is a very simple question. Do you use it better, or does the adversary use it better? Very simple. When we start to think about how this all works, you are the adversary, and we start to think about where this is all going to play out, it gets answered on the endpoint, on your agents. This is where we start to talk about AI Detection and Response. Let us talk a little bit about AI governance. Organizations heavily investing in it, discovery, posture, policy, compliance, those things all matter. Of course they are. I am not going to tell you they do not. They all answer one question, what could happen? The question that I want answered, the question that I want to answer with you all is what is happening right now, because AI does not necessarily run on simple policy, it executes at runtime. Tool calls happen at runtime. Threats unfold at runtime. We have seen this before. We know this story. The internet created network security. The endpoint created EDR. The cloud created cloud security. Just like EDR secured the endpoint at runtime, AI needs its own runtime category. We call that AI Detection and Response. Here is the fundamental change. AI agents do not just generate answers, they take action. We have talked about this. The architecture goes well beyond just agents. You have models, you have identities, you have data, you have applications, there is infrastructure. All of this has to be protected. You need to secure how AI is built, how it is accessed, how it behaves, what it is allowed to do at runtime. This requires a totally different category. AIDR brings this all together, discovery, posture, identity, data protection, runtime guardrails and response across SaaS, endpoint, cloud. This is not just another security product. I talked about this. EDR defined how we secured the endpoint, AIDR defines how we secure the AI estate. Guardian is how CrowdStrike delivers it. George introduced this yesterday, incredibly proud to see this announcement. The product went live at the very minute George put that slide up, which is absolutely fantastic. I want to show you why it matters. Because once AI becomes part of the enterprise, visibility is no longer enough. You need to know what is running, what it can access, what it is doing, where to draw the line. That is Guardian. It gives you runtime visibility across the entire AI estate, what your agents are doing, what they are accessing, what actions they are taking, whether you know about it or not, and where you need to step in, importantly, before something goes wrong. We know everybody is talking about securing AI. The industry is talking about it. When we talk about Guardian, what is really, really exciting about this is we have been running this inside CrowdStrike for some time. We have people in this room that have been running this for some time. We want our people at CrowdStrike building with AI. We do not want to slow that down. We want to use the power, the benefit, the advantages that comes, but we need to know what everybody is doing. We need to know what every agent is doing, where it is deployed, and who is using it. We want to set the rules for what people can use and what it can do. That is what we use it for. Let me show you how it works. Incredibly proud to show you a big demo. Roll the demo of Guardian. Introducing Falcon Guardian, our new solution for securing AI agents where they execute, on the endpoint, at runtime. The Falcon sensor now extends to AI agents. No hooks, no SDK. Guardian fuses AI and OS telemetry from prompt to process across your entire AI estate. Let us see this in action. Last month, a Fortune 500 company found 18,000 AI agents running across their endpoints. They approved 300. Every dot you are looking at is an AI agent running right now discovered by Guardian on day one, from OpenAI Codex, Claude Code, Cursor, and Kiro to unclassified shadow AI. Active, dormant, or hiding in plain sight, they are detected by sensor, scheduled scans, and DNS queries. You see them, now you can control them. Start with the simplest case. Ken, in customer service, is working on a billing dispute. He reaches for Gemini out of habit. It is what he uses at home. Guardian blocks it and points him to Claude, the approved app. He moves to Claude and pastes in the customer record, including a full credit card number. Guardian masks it at the prompt. The number never reaches the model. Ken gets a policy notice, the security team gets the event. Ken was typing. Agents do not type, they act, and they can act on text that is invisible to humans. Marcus in engineering prompts Claude Code to debug a Lambda deployment and walks away. The agent gets to work. Unaware, Marcus just put his whole company at risk. Falcon Guardian brings these risks into sharp focus. In a cluster of high-risk Claude Code agents, one lights up as critical with a threat score of 90. Guardian identifies it as Marcus' agent and resolves it to his AD identity. Unknowingly, his agent introduced three critical risks, a malicious skill, an attempt to transmit data to an external destination, and AWS credentials were accessed outside of their expected scope. His agent footprint shows every skill, tool, MCP server, and connection, feeding one composite threat score. The sensor builds a single causal timeline, prompts, skills, and tool calls from the agent fused with process spawns, file reads, and network egress from the operating system. One story end to end. This is the agent graph. Marcus' agent follows a link in the repo docs to a GitHub issue thread. Buried in that thread, a hidden instruction, an indirect prompt injection. It tells the agent to load a skill and exfiltrate Marcus' credentials. Marcus never sees it. Guardian stops it. The credential exfiltration is blocked before the keys leave the machine. Where else is the skill running? In an AI first world, security teams can now use their agents to directly investigate these events with the Falcon MCP server. In Claude Code, an analyst queries the Falcon platform for agents that have previously used the skill. 12 found, every attempt blocked, no credentials left any machine. The hosts are quarantined for investigation. That was the prompt layer. Here is an attack that never touches it. On another workstation, Claude Code installs a new plugin from a public repo. It registers a local MCP server to assist with project indexing. The prompt layer looks clean, the model is not being manipulated. But that MCP server quietly performs credential theft and exfiltration on each tool call to index project. The sensor layer catches the exfiltration. Prompt-only security tools see a clean plugin. The sensor sees the attack. That is layered protection. Now the operational side. Guardian tracks token usage in real time, per user, per agent, and per model. Each session attributed, each model accounted for. Finance has expense visibility. Security sees anomalies. Both get the data from the same source. Two attacks, two layers, the prompt and the process. One sensor, one graph, one truth. This is Guardian. This is security for AI. What do we think? That is Guardian. That is exactly what happens when AI security meets the Falcon sensor. The great news is, everybody in this room that is using Falcon Flex, everyone online, contact your account manager, contact your channel partner, and you can be running that by the end of the day. Pretty straightforward. A lot of the features that I showed you leverage the sensor. Here is the great news. That capability shipped in our sensor some weeks ago now. So as I said, a lot of people in the room, you are already enabled. It is an entitlement for you to be able to use this, which is absolutely fantastic. For some of you in the room, you are already running parts of Guardian, if not Guardian at all. I do want to take the opportunity to say a big thank you to all of our development partners. We worked with some of the largest companies in the world, some of you in the room today, to test it, to give us feedback, to make it better, to challenge us, because we wanted to know what challenges you, and we wanted to build to you. So big thank you to every customer helped bring this to everybody. I am incredibly excited about this, and you are going to see more from us every month as we keep building out the Guardian platform. But that is not all. George talked about choice yesterday. You need AI flexibility. Every agent you just watched had to reach a model to do its work. It is also what everyone in your company is doing when they use AI. You need model flexibility, and you need model choice. That basically means that when people in the organization are using things inside their environment with different providers, with different accounts, with different models, nobody is deciding who should have access to what. Nobody is checking what is in the prompts before they go. You do not see those requests. You cannot stop them. But at the same time, with everybody using all the different models, firing a whole bunch of queries, you are also paying for a lot of this. Every use, it is very complex. A lot of the times, the first time you see what is going on inside your environment and you see the number and the cost is at the end of the month. That is why we are soon releasing our AI gateway, because our job is not to watch a breach, it is to stop a breach. And you cannot stop what you have no way to reach. Very simple. With the AI gateway, every AI request goes through one path. And for me, that