I'm so glad all of you are here. I'm glad there's more than five of us here together. I'm glad I'm here. I'm glad we all made it. It's incredible. Look at the arena. It's an incredible place. So big. I think it's a testament to all of you. We're all here to talk about the same things. Looks like you all are having a good time, and that's great to see. I need to set the stage just a little bit. If we go back to Tuesday, if we go back to Wednesday, if you were here, I know you saw a lot of great demos. Think about what you saw in George's keynote. Think about Mike's keynote with Falcon Guardian, an incredible demo that you saw with Falcon Guardian. I think what you're going to like about today is I have something equally exciting for you. I have graphs and charts. That was weak, but that's the loudest that applause has ever been for graphs and charts, so I'm going to take it. I'm going to take it. Let's get into it. Let's just get started. Last year, if you were here last year, you probably heard George talk about cybersecurity intelligence. You heard him say his vision to transform CrowdStrike into the world's first cybersecurity frontier AI company. I had a fantastic call with George, and a lot of people at CrowdStrike, and the question was basically, "Hey, do you want to do this thing?" What do you say to that? I'll give you the answer. The answer is apparently you say yes. We're here. What does that mean? What happens after you say yes to that? AI and what it does is incredible. What it does for cyber is it ratchets up the speed, it ratchets up the need for defense by about 1,000, if not more. Your job was already difficult. This is the part of the presentation that I call Things You Already Know. Your job was already difficult. It just got a lot more difficult. It comes down to four core challenges you've been hearing about all week, rogue AI, insider risk, AI as an attack surface itself, and the changing economics of cyber attacks. Everyone's chasing the same ceiling, scaling logs, bigger models, more tokens, more compute, scale upon scale. Turtles all the way down, for those of you that get that reference in the audience, right? There's tremendous value in domain-specific models and harnesses. Focus is a superpower. We can have these amazing advancements by focusing on models, focusing on applications. You need AI to operate in situ, working alongside people, working alongside you and your companies, the people who understand your enterprise the best. Look, we now live in a world of unlimited offense. The bounty of offense is like nothing before. Time scales are compressing. It's easier than ever to share tradecraft. The full attack life cycle has been commoditized. What gives the defenders back their advantage? That's the question that we're setting out to answer. What gives you back the advantage? What gives you back not just a tiny advantage, but an insurmountable advantage? We must do this. We must create not only equivalent, but better defense, one that accounts for the full attack life cycle, how adversaries operate in the wild. That's why we built the world's first Cyber Superintelligence Lab. It's an incredible lab. I'm really proud to be a part of it, really proud that CrowdStrike is doing it, and really proud that we chose a very long name for it. That's how important it is, the world's first Cyber Superintelligence Lab. This is not a lab just to crank out research papers, although spoiler alert, we're going to do some of that. Please read it, cite it. I need my h-index to go up, for those of you in the audience. It's not a lab just to say what we can't do. A lot of labs, a lot of places will write papers and they'll say, "You can't do this, you can't do that, you can't do this." I want to tell you what you can do. This lab is built for the real world. To do this right, we need a lot of things. We need the best talent. We're bringing together the best talent across AI, cybersecurity, adversary strategy, and engineering. Look, one of my goals, and we'll debate how good I am at this at the very end. We can debate about it, is to make things as straightforward and simple for everyone as possible. The lab mandate is incredibly straightforward. We are a frontier AI research applied to cyber defense. Remember, focus is a superpower. That's what gives us the advantage. We're fundamentally changing the way we perform cybersecurity operations. It's 2026, we're doing it. It breaks down into four key areas. They're even on the screen. We didn't even talk about the size of the screen. No one's mentioned the size. It's huge. So you can read it from wherever you're at. The four key areas, developing industry-leading frontier cybersecurity models. Core one. We must do this. Engineering specialized harnesses designed from the ground up to operate these world-class models effectively and efficiently. It is not sufficient just to be effective. You must be efficient. We're going to talk about the need for always-on continuous defense. You don't do that without efficiency. If you remember George's keynote back from Tuesday, you saw the loop. It was a great graphic. It was a great graphic, great demo. Again, I have charts. But