is very simple. Your path. You decide which models your people can use. You decide what is allowed to go out. You make that call while the request is happening. And of course, when we talk about choice, some of you in the room are already running a gateway. I am not asking you to change that. We will work with it. But we will also have our own. So incredibly excited to say this will be shipping in September. The first version runs as a hosted SaaS solution. A hybrid version will follow shortly after, so you can run it wherever your AI runs. Because we know that your AI is not going to stay just in one place. It is going to run in your cloud. It is going to run on your endpoints. Soon, you will be running devices that you have not even thought about yet. So we want to make sure that you can reach it all, and that is including the agent working together with the sensor. And if you are running Guardian, you will get the AI gateway. So great news for you there as well. So let us keep going. I talked about AI changing software. I heard the claps. Thank you. So we talked about AI changing software. So now you are going to see all of your agents. You are going to be able to control them. I have a question for you. Can you trust what they build with? Let me show you what is actually happening inside your environment right now. I think many of you have been dealing with this for a little while now, so I do not think this is going to be a new concept to anybody in the room. We know agents ship at code at machine speeds. Every agent inside your environment is writing code, writing code and pulling packages, building software. When they do, they move very fast. Code gets pushed to a repository. The build kicks off. Dependencies get pulled in from public registries, NPM packages, PyPI packages, open libraries that anyone can publish to. Nobody is reviewing what gets pulled because it happens so quickly. It goes straight into production. No human in the loop. You used to defend at the perimeter. Now the threat comes inside from the software itself when it pulls things down. We have seen this story play out now for a few years. Adversaries exploiting public registries. Adversaries understand this better than anybody else. They know that one compromised dependency can open the door to thousands, hundreds of thousands of organizations. You read about this every week. AI is making software faster than ever, but it is also making the supply chain something that you have to trust. Right now, you cannot. Let us talk a little bit more about this. There is another side to this. AI is not changing how software only how it operates, but it is changing how it is being built. We talk about developers pulling in packages, we talk about those dependencies, but here is the interesting thing. The agents are the ones that are now doing it. A lot of the time, it is not the developer that is pulling down a package that may pause and think about it, should I be doing that? The agents are doing it for them without the developer knowing. Where does this all happen? It happens on the endpoint, where developers build, where packages are downloaded, where code is being executed, and increasingly, where AI agents operate. That is why we believe software supply chain security belongs in the platform, not as another product, not as another console, not as another bill. We do not think security should work that way, especially when you are already dealing with runaway complexity and cost. With Falcon, telemetry and control are already there. We can identify malicious packages before they execute. We can stop compromised dependencies before they enter your applications and do it as part of the platform that most of you in the room are already running. You have seen us give you control of the agents. Now watch what happens when one of those agents tries to bring something malicious into your environment. Roll the supply chain demo. This is Tim in finance. He asked Claude to automate merging monthly reports from five separate payment systems. No code. No technical ask. Claude writes a script, picks the library, and pulls down various packages without Tim having to know any of the technical details. The package is trusted, the version is not. An attacker took over the maintainer's account and shipped a credential stealer. Adversary Intelligence's package repo analysis identified this package as suspicious, and it was blocked on write. Moving into Falcon, we see the action taken along with the reason why. However, this only solves part of the problem. To effectively mitigate risk, you need visibility and control over package installation before malicious code ever runs. This is where Falcon supply chain protection policies come in. An admin can define exactly which packages are permitted using criteria- like approved package managers, acceptable risk tolerance, and cool down threshold. Let's take cool down threshold as an example. Most supply chain attacks seen in the news, such as the recent XZ compromise, share one thing in common, a recent update poisoned a legitimate package. With Falcon, you can set a policy that blocks any package version published within a threshold you define. That single rule can mitigate an entire class of attack before it reaches the endpoint. Back to Tim now, asking his agent to complete another task. The PDF package here was recently updated within the cool down period. The package installation is blocked per the protection policy, stopping any potential risk to the environment before it can be compromised by adversaries. How cool is that? The best part of that story, over 8,000 of you in the room and online are already using this, and this was just the policy that you had to set and turn on because we made this part of the platform. Not another product that you need to buy, not something that we had to go and acquire. We built this. We integrated it. We worked together with the CIO team. Stop what's malicious, put in the policies, get the threat protection from us as well, which is absolutely fantastic. I've spent the last few minutes talking about how agents work, running on your endpoints, pulling in code, taking action. But here's what's easy to miss. Every one of those agents has to access something. They call APIs, they use credentials, they touch sensitive data, they take action across your environment. Every agent has an identity, and in most cases, it's an overprivileged identity. In too many cases, it inherits the human permissions, and you are all deploying them faster than you can govern them. That's just how they work. Who or what created the agent? That's a really, really important question. Who is it shared with? What third-party systems can it access? What permissions does it have, and where can it get to? The challenge isn't granting access to that agent once. It's knowing what it should be allowed to do at every moment it's running and every step. We have to make a big change here. Trust cannot stop at authentication. This is how identity has always worked. You make one decision at login, and then you trust that decision for the whole session. That is what happens when people log in most of the time with most systems. That does not work anymore in this world. AI agents operate continuously. Access cannot be a one-time decision. It has to reflect the task, the data, and the risk around it. Access only when it is needed, tightly scoped to the specific task, short-lived to reduce risk, and gone when the work is done. You need to remove the access. When one agent hands off to another, you have to trace that entire chain so that you have explainability from the request to the agent, to the resource, to the response. That is why we are announcing the CrowdStrike Agentic Identity Provider solution, extending continuous identity discovery, enrichment, zero standing access to humans and to agents. Let me show you, it is better to just roll the demo. Let us go. Emily, a DevOps engineer, wants to use Claude with an AWS MCP server. A CrowdStrike policy secures this end-to-end. It defines the required risk level, trusted device posture, ServiceNow ticket context, and identity verification with MFA needed to grant AWS access with the appropriate roles. Emily must authenticate first. CrowdStrike checks policy conditions are true and requires MFA. In the background, Falcon Guardian discovered the agent and automatically registered it with CrowdStrike's Agentic Identity Provider. Here you can see the agent record has been enriched with information about Emily, business context such as the department she works in, and security information such as risk score, privileges, and account type. This also includes an assigned SPIFFE ID, a stable, standards-based identity that tells us exactly what software is running. With the agent registered and its identity known, we can now enforce the right authorization policies. Emily queries all ECS services for changes in the last 24 hours. Claude communicates with the AWS MCP server and returns the data. Next, she attempts to access production customer data in S3. The policy assigned an AWS role that excludes S3 permissions. All right, I will come back. We lost sound, but we will make sure we get that one to everybody. We will get out a link to everybody. We were going so well with the demos. We have a lot more exciting announcements regarding our Agentic IdP coming at Fal.Con Europe this November. The great thing there as part of the demo was to show you