you already saw it, and you can go look at it online again. But you saw the loop. The best defense in the world is informed by the best offense. But how do we do that? How do we let the best defense be informed by the best offense? We must create areas to securely run those tests, areas we control as defenders. Thousands of high-fidelity tests, these digital twins. We can't do any of this without a clear benchmarking strategy, a clear evaluation strategy, a clear, open, and transparent way to share our results with all of you and have all of you share your results with us. CrowdStrike brings together the rigor of that lab, matched with the pragmatism of a trusted cybersecurity company in a way that I haven't seen before. I don't think any of you have either. Let's talk about the features. Let's talk about the individual components that go into success. What is necessary? First is the data. In order to fuel model tuning, validation, harness development, you need the best data. If we go back a decade, sounds terrible to say it like that. When we were starting this thing called data science, we had this saying for the data scientists in the group, "garbage in, garbage out." That's what we would say. Data is so important, and it's not just the volume of data that you need. You need the highest quality, highest fidelity amount of data you can get, and of course, you do need a massive amount of that. The CrowdStrike Falcon platform stores more than an exabyte of uncompressed data. That's 50 times the Library of Congress's digital collection. Every day, today, yesterday, we analyze over 7 trillion events. That's more than 840 events for every person on Earth, every single day. I can't remember the last 12 events that I did, much less the last 840 events that I did. It's an incredible amount of fidelity that we're talking about in this data. Finally, we also ingest around 14 PB across first and third-party data every single day. For those of you that are looking forward to binge-watching on the flight back, that's more than enough data to stream 2 billion hours of 4K video. CrowdStrike has the best data in the highest volume, and the data is foundational. It's foundational, and it allows the lab to take open source AI models and turn them into those highly specialized, highly bespoke, highly accurate security intelligence tools. Data without expertise is just data. It's fuel that's just laying there on the ground. At CrowdStrike, again, we're solely focused on cybersecurity. You can say it with me. Focus is a superpower. It is our superpower. We are focused on making the best possible defense, giving you the advantage. We have 270 PhDs, over 500 threat researchers, hundreds of AI researchers dedicated to this task at CrowdStrike. Of course, none of this is also possible without the Falcon platform. Look, the Falcon platform was built to take advantage of this AI era, even before we knew what the current definition of the word AI was. I don't want to date myself too much for all of my newfound friends in the audience, but if I go back, AI had a very different meaning even 30 years ago. Maybe even two years ago, than it did today. But the great thing about the Falcon platform is it was built for the fundamentals of AI that we have today. It's built for the data ingest, it's built for that high fidelity, and it's built to allow the best offensive researchers and the defensive researchers to operate in that platform as well. It gives us the foundation for everything I'm going to talk about today. So that's a little bit of setup with the lab. Let's talk about the lab's first series of innovations, and we're calling that CrowdStrike SafeMind. It's a shorter title, right? Shorter title. It's a great title. CrowdStrike SafeMind. SafeMind is how we're building beyond frontier capable defenses, co-evolved with the best offensive techniques. I totally forgot to mention, there will be a test after it. So you can pick up the test in the back. So make sure you get the test on the back. There's all the fancy words you're going to need to know. The charts are coming. That'll all be part of the test. We've poured countless of hours into harness engineering, built two new classes of frontier models. In short, the first series, the first steps, innovation in what lets defenders take back the advantage. Again, you saw the demo. Demo was great. Please go back and watch the demo. I want to double-click a few levels deeper into that and walk you step by step through it. What is SafeMind? There are three important areas of SafeMind. As anyone knows, everyone on the planet is contractually obligated to have three components for everything. It is never four, it is never two, it is always three. So there is three components of SafeMind. The first is offense. Why is offense the first in a system that is built for defense? Well, you cannot build you cannot build the best defense without knowing about the best offense, without knowing the adversary. Is not that right? You cannot build defense for things you cannot see. Second is defense, informed and co-trained with the best offense. Third is a complex and accurate cyber environment, a digital twin, an emulation. Underlying all of this, I know it is not on the slide because you are getting three things on this slide, but for all of the data scientists, for all of the researchers in the room, it is there. Underlying all of this is rigorous evaluations, transparency, and trust. Until now, how was it? How long have we been up here? 10 minutes or whatever. Until now, the industry has had separate agents for offense and separate agents for defense. Look, I get it. It makes total sense to do this. I even said it. I have said it so many times, you are going to be sick of me saying it. Focus is a superpower. So I get it. You want to make offensive agents, you want to make defensive agents, right? The issue is that approach is siloed, fragmented, and there is no connective tissue between it. It is manual, inaccurate, slow, fragile, brittle, not built for the frontier AI world. We needed a completely different approach. That is why, as part of SafeMind, we have been working on a closed loop system that we call adversarial co-evolution. That will be on the test. Adversarial co-evolution. The best defense forged against the best offense. Then we use each other. We use the defense to improve the offense, we use the offense to make the defense do better, and so on and so forth. Each cycle in this adversarial co-evolution is designed to improve both parts. When the defense agent blocks the offense, we do not just tell the offense to try again. Instead, we give the offensive agent and the harnesses back the newly hardened environment. So we have hardened the environment, we have made changes into it, we give it back to the offensive agent, and we tell the offensive agent to try again. But not only do we tell it to try again, not only do we hand it the newly hardened environment, we tell it exactly what we did to the environment. So we are not asking it to just break again or try to bypass our simulated environment again. We are telling it, "Hey, try to bypass it. By the way, here is everything I did to stop you the first time. Here is everything I did." We are giving it the answer to the test and still asking it to beat it. That is harder, right? Powering these harnesses are two new classes of models, Red Tempest and Blue Solano. Think about the harness as the runtime layer that surrounds these models and makes all of this possible. Until Tuesday, I would have described the model as the brain and the harness as the body. If you were here on Tuesday and saw the great chat with George and Jensen described the harness as the exoskeleton of LLMs. I was at NVIDIA for around nine years. It is the first time ever I have heard him call it the exoskeleton of LLMs. I guess I am calling it the exoskeleton of LLMs now. Red Tempest, if we talk about Red for just a second, again, an incredible advancement. It thinks, acts, and reasons just like real adversaries. The end goal is not the strong offense, it is to allow the defense to get better. That is on the other side. That is the Blue Solano on the right side of your screen. Our post-trained Nemotron model. We post-trained Blue Solano, we post-trained Red Tempest. I will tell you more about it. We did not do it alone. We did it in combination with our partners at NVIDIA and CoreWeave. Let us break down how the system works. Let us start with Red Tempest and the offensive agent. Many offensive agents and offensive tests stop at vulnerability discovery. They stop there. I get it. That is important. We want to find all the vulnerabilities. We went further. In our offensive agent, we not only do vulnerability discoveries, we do exploitation, privilege escalation, lateral movement, persistence, all the ways that an adversarial objective might be represented via this apex predator adversary. We have thousands of distinct attack scenarios covering 155 MITRE ATT&CK techniques that are built into this agent. Paired with that is Blue Solano. Every offensive trace is captured. If you are not familiar with trace, we have these things we call harnesses, apparently exoskeletons, but we have these things that we call harnesses or exoskeletons that the data, the digital dust that comes out of that is called a trace. We collect all of that. It feeds back into what CrowdStrike has been since day one, a net data creator. We have been a net data creator from day one on adversary and defense, and now we are a net data creator for agents and how they operate. So every offensive trace is captured and handed back to Blue Solano. Again, like I mentioned, those defensive agents use it again, and they write remediation, and they write patches. These defensive agents are designed with the judgment, expertise, and 3.1 million working hours of expertise from our world-class detection engineers. I do not have a good slide for that, but it is a lot. 3.1 million hours of experience. Of course, these by themselves are the old school siloed approach. We are not doing that anymore, right. We connect offense and defense, and we need a cyber environment to do that. Red Tempest is so high fidelity and it is so good, that we use its behaviors both to train Blue Solano and improve the harness that powers it. Again, here is that really cool