that we now have the ability to give people one-time access, but importantly, to remove it and give access on demand, to give access when they need it, access by role type, access to carry out a specific task, and importantly, make sure that you remove all standing privilege. Big shout-out to the Signal AI team. I saw them earlier. It has been fantastic integrating this with the platform and everything working together. Get over to the expo hall, have a look at the deep dive demos. Really excited to go through what we are going to show you, throughout the rest of the roadmap for next-gen identity. We have given you control of your agents. We have caught what they bring in. We have governed their identity. Now the real question, how does all of this actually work day to day inside your SOC? Over the last couple of years, we have talked about the agentic SOC, the need for that. Last year, I talked about the analyst becoming the orchestrator. That direction has not changed at all. But in a world where autonomous attacks are here, even with an army of agents, defenders still have one problem, and that is time. George talked a little bit about the breakout time. Even with that army of agents, it is going to be really, really difficult to manage time. George showed you that. I will argue that the breakout time is over. Think about what that means. We now live in a world where a model finds a vulnerability and weaponizes it at the same time. It executes it at the same time. Think about that. You are not going to be scanning vulnerabilities and spending weeks to think about where to deal with an issue. There is no gap left to measure. There is no window. We are living in a world where the breakout time is zero. I think maybe to answer George's question yesterday, the new measurement may be the time from when the damage is done to when damage is discovered. And that does not sit well with me when I start to think about that as a concept. We need to start to move to investigations at machine speed. This is why the old SOC model is broken in many ways. Just think about an investigation now. An alert fires on an endpoint somewhere in the network, maybe someone clicked on something in an email, your analyst works on it, another fires on identity, somebody else picks it up, someone goes to lunch, something looks wrong in the cloud. Now you have got a third person involved because they have got the cloud skills. Somebody has to come back from lunch and sit down and work out whether there is one attack or three separate problems, piece by piece. Probably sounds a bit familiar, a few people fidgety in their chair. The attack moves in minutes or less. The investigation cannot take hours. An agentic SOC has to take that complexity off your plate. That is the point. A lot of people say to me, well, what is it? That is what it is. So that your team can stay ahead, so that you have agents that investigate it together. Until now, agents worked one at a time. Many people have lots of different solutions. Endpoint agent would do something and then finish. Identity would start, the agent would do something, and it finished, and the cloud, they investigate together. One takes endpoint, one takes identity, one takes cloud. Same case, same time, shared memory. What one learns, the others know. No hand-offs, no waitings, no starting over. That is what should work together. That is the difference between a collection of agents and an agentic SOC, not working independently, but working together in that shared space, giving you the ability to stay in control. The agents do the work at machine speed. But there is another concept here. Speed only matters if you can trust the outcome, if you can trust what comes back. We built agents to work the way your best analysts already do, look at the evidence, ask what else it could be, rule out the innocent explanation before it ever reaches you, get you an answer that you can act on. This isn't a slide. This isn't just a discussion. This is what we are running inside now. Let me show you, hopefully with audio. Roll the demo. This is CrowdStrike's agentic SOC. You can see attacks assessed, detections triaged, meantime to resolve, and autonomous resolution rate. Detections are being triaged, investigated, and resolved continuously without anyone grinding through a queue to make it happen. This is the operation at full scale, thousands a day around the clock at machine speed, with humans on the loop wherever you want them and on every critical decision. Let's go inside one of these investigations, start to finish. The investigation opens and runs from the top. It's an AI abuse case. An attacker tricks the IT helpdesk copilot into issuing a rogue credential, then uses it to reroute payments. When a verdict comes out of a system like this, the first question is always the same: How do I trust it? How do I know it's right? The agentic SOC earns that trust by showing the work done, dispatching expert agents in parallel, each specialized in its own area. Underneath, they run an analysis of competing hypotheses, the same tradecraft analysts have used for decades, weighing the evidence and ruling out the benign explanations. Together, the collective agents land the verdict, true positive, malicious, response staged and ready. But nothing irreversible fires until approved. Work that once took hours or days, done in minutes. Your people stop doing the grind and start making the call. That's what runs out of the box, but this is your SOC with your use cases and your data sources. Build your own agents and wire them in. Describe what you want. An insider risk enrichment agent that understands your business and pulls in HR data, badge access, and prior incidents. That data typically lives in other systems like your ERP or ITSM platform. Connect it to your Workday and ServiceNow MCP servers and your Next-Gen SIEM data for correlation. A few clicks and Agentic SOAR handles the rest. Before rolling it out, test it. Pull a recent detection and see what the new agent flags. Once it looks right, publish it. The agent gets to work, enriching insider cases with your data alongside our built-in experts. You saw the SOC dashboard, attacks assessed, investigations resolved, but you're also managing the automation behind the operation, dozens of agents and workflows across multiple projects. You can't check each one by hand, and you don't want to hear something's wrong from an analyst. This is your view. One dashboard for every project, every agent, and every workflow. You see the work each is doing, what each is costing, and what's failing. Let's drill into the SOC automation project. Now we see each resource inside, agents and workflows all in one place. The SOC gets the automation benefits while you maintain governance and control. This is your agentic SOC, powered by CrowdStrike, triaging, investigating, and responding on its own. That's what works out of the box, but this is where it gets fun now because this is your SOC, your systems, your workflows, your unique edge cases. I didn't want to give you a fixed set of agents and say good luck. That's why the team built AgentWorks. You define the mission, you connect the data, you connect the systems, you build the agents that your team actually needs. They work alongside ours. But rather than show you a concept slide or rather than show you what we've built, I want to show you something much better. One of our largest customers in the room here this morning is already doing this. They built agents for triage, enrichment, host investigation, identity investigation, and threat hunting. Their agents, their environment, taking real actions today. Enough from me. Let's listen to them and see what they've built. At Salesforce, our analysts already have the expertise. The problem was time. The threat intelligence, endpoint data, identity context, and SIEM telemetry were already there, but responding to adversaries needs to happen in real time. Sharing threat intelligence between investigators while maintaining context is critical for investigations to happen in minutes. To accelerate our agentic SOC journey, we used Charlotte AI AgentWorks to turn repeatable investigation steps into specialist agents built around the way our team works. We built a threat intelligence agent to investigate suspicious indicators using CrowdStrike intelligence, a host and identity context agent to bring endpoint and user activity together, and a Next-Gen SIEM assistant to turn investigation findings into detection logic. Then we connected them through an orchestrator. Instead of analysts deciding which agent or tool to use, they simply ask a question. The orchestrator selects the right specialist agent in AgentWorks and carries the investigation forward, and they can start where they already work, Slack. Salesforce's conversational AI layer, Calie, routes the analyst's question directly to our custom AgentWorks agents, bringing evidence together from across the Falcon platform. Let's see it in action. Is this hash malicious? Calie routes the question to our custom threat intelligence agent in AgentWorks. The agent identifies the hash and connects it to a known adversary. Have we seen it across our fleet? The context carries forward. The orchestrator hands the investigation to our host and identity context agent. No new search, no copying indicators between tools. The agent searches across the environment and identifies two impacted hosts. Tell me more about this host. Who logged in recently? The host and identity context agent continues the investigation, bringing together system posture and recent authentication activity. Then draft a next-gen SIEM correlation rule for this activity. That request is fielded by our custom Next-Gen SIEM assistant in AgentWorks, which turns the investigation findings into a rule ready for analyst review. What once required separate threat intelligence, endpoint, identity, and SIEM workflows now happens in one coordinated investigation. From suspicious indicator to detection logic in less than a minute. One investigation, one conversation, a team of agents. That's how Salesforce is using Charlotte AI AgentWorks to accelerate the agentic SOC. Huge shout-out to the Salesforce team. I would love to see next year a collection of these that everybody can use that we can share across the community. Let's start to bring this all together. Look at what you've just seen. We've talked about AI changing what we defend and how we defend it. We didn't build a whole raft of new point products. There's some new releases, but we built one platform for the AI era at the start of CrowdStrike, and we've continued to build on that platform so that you can build faster with AI without losing control. It starts with the platform and the sensor, and we keep building on that. This week, we added a new layer with the announcement of SafeMind and a number of new innovations. Everything we've shown you today still has a person at the center. This is incredibly important. But our world is changing, and we're going to have to start to think differently. We're always going to have a human in the loop, but that model is going to change. Adversaries will use autonomous AI to find weaknesses to adapt, to attack. I challenge everyone to think the same. Defenders need AI that can do the same. Defenders need to think differently and start to leverage the tools that give them speed. We need to start to think about AI working against AI continuously, autonomously, many times before a human even knows there's a fight. This is where this is all going, and I believe AI is going to move us faster and give us a really powerful thing, trust, where trust can become an advantage. Let me come back to where I started. We know where AI is going. We can see it. No one in the room, no one online is going to win by slowing it down. You win by moving fast without losing control, and I firmly believe control creates trust, and trust lets you go faster. Let's embrace this AI era. Let's create an enormous advantage for us as defenders, for us as a defending community, and make sure that we create an unfair advantage for us that weakens the adversary. I'll go back to that question that I asked. Who is going to get there first, you or the adversary? Today, you've seen what happens when security moves at the same speed as AI. These are not ideas. These are innovations in play today, running, that you can leverage straight after the session. Don't fear what AI changes. Control it, use it, move faster with it, because in an AI era, speed is the advantage, and the advantage belongs to the defender, all of you. Thank you. Please welcome Senior Vice President, Counter Adversary Operations at CrowdStrike, Adam Meyers. Good morning. All right. We have a lot to get through, so I am going to jump straight into it. First off, I would like to tell everybody here about something that we kicked off for the first time this year, which was the Day Zero Conference. This was a threat researcher summit that we threw. This was on Monday, and we brought together a very small group of analysts and researchers across the community. It was people from government, people from law enforcement, competitors. The focus of this event was for us to come together to figure out how can we bring the fight to the adversary. How can we as a community come together and do something collectively to disrupt adversaries? During the event, one of the cool things that happened, and I am going to share this with everybody, you may have seen this in the news yesterday, we worked with our partners in law enforcement across the world, and we were able to disrupt a botnet called Sality. Sality has been plaguing the internet for 23 years. It is a peer-to-peer botnet, and peer-to-peer botnets are meant to be resilient. The reason that they use these peer-to-peer protocols is to make sure that they cannot be disrupted, they cannot be taken down. After years of research and an incredible amount of work, thousands and thousands of lines of C code, Tillmann Werner and the team from CAO were able to take this botnet down live on stage in front of the entire audience. I just wanted to point out that we can do things to bring the fight to the adversary, and we can raise the cost of doing business for them. Just maybe we could do a quick round of applause for the CAO team because-- All right. Thank you. Just wanted to start off with a little bit of good news, a little positivity about what we can do to disrupt those adversaries. Now, not such good news is the impact that we've seen just in the last six months. So much has changed since I was on the stage last year, and one of the things that we covered in the Threat Hunting Report, which came out a few weeks ago, and if you haven't had a chance to read it, obviously I highly recommend that. We found that the number of detections across the platform and what we could see changed, and for the first time, agents were responsible for 2.5x more detections than humans. So let that sink in for a second. Think about what that means. We now have agents that are triggering detections and causing all of the security teams to have to respond to a whole set of activity that they've never had to look at before. That is, in one stat, the AI era. So, welcome to the AI world, and that's what it looks like from a threat perspective. Complexity is something I've talked a lot about. You may recall on stage last year, I was talking about threat analysts, and they have seven or eight different jobs, or at least they did last year. Every time that they have to switch their job. They have to re-instrument what they're doing. They have to start looking at different data sets. They have to move between tools. I always think about that in terms of air traffic controllers. When you think about an air traffic controller, they've always been described as the folks that have the highest burnout and the most stressful job. When I think about our threat analysts and the SOC analysts, they're not doing just one job, they're doing eight jobs, and that complexity accelerates, and the cognitive load on those folks is incredible. The world has continued to change, obviously, and that change is compounding, and it's making their jobs much harder. That's really some of the things that we need to keep in mind when we're thinking about how to bring agentic SOC and what folks need in order to defend against these threats. You heard George talk about the Mythos moment yesterday, and I think the Mythos moment for me started in April, and that's when we first learned about this new model called Mythos. It wasn't so famous or so infamous, depending on how you think about it, because it was released, rather because it wasn't released. That Mythos moment that started in April, then in May, we see something called Project Glasswing, where they bring together security researchers realizing that they needed to bring security domain expertise to understand the capabilities of this model and to see what it can do. As we started getting access to that, what we found was that it was really good at finding vulnerabilities, but there was an 80% false positive rate. As we started trying to address that, we recognized that the model itself is not the most, or the only part that you need to be thinking about. We love racing here at CrowdStrike, so I think by contract, I have to use some sort of racing analogy in all my presentations. I think about the model as the engine of the car, and the harness is really the chassis of that car. By implementing the right harness and bringing the expertise together to build a harness to use these models, we were able to reduce that 80% false positive rate down to 20%. By June, CrowdStrike had submitted 2,400 vulnerabilities as CVEs. We went through the responsible disclosure process. We notified all the affected vendors. That is really, I think, what for me is that Mythos moment. To put a finer point on that, let me give you an image of what that looks like. The vulnerabilities, as you can see-- Whoops, somebody put that backwards, sorry. The vulnerabilities, as you can see, have hockey sticked. In June of this year, there were 7,400 vulnerabilities that were registered as CVEs. This is the lowest number I could find. If you go do this research on your own or throw it into your AI of choice, you might find more vulnerabilities, but I wanted to try to temper that, so I gave you the lowest number that we had. What is really significant about that 7,400 vulnerabilities in June, which would have been the first time we see vulnerabilities that were discovered through some of these advanced AI frontier models, that was 96% more than June of the previous year. By July and August, I have those stats, this is the last time I think we will see double-digit growth there, because now it is in the triple digits. This is what that looks like in terms of the AI moment, that Mythos moment. If you recall, I said 2,400 vulnerabilities that CrowdStrike found in various products. That is 30% of all the vulnerabilities that were reported in June. We are doing responsible disclosure. Imagine what the adversaries that are not doing responsible disclosure are finding and how they are weaponizing these things. The 30-day patch cycle is obsolete, and I think we are approaching probably a 30-minute patch cycle because we have seen China and other nation states take vulnerabilities when they are released and weaponize them inside of 24 hours. It is not just China. We saw Belarus do this. This is kind of where things are going. More vulnerabilities, faster exploitation, and less time to respond, and that is the challenge that we face today. But the good news is, from a CrowdStrike perspective, the exploit is not the end of the story, it is the beginning of the attack. Through the CrowdStrike Falcon platform, we can still track lateral movement, privilege escalation, all of the things that an adversary needs to do once they execute that zero-day vulnerability. That is really where the power of the platform comes in and allows us to start to put a stop to this. The breakout time, as we've heard, is quickly approaching zero. In the last year, it was 29 minutes on average. 