part, when Blue Solano and its harness has created new remediations and detections, we say, "Try again. Try again, Red Tempest." We give it the full knowledge. We give it the full experience. The cycle runs many times until Red Tempest cannot win anymore. Think about it this way. Would you do this? Take your house, take the architectural plans for your house, take the blueprint for your house, take all your passwords for your house. Houses don't have passwords. Maybe they do today. You can log in with an app. Keys for your house, right? All that kind of stuff. Give it to an adversary, give it to a burglar, give it to something like that and say, "Hey, I want you to try to break in." I bet it would be pretty easy, right? That's essentially what we're doing here. We're giving it all this information and saying, "Go try. Best of luck. YOLO your way through this. Figure it out. Let us know how it goes." Some say the best security in the world is the security you don't have to think about, and I think that's true, right? The best security in the world is the security you might not have to think about. That's why we're all here. We provide that value, so that others can rest assured they don't have to think about it. I would say that's true, but I would also say the best security in the world is where you give an adversary every blueprint, every code, every defense technique, and they still fail. That's the best security in the world. Let's look under the hood a little bit. Now it's time, if you were out too late, I promised I'd tell you, now's the time, if you're not interested in very technical terms, is the nap time, right? I'll tell you when to wake back up. Let's talk about Red Tempest and its harness. Red Tempest sits inside a harness. It's a multi-agent architecture with an orchestrator in a swarm environment. We fine-tuned a 27 billion parameter dense model that orchestrates and powers each sub-agent. This has a 256,000 context window, which can go up to 1 million for extended window processing. The non-technical way to say that is it's a lot, right? That's important. It's important. Why is it important? Because you want to be able to save context as you're going through a red offensive attack, right? Think about your brain and think about what do they say? You can hold seven things in your brain at once. What if you could hold 1 million things in your brain at once? That's what we're saying here. Imagine the connections and the possibilities you could do, right? This architecture is broken into sub-agents that handle specialized tasks. This manager agent tracks the overall campaign, which also delegates actions to sub-agents like a recon agent, an assault agent. It is a true modern agentic architecture agent 2.0, whatever your favorite buzzword of talking about agents is. But it's not just that. Red Tempest and its harness executes what we call long horizon tasks. If you haven't heard a lot about long horizon tasks, I promise you will over the next year. Here, the agent's given a goal. Maybe it's data exfil, maybe it's some other type of compromise, it doesn't matter. But the point is, the goal can be broken down into a few milestones. The system has to take thousands of actions over several consecutive runs in order to accomplish this. Right? You saw it animate out there from the screen. There's a lot there. The point isn't exactly what it's doing. The point is that we broke it down, and now we have this long-running type of agent, which is very complex. Again, I will say this for all you computer science nerds in the building, it is a high fan-out, right? We do this high fan-out capability, and go through this long-running task. Only a specialized family of offensive agents could accomplish this, right? That sounds great. Oh, remember the chart? Here we go, right? That sounds great in practice, but do not worry, I come bearing metrics and charts. Let us look at this one. X is the cost, Y shows percent compromise. 100%, total compromise. Pretty easy. You are going to see a couple different models. Let us look at the first one. The yellow line is an off-the-shelf closed frontier model. It achieves, in a harness, 100% compromise and costs $96. Not bad, right? Now let us do the blue line. Let us say you go down the street, you go to the model store. You pick an open model right off the shelf, 100% compromise, $62. Again, not bad. Red Tempest operating in our specialized harness, $21, 100% compromise, right? Again, other frontier models can succeed at this task, but they are much more expensive to run. We do it 100%, 80% cost reduction. But remember, offense is not the goal. No matter what the fancy chart just told you, offense is not the goal. The reason you have to make offense cheaper is so you can do better defense, and that is where Blue Solano and the defender harness comes into play. A true multi-turn agentic system powers our defensive agents. For Blue Solano, we post-trained a Nemotron-3 Super 128B parameter Mixture of Experts model, 12 billion active parameters for rule creation. We also utilize Nemotron 3 Ultra as the reasoning orchestrator that also has up to a million context window. That is still a lot. We