27 seconds was the fastest breakout time that we've seen. We are building the systems and preparing for this to approach zero. I think Mike's point about having to go from time of discovery is probably a more interesting metric that we'll need to start to look at. As we go into this, I want to share some stories from the frontline. George yesterday talked a little bit about the Hugging Face situation, but this is stuff that we've observed. I think it's really important to go through just what's changed in the last month, last 6 months. In the last month, for example, we've seen almost as many agentic adversaries as we did in the six months prior to that. This is something that is not theoretical, it's here, and adversaries are using open weight models. They're figuring out ways to weaponize vulnerabilities, and the adversaries are evolving and are continuing to generate even more capabilities as we speak. I'll show you this. This is kind of interesting. This is from Vault Panda, targeted an organization, and within an hour had issued 1,100 commands. This is just a snapshot of the reasoning that we were able to identify from the agentic capabilities that this adversary brought with them using a local LLM on a command and control server to increase the speed and capabilities of their attack. This gives you a sense of what we're seeing now is that we're watching the reasoning of the adversary evolve in seconds. This here, the adversary was able to, or the agent I should say, was able to figure out that what it was doing wasn't working and we could see it evolve. We could see it learn. We could see how it was able to develop the attack to be successful. We've also seen that agentic AI is now a participant in ransomware operations. In one incident where we were tracking REVENANT SPIDER, we identified a command and control server that they had left open web directory. Thankfully, even with the power of AI, adversaries still have pretty bad OPSEC in many cases. Through looking at this, we were able to see Claude documentation. We saw markup language stuff. We saw all of these things that let us get a view into how the adversary was using AI and how that AI was helping ransomware. In one incident, it was able to find 17 different victims. What's so notable here, each victim had a custom web shell, and that web shell went from being written to being deployed in seconds. It was able to quickly reason to figure out that there was credit card information that they were trying to steal that was encrypted, and so the agent was able to, on the fly, figure out how to decrypt that credit card information in order to exfiltrate it out. You can see that this entire process took something like 48 minutes. This is what we're seeing from some of the advanced adversaries that are out there. We need to secure AI across your attack surfaces. Last year, I talked about how we brought some of our cross domain capabilities for Falcon Adversary OverWatch into the fold. We had the ability to look at cloud control plane, Next-Gen SIEM. We are now at a point where we've got to bring Overwatch to other areas. We're really excited with the release of Guardian and AIDR to now have Overwatch for Guardian and AIDR. Falcon Adversary OverWatch: Cross-Domain Threat Hunting is what we are announcing today. This is officially available, and what this allows us to do is to bring the power of Overwatch across all of the domains that need to be protected. You can see, when you look at this, that we have expanded Overwatch for Guardian AIDR and we're also bundling it up with Identity and Cloud Control Plane and all of the Next-Gen SIEM stuff, so that now Overwatch can protect everything with one SKU. Buying Overwatch for cross domain gives you the capability, the threat hunting to find these advanced adversaries on all of your systems. This extends across the platform. Last year I talked about Threat AI, and that was our vision for bringing threat intelligence and threat hunting into the AI era. We released a number of new agents last year. We released the malware analysis agent, the exposure prioritization agent, the threat intelligence agent, and the hunt agent. If you haven't seen it, the threat intelligence agent is, I think, one of the coolest things that we released. As we think about how we bring new agents into the fold, George gave us a mandate, 70% work reduction, 100% traceability, and it needs to extend across the platform. Let me show you just a quick demo here of what we have for threat intelligence agent. The threat intelligence agent takes something that has taken analysts days, weeks to read all of the intelligence reporting, to comprehend it, to turn it into action, and we've brought that out as just a very simple agent for analysts to interact with. Let me go ahead and just run the demo. Threat intelligence can tell you which adversaries pose the greatest risk, how they're likely to target you, and where to focus your defenses. Getting to those answers can take hours of research and manual pivoting, sometimes stretching into days. The threat intelligence agent can do it in minutes by drawing on CrowdStrike intelligence, dark web collection, and your organization's own context. That lowers the skill barrier so any user can access expert level intelligence. Here, a financial services SOC analyst needs to understand which threats are most relevant to their organization. So they ask, what's the biggest threat my detection engineering team should be focused on? The agent surfaces Stardust Chollima as the adversary the team should prioritize. More importantly, it explains why. Stardust Chollima is actively targeting financial services in the same geographies where the organization operates. Just weeks ago, CrowdStrike observed this adversary using a new ClickFix attack chain in a financial services intrusion. From one simple question, the analyst now knows who matters, why they matter to the organization, and what they are doing right now. The organization has already seen a Stardust Chollima associated detection in its environment. Earlier this year, that detection was blocked. Now the analyst wants to make sure the right defenses are in place. They ask, h ow is Stardust Chollima most likely to attack my organization, and how should I defend against it? The agent generates detection engineering recommendations, hunting queries, vulnerabilities to prioritize for patching, and additional defensive mitigations. The analyst takes it one step further, asking how to turn that intelligence into action. From there, agentic workflows can automate defensive and response actions, enrich detections, execute hunts, and prioritize actionable findings. What once took hours of research and manual pivoting now takes minutes. The analyst goes from asking what matters to knowing what to do about it. All right. Yeah. Turning intelligence into action is one of the coolest things that you can do, and as somebody who has spent my career doing threat intelligence, reverse engineering, trying to make sense out of the downrange artifacts that we have from adversaries, this is a game changer. We do not need to have highly trained threat intelligence analysts focusing on all of that. They can now focus on what action to take and how to protect the environment. That is available now. What is coming out next, I am really excited about, and this is the missing piece that we had on the Threat AI vision that we announced last year. What we have available or coming available is what we call Agentic Recon. Agentic Recon is the ability to start to look at the dark web, because one of the biggest things that we have been tracking is identity compromises. Threat actors would rather log in than hack in, and compromising legitimate credentials is the way that they do that. Agentic Recon is the tool that you can use to stop that. Let us go ahead and roll the demo. Falcon Intelligence Recon gives your organization visibility across millions of criminal underground and dark web posts from closed forums, marketplaces, leak sites, private channels, and more. The challenge is knowing what matters and what to do about it before an adversary can act on that exposure. That's what Agentic Recon is built to solve. It coordinates specialized agents to identify exposure, prioritize what matters, and drive response. You can simply ask, what are all of the exposed credentials for my employee accounts? Behind that question, Recon uses what CrowdStrike already knows about your domains, infrastructure, and organization profile to tailor the search to your organization. Recon gives you a clear view of what's exposed. At enterprise scale, that can mean hundreds or even thousands of findings. The question becomes which ones matter most. That's where the threat intelligence agent comes in. It analyzes the Recon findings against CrowdStrike threat intelligence to identify the exposures most relevant to current adversary activity. Here, it prioritizes the finding and explains why it matters. A search gives you a point-in-time view, but exposure keeps changing. New credentials leak and new findings surface, so understanding your exposure can't stop with one search. Save your questions as intelligence requirements with monitoring rules, and Recon keeps watching for the next exposure automatically. As Recon monitoring surfaces new findings, a specialized triage agent assesses each notification in context, assigns severity, and prioritizes the most critical exposures. Here, a new batch of employee credentials tied to Raccoon Stealer rises to the top. The agent recommends specific response actions for each threat in Falcon and across connected systems. The path forward is clear. Reset exposed accounts, investigate affected hosts, coordinate credential resets with tenant admins, block IoCs, and run the recommended hunts all in one workflow. For recurring threats, those actions can also be automated through AgentWorks and Agentic SOAR. That's the shift with Agentic Recon, from exposure to action, while Recon keeps watching for what changes. The criminal underground moves fast. Agentic Recon helps close the gap. See the exposure, understand the risk, stop the breach. All right, we'll give that one a round of applause, too, yeah. Exposure to action, it doesn't get any better than that. That'll be out in a few weeks, and looking forward to working with everybody here to get that rolled out. In conclusion, AI is an arms race, and now is the time to secure the advantage. Thank you. Please welcome back Michael Sentonas. Okay. Great demos there from Adam. Very excited about those as well. We talked about this yesterday, the power of the community. I think collaboration with our customers and partners is how we win the fight against adversaries. At the event here at Falcon, it gives us the opportunity to bring so many of you together to share your insights, to strengthen our advantage. It is now my pleasure to invite to the stage someone who lives for speed, our customer Chief Information Security Officer at Amazon and race car driver, CJ Moses. Thank you. Grab a seat. CJ, why don't we start by, I'll get you to do a little bit of introduction to yourself and to your role, and say hello to 10,000 of your closest friends. Absolutely. Wonderful crowd here today. It looks great. As Mike indicated, I'm the CISO for Amazon, but what does that really mean? We take a different look at how a CISO operates, at least in my role is integrating the security across the totality of Amazon. That's 148 lines of business global. What's that really look like? Many of you will start to be confused if you're CISOs, because I have everything from cyber threat intelligence all the way through all the lines of intelligence. I have physical security, personnel security, all of our executive protection, all of those things. That's one of the things that we learned working in the government and the like, that integrating all lines of intelligence and being able to act on that intelligence by owning the things that need to be done in one place allows us to have that single-threaded leader that can not only distill the intelligence, but then act immediately on it. Across the large organization that we have, it's become very key to us stopping bad things from happening to good people. We can take this conversation with that sort of introduction in a lot of different areas. Yeah. You sit on top of one of the widest views of the threat landscape anywhere, given the size of customers and the telemetry and everything that you see. Talk us through a little bit about what you are seeing that a lot of people in this room may not have visibility or appreciation for. Yeah, absolutely. I think one of the things that we have is we actually have across the totality of the Amazon cloud, we have honeypots. We call this MadPot, and across that totality of that environment, we actually on a daily basis see 750 million threat interactions. That is 750 million interactions a day that allow us to actually glean intelligence on how threat actors and adversaries, what they are doing and how they are doing it. That further allows us also to be able to inform the things that we do in a defensive posture based upon what we are actually seeing on a day-to-day basis. Just in July, just to give an example, one of the honeypots actually captured an AI agent that was completing a full cyber attack, and it did it in 12 minutes and 42 seconds. You would normally think this is the type of thing that would be, it was 94 events, zero syntax errors, the ability for it to respond in less than 500 milliseconds, which no human could actually distill what was being presented back to them and respond, and did this rapid fire so fast that it was, but for knowing that AI was behind it, you would think somebody was pretty quick on the keyboard. Not really something that is possible. That is, I think, one of the things is that AI has given threat actors, it has not made them better. It has given them breadth, scale, and speed that we've never seen before. I think that this is one of the things that AI is probably the most powerful tool that we also as defenders have, because AI is a tool, and just like most tools, you can use it for good or you can use it for evil. In our case, we're actually seeing that defenders have to not only keep pace, but get in front of- Yeah. ...how others are actually using it to attack us. You and I have talked a lot over the last few months about Mythos and about- Yeah. ...frontier AI models and what they can do. Yeah. Obviously, everyone is really fixated, and I thought George talked about this really well yesterday. Yeah. Everyone talks about finding the flaws. Yeah. How do you operate when finding the flaws is the easy part- Right ...in an organization the size of yours? Yeah. I think some of the discussion we've had here actually applies, and that is that back about three years ago when I was the AWS CISO at re:Invent, I actually gave a presentation that was, we shouldn't be looking at how many vulnerabilities are we finding as a metric that mattered because it really didn't. You can find them, but it actually was, I coined a term of mean time to defense, and that is really the disclosure to remediation or potentially exploitation. It's not window that you actually have there. And with organizations seeing 100x or whatever it is these days of vulnerabilities, having that kind of a flaw in the patching system that can't be responsive quick enough is a problem. I think there is a misconception right now, though, that hopefully, this conference has dispelled, and I've heard it a bit, and that is that the Mythos moment was really a bump in the wire where we're going to have all of these vulnerabilities, and then things are going to go back to the way they used to be once we get a chance to actually burn down these vulnerabilities. And the reality couldn't be further from that. The reality is that this is the new normal, if you will. This is the new, we've made a step change. We're going to continue down this path. So that really means is that we as defenders need to accept that and use the AI to our advantage in order to be able to patch, to also defend in other ways. There's various different mitigation ways, and I think some of the things that you all have launched this week are perfect to assist in that. You've touched on a few interesting points, and- Yeah. ...I think since April, all of us have been reading a lot of news about the models and what they do and what they don't do and a lot of pontification online. Yeah, yeah. With all of that, what are a couple of myths that you'd love to bust? Well, I think I just busted one to some extent, and that was that frontier models are great at finding vulnerabilities, and after they find them and we mitigate them, then we can go back to normal. I don't think that's going to happen, so that'd probably be number one. I'll give a few here. That AI is creating a new class of vulnerability, and I don't believe that to be the case. I think what you're actually seeing is that AI doesn't take a normal human and make them superhuman. It may take a human that's really good already and give them the breadth, scale, and speed that AI can provide, but it's not going to change them inherently. That is one of the things that we've talked about a little bit this week, but I think advanced adversaries are using AI as an automation, not a novel attack. It's not changing the capabilities that they have from the standpoint of the attacking. What is changing is the ability to do it much faster along the line. There's not a new class of attack. It's essentially the same types of attacks done so quickly and with the breadth. The one