use both supervised fine-tuning and reinforcement learning for post-training. Again, this defensive agent looks at all the telemetry, all the traces from the offense and some models stop there, and they give you a list of everything that is wrong but we go further. We think that misses the mark. Blue Solano not only identifies what to do, but autonomously writes new defenses and remediations to catch the novel behavior and we do not only go further we also do it for much less. Second chart. I do not know who had chart bingo, right? But second chart. Again, x-axis here is efficiency y-axis is accuracy you got to be both you cannot be really accurate and cost $10 million, right? You cannot run it over and over again because defense is not a one-time thing. Defense is continuous, right? It must be effective. It must be efficient to do it, right? The only way to achieve full autonomy is to be in the top right of this chart, high accuracy, most efficient, right? Let us see here in gray again, you go to the model store you pick an off-the-shelf model, you pick an off-the-shelf harness. This is how most people start to be honest with you. You know what? I get it. It is a great place to start. It is a fast way to start, right? It gets you up and running. I get it. It is a combination of closed models, combination of open models. You see, not that accurate, not that efficient, but it is okay. You got them at the bargain model store. It is okay, right? What happens if you take those same models and you put them into custom-built harnesses? Because as you heard Tuesday, as you heard Wednesday, it is not just about the model, it is even more important with the harness, right? We can take those same models, we can put them in custom-tuned harness, custom cyber harnesses, and we do a lot better. We are getting closer to the top right. Blue Solano outpaces all of them, right? Blue Solano in the top right. It gives us the biggest gains, highest accuracy than Frontier in any class of harness, right? How good, how much better? One, capability goes up, cost goes down. That is the right way. 6x faster than the leading capability to do defense remediation. 70% more accurate than the leading way of doing detection and remediation, and 99% cost reduction. What is 99% cost reduction? To be able to detect and write a new detection policy or whatever off-the-shelf Frontier costs you $10. Blue Solano costs you $0.03, right? We just commoditized defense. Defense is commoditized. I just showed you how we have done that. I showed you the loop. Remember, the best defense built on the best, most sophisticated offense. Where do you run it? We had to create specialized environments. Real attacks need real targets, right? Real attacks need real targets. A safe place that is based on reality where these incredible capable models can operate. George talked about on Tuesday, an environment you control, a digital twin of your environment, but one that is so insanely high fidelity, the perfect test, right? That is why CrowdStrike has created this bespoke agent cyber environment that can be tailored just for you. You can create this in so many different ways, from network maps, from Jira tickets, from data coming from the Falcon platform so it matches your network and how the adversary operates within it. High fidelity slices of your real enterprise stood up on demand. You know what? Do not tell Jensen. It does not actually need to be an exact digital twin, right? We use the word, but it can be really close. Sometimes when we say digital twin, we get caught up in like it must be perfect, right? We cannot let perfect get in the way of good, right? These high fidelity environments can be very good. This is where we unleash Red Tempest. Over 1,000 distinct attack scenarios, each with multi real VM environments, real telemetry, validated adversarial objectives from those over 155 MITRE ATT&CK techniques. To capture the complexity of this, we do not just do it once, we do it more than 10,000 times. It turns out there are other advantages. You heard me talk about like this adversarial co-evolution and how we are using red to improve blue and blue to improve red. You hear about agent escapes all the time. It turns out you can use this same technique of using cycles to harden an environment, to harden where your agents are actually running. An enclave that takes the best things about sandboxes and adds adversarial co-evolution technique to harden it. Red Tempest will try to find vulnerabilities and exploits. Then we use Blue Solano to match and remediate those, and we monitor with the Falcon sensor. We have run tens of thousands of offensive attacks without any unintentional agent escapes thus far, and we are running millions more. That is the lab. Frontier AI for cybersecurity. I am so happy to be here with you today, so happy to share our first results. There are many more, right? There are many more that are here that I am excited about to tell you about later, right? Not today, so keep your eyes peeled. But I have only got these 30 minutes. To wrap it up, CrowdStrike, we have the best data, the best expertise, the best platform, and now we have the lab to bring it