thing that we can pretty much stamp your foot on is that security through obscurity is gone. It's done. Things that you used to be able to get away with in the past are now being found because AI can find it, and the attackers will use that. I think one of the things is that probably a myth that we'd all like the easy button. As CISOs or defenders, we'd all like the easy button. That is to be able to buy one tool, not have to have an advance team that actually knows how to do the thing, and be able to move on to the next. The reality is that even with the great tooling, some of the things that you all have launched this week, you still need to have a strong team that understands not only the technology, but also how to use that technology in order to defend the infrastructure and the environments that you have, especially in the AI era. I'm going to jump around a bit. We're big users of Amazon Bedrock. Yeah. George talked a lot about where we're going yesterday and giving- Yeah. ...our customers choice and being able to bring models. I talked a little bit about the AI gateway as well. Yeah. We've obviously got a pretty clear view on we want people to use SafeMind, but we want people to use their own technology as well. Yeah. What do you think about model choice? Because I think this is an interesting debate going on in the industry right now. Yeah. Frontier, OpenAI, what that all means. Yeah, I think, well, if you brought your car to the mechanic, and the mechanic has a whole set of tools, and the mechanic only reached in there and grabbed out the BFH, the big fantastic hammer that is for all of you out there, and started banging on your car, you would be pretty upset. Use the toolkit that you have for the things that make sense. You want them to use the 10 millimeter socket on the 10 millimeter bolt. In this case, Frontier models or models in general should be used for the thing that they are best at and use the whole tool set. You can use, and quite honestly, it is much more efficient as well as much more secure to use a specialized model that has a limited scope for only that task that you have it doing, and then use other models and actually to test against the output of that. The idea to use the BFH, the Mythos in this case, the current timeframe, to do everything, just does not make sense either financially or from a security perspective to begin with. And because we like our cars, we do not like them getting hit with big hammers. Have you used the big hammer on the race car before? I have actually. Unfortunately, sometimes it is a required tool. But it normally means- Work out well? ...that you bounced off a wall somewhere before and you are trying to bend something back quickly. We are not going to go talking about that. I like the sideways. Yeah. rather than the straight bit, but that is a different conversation. Well, let's real quick, the one thing I didn't hit on, you brought up Amazon Bedrock, and I think one of the things that I'd be remiss if I didn't mention is that in our space with Amazon Bedrock, with the guardrails and walls around it, is that being able to use all these specialized models and stuff like that, you think that you have to have all kinds of new tooling in order to do so, in order to operate that. The nice thing about Amazon Bedrock, and I'd say this if I even wasn't with Amazon, is that it's the same API set to use whatever model you want to use. You can use the same tooling and API set in order to use whatever model and switch them in and out rather easily. It's kind of also a modular thing. That's one of the things that we've run into that makes it a lot easier for us to be able to operate. Let's jump into the operational side. Yeah. I think like a lot of people in the room, you obviously overlook all the agents that are being deployed. You've talked about a couple of projects already. Go back to maybe one of the first agents that you all deployed. Yeah. Talk us through how that went. What kept you up at night before going live? Well, my standard answer to what keeps me up at night is normally my dog, but in this case, I'll stay on track and say agents are single-minded and determined to complete the goal. There's no morals. There's no sense of fear or fear that they're going to get in trouble. They're going to do the things they need to do in order to meet that goal set, and they will find ways to get out of the box that you put them in because quite honestly, that's kind of what we're telling them to do. Get this goal done and get it done as fast as possible and give me the answers I want or the output that I expect. Therefore, in that kind of environment, we need to make sure that the boundaries we put around those agents is secure and might be a little controversial, little hot take here is containers are not adequate as a security boundary for an agent on its basis. Think of it from the standpoint of you want to have 100% visibility into what agents are doing, AI services in general, what you're using, and if you don't, you're going to have a problem. That's pretty much one of the things that we've already learned, that visibility is just the beginning. Then you need to also understand what the agent is doing, what data it has access to, what permission sets, what the prompt is driving it to act and do the things that it's doing. What identity and credentials are being used. These are all things, what file access on the local machines and things like that that it has. Then you need to be able to figure out what it's doing is consistent with the prompt that it's been given. This is sometimes one of the things you run into with agents is you give it a command, then it does something, and you're not really sure why it did what it did, but that's one of the things you can actually test against. Finally, visibility. 100% visibility is great, but you also have to have control over that agent. If it goes rogue or is doing things that you do not want it to be able to do, you have to have an ability to be able to stop it from doing what it's doing or limit or isolate it. This is one of those things that you normally can't do if it's something that's only controlled via the container. You actually have to have a physical infrastructure layer or separation that allows you to be able to take that on. That's one of the things that we do on the Amazon side of the house with Nitro, from the standpoint of being able to maintain the isolation between the data and the control plane. That control plane being separate by way of the agent allows us to interrupt that communication and then be able to keep the agent from doing things that are rogue. This is one of the things that kind of separates the kind of model that we've used in the past, to be able to apply what we've learned over literally decades of creating a hypervisor that allows us to provide that level of isolation, now applying it to not only the humans using things, but the AI doing so as well. I want to stick to the topic a little bit because I think just chatting to people- Yeah ...last night when they heard about Guardian, a lot of questions. We've really valued exchanging a lot of ideas with you and your team on this topic, how to think about securing agents. GA with Guardian yesterday. Yeah. I have got to say that again. Got to keep pushing that. How are you thinking about AI security, especially at the agent and endpoint layer? What is important? Obviously, you covered a lot just now. Yeah. But how are you thinking about it at the endpoint layer? Yeah. So, number one thing, very excited about Guardian. We have been talking behind the scenes on that for quite a while now, and I was really glad to see it released and also that the name was released because I like the name and at dinner the other night, I think I said it in front of somebody, and I got the sneer, and I was like, "Uh-oh, I guess that is not public yet. Me leaning across the table. Yes. Ixnay on the Guardiansnay. But, I think one of the things from our perspective is that at the endpoint layer or kind of leading from that is that up until now, there's really been two identity types. For decades, it's been humans and computers. We don't necessarily believe today that AI is either. It's its own thing, so you need now a third. We've now added a third leg to the stool from an identity perspective. You need to have that identity have its own level of access that includes being able to tag it as an agent so that in all your data, your logs, and things like that, you know that this is an agent. But the scope that it is given should never be more than the individual that is operating it. So that's your base. That's not the base access you should give the agent, but that's the top layer that it ever could get. So, that gives you a boundary to begin with. Then it should be task or specific task-based for the ANA that it actually provided from an identity and authorization type of perspective. Being able to do that permissions enforcement at the infrastructure layer, not in the agent's reasoning, is huge, going back to my previous part there. So it is one of those things that we really foot stomp and make sure that we do, because if you give an agent too much runway, it'll use it, and the outcomes probably won't be in your favor. We're nearly out of time. We're rocking. Typically, at a cyber conference, we talk about all the bad things, all the things that are worrying us. Yeah. I want to end on a positive. Yeah. What excites you about where we are in the world right now? Yeah. I think the thing that excites me is that the opportunity is like we've never seen before. AI can be seen as a negative thing or the attackers are using it or otherwise. But I think that we're in a position now where we have the ability to use AI to do things we couldn't do before. All of you that are out there and have teams that have been under mountains of data that they couldn't get through and analysts that spend most of their lives trying to just figure out the basics now actually have the time to do the stuff they wanted to do, and that is to actually be able to find the adversaries and respond to them. Now you have the tooling. You can see the big picture. The needle in the needle stack is now clear, and it gives them the ability to actually do that reaction. I think that we're at the point where there's a misconception that AI was the magic wand that was going to fix everything. But I think on an end, I think we, as humans, especially the experienced ones, are required to drive AI because it is not magic. The people that operate it are. So a lot of comfort talking about solutions and not ending on problems. CJ, thank you. Appreciate it. All right. I'm going to let you get on with your day. Big round of applause for CJ. Thank you. Thank you. Thanks, Mike. Thanks, mate. Okay. I just want to know where your leather jacket is. Please welcome Chief Commercial Officer, Andy Duffett, and CrowdStrike's Chief Marketing Officer, Jennifer JJ Johnson. Hello, hello. Hello. What a morning. All right, we're almost there. Welcome to the 2026 CrowdStrike Customer Impact Awards. It is so great to be here with all of you because Fal.Con is really about all of you, our customers, the work you are doing, the problems you are solving, and how you are leading through one of the biggest shifts that our industry has seen. You push us to think differently. You raise the bar, and what we learn from you helps shape where we go and what is next in cybersecurity and where we go next. Today, we celebrate the leaders raising the bar for our entire industry. All right, let us get to it. All right. Let's recognize this year's Customer Impact Award winners. Please welcome back George Kurtz and Michael Sentonas. All right. Our first category today is the Platform Pioneer Award. This award recognizes a customer leading the way with the Falcon platform, transforming and strengthening cybersecurity across the organization and proving what's possible when the full power of the platform is put to work. Welcome. The Platform Pioneer Award goes to United Airlines. Woo. United Airlines runs one of the most complex, always-on environments in the world, where every system matters and downtime is not an option. What began as a move beyond legacy antivirus has become a flagship Falcon platform partnership. 99% endpoint coverage, thousands of cloud workloads secured, stronger identity protection, compliance support, and Falcon for IT through one lightweight agent. Now helping shape the agentic SOC and partnering with CrowdStrike to put the AI in Airlines. Accepting on behalf of United Airlines, Vice President and CISO, Deneen Defiore. All right. Congratulations to Deneen and the entire United Airlines team. Okay, next award, the AI Innovation Award. This award recognizes a customer that's putting AI to work to accelerate security outcomes. This winner is setting the pace and showing what the agentic SOC looks like in action and helping define the future of security operations. The AI Innovation Award goes to Salesforce. Salesforce is defining the next era of security operations by transforming to an agentic SOC with CrowdStrike. Across one of the world's most complex SaaS ecosystems, Salesforce is unifying detection and response with Falcon Next-Gen SIEM. With Agentforce and AgentWorks powering the SOC, they're targeting sub 30-minute detection, 50% fewer alerts, and 99% coverage while upleveling SOC staff across the enterprise. Accepting for Salesforce are Senior Vice President, Deputy CISO, Security Operations, Kelly McCracken, and Vice President, Environment Security, Asiya Haque. Congratulations to Kelly, Asiya, and the entire Salesforce team for turning the agentic SOC from a vision into a reality. Our next award celebrates a customer driving meaningful change across the organization, the Transformation Award. This customer worked hand in hand with CrowdStrike Professional Services to strengthen their security program and build lasting resilience. The Transformation Award goes to Providence Health & Services. Woo. Providence Health and Services shows how strategic services can unlock transformation at scale. With CrowdStrike Professional Services, Providence advanced its SaaS security assessments, Next-Gen SIEM implementation, and AI application penetration testing. They've strengthened operations, readiness, and resilience with the Falcon platform as the foundation across endpoint, identity, cloud, SIEM, Charlotte AI, Falcon Shield, and AIDR, a model of continuous improvement and trusted partnership. Accepting on behalf of Providence Health & Services is CISO, Mike Ratliff. Congratulations to Mike and the entire Providence team for showing what real transformation looks like. All right. This next award gets to the heart of what Fal.Con is all about. It's our Community Impact Award. It recognizes an organization that makes the entire community around us stronger, because when one of us gets stronger, the entire crowd gets stronger. The Community Impact Award goes to Mondelez International. Mondelez International makes the crowd stronger in every sense, transforming its own global security operations while helping the broader community move forward. Mondelez has achieved impressive security transformation outcomes with the Falcon platform and proudly shares their story with the community through regular industry event speaking engagements, peer-to-peer mentoring, and participation in our customer advisory board. They put security advocacy into action and exemplify the power of the crowd. Accepting on behalf of Mondelez International is Deputy CISO, Emmet Cohen. All right. Congratulations again to Emmet and the entire team at Mondelez International for strengthening our entire crowd. Okay, our final customer category is the Leadership Impact Award. In the AI era, leadership means moving at the speed of innovation without compromising trust. This award recognizes a leader defining and architecting this AI era that we're in. They're advancing the frontier of AI and trusting CrowdStrike to help protect the infrastructure behind some of the world's most consequential AI models. The Leadership Impact Award goes to Anthropic. Anthropic is helping define the frontier of artificial intelligence as the company behind Claude, and advancing AI that is powerful, trustworthy, and designed to serve humanity. Protecting innovation at that pace and scale demands an equally forward-looking approach to cybersecurity. Anthropic has embraced the Falcon platform, including Falcon Cloud Security, to protect its fast-moving cloud-native environment. Accepting on behalf of Anthropic is Head of Industry Transformation for Cyber, Rob Hebert. Presenting the 2026 Global Partner of the Year, please welcome Daniel Bernard. Congratulations again to our Customer Impact Award winners. We have one more recognition today, celebrating something that has always been core to CrowdStrike, the power of our partner ecosystem. The strongest security outcomes are built together, with partners bringing the technology, the infrastructure, the data, and expertise our customers rely on every single day. Our final award recognizes a partner whose impact extends well beyond a typical technology relationship. Together, we're helping define how security is built into the foundation of AI infrastructure, helping customers adopt AI with confidence, resilience, and scale. Please join us in congratulating CrowdStrike's 2026 Global Partner of the Year, Nvidia. Nvidia and CrowdStrike are building a future where security is foundational to every innovation, made possible in the AI era. Together, we are bringing security into AI infrastructure from day zero, including the AI factories where enterprise AI is built, deployed, and run. From Charlotte AI AgentWorks with Nvidia Nemotron, our newly announced SafeMind model family, this partnership powers agentic defense and helps customers adopt AI safely, confidently, and at speed. Accepting on behalf of Nvidia is Vice President of Strategic Enterprise Partnerships, Pat Lee. Huge congratulations to all of our winners. Thank you for another day at Fal.Con. I hope everyone had a great day. There is more than 10,000 people here from over 70 countries, over 500 sessions, over 100 hands-on workshops. We are able to do this and bring you the amazing event. Thank you. A huge thank you to all of our sponsors, more than 150 sponsors. They are all over at the hub, so I want to make sure I give them a shout-out. Head on over there and have a look. You heard it yesterday during the CEO fireside chat, the community is the advantage. The crowd is our advantage, working together, learning together, fighting together. Which means the one thing that we have left to do is to celebrate together. Tonight, the best party in town, Fal.Con Fest. Make sure you get there. Very special guest headlining, The Chainsmokers, friends of CrowdStrike. Get out there. Have fun. I will see you there.
Loading workspace