all together. This is how we tilt the advantage back to the defender. This is how we stop breaches in the AI era and the defender advantage starts now. Thank you all. I am going to pass the baton to Alex Ionescu, our Chief Technology Innovation Officer. Thank you all so much. Appreciate it. Please welcome CrowdStrike's Chief Technology Innovation Officer, Alex Ionescu. Thank you, Bartley, for that incredible lesson in frontier AI. Hi, everybody. I am stoked to be back here at Fal.Con for another biggest event ever. I grew up with stage fright, so an arena of 10,000 customers and partners was not on my childhood bingo cards. It is really exciting to hear about all the work we are doing around super intelligence and the new team we are growing under Bartley. I hope you are equally excited about it too. If you were here last year, then you probably know this is my second Fal.Con since coming back to the company, but my history goes back a lot further. I was there since 2011 when we co-founded CrowdStrike as the chief architect. The sensor we are going to be talking about for the next half an hour is the one I have built and one that a great many people have made far better since. Today, I am going to show you how the sensor is evolving to handle the next generation of AI-enabled threats, the road ahead to take all of the great work that teams like Bartley's are doing and bringing that to the endpoint in real time. Last year, I stood here on stage and told you where the industry was heading, the kernel dilemma, compute moving to the endpoint. I made you a promise that CrowdStrike was not merely going to follow those shifts. We were going to lead them from the front. Talk is cheap. Anybody can stand on a stage and point at the horizon. This year, the word on the slide that matters the most is the last one, delivered. I am here to show you the work, the receipts, as the kids say these days. Most importantly, I am going to show you how this will enable the paradigm shift that endpoint security will need to go through. Now, a quick refresher for anyone who was not in the room last year. Two shifts. The first one, the kernel dilemma. Adversaries operate in the kernel. For 15 years, protecting you meant operating there too. Not just us, all of us, security vendors, VPN clients, DRM, anti-cheat. There was a party in the kernel and everyone was invited. Every operating system vendor eventually reached the same conclusion. An operating system where dozens of third parties all need kernel access is an operating system that is harder to evolve for everybody in it. They went and built somewhere better to do the work. Linux did it with eBPF. Apple did it with the Endpoint Security Framework. Now Windows is doing it with the Windows Endpoint Security Platform, WESP. Three operating systems, same conclusion, 15 years. The second shift is compute moves forward. The dual core box from 2011 is now a 16-core powerhouse with a dedicated GPU and a dedicated NPU. Real inference capability arrived at the node and at the edge. In George and Mike's keynotes, you saw exactly what that means in the AI era. Agentic workloads have to run somewhere, and that somewhere is the endpoint. The endpoint is reigning again. Here is this year. On the software side, user mode delivered, WESP in both halves, the kernel engine Microsoft provides and us as the user mode client on top of it, and two projects of our own that I will spend real time on today, Ascent and Modularity. On the silicon side, compute at the node running on your CPUs, GPUs, and NPUs. Let us start with our WESP work and Microsoft engineering partnership. I would rather show it to you than describe it, so I will go straight into it. You are going to see a real machine with an adversary deploying malware on a Falcon-protected system and how WESP enhances the security you already enjoy today. Now, one thing before I roll this, what you are about to see is real. Our engineering teams built it all, and it runs. It is also directional. It is where we are taking the platform, not something you can switch on next week just yet because of some platform dependencies. I will get back to timing on that in a few minutes, but first, let us roll the demo. Let's look at a realistic example of an adversary deploying malware on a Falcon-protected system. As expected, when the user or an operator tries to launch this malicious process, Falcon blocks the attempt. At this point, Falcon is using Windows' typical process callback routines, which are exposed to kernel mode security drivers. In response, the adversary deploys an EDR killer that leverages a previously novel malicious driver to unhook the sensor's kernel callbacks. Normally, the sensor would block this and throw an alert as part of its anti-tampering features, but we've gone ahead and turned that off for the demo. While we always recommend customers turn on anti-tamper, operational constraints don't always make it possible. Note that even with the kernel callbacks removed, the malware still doesn't run. Thanks to WESP, Falcon continues protecting the system against the attack. That's because WESP is able to provide capabilities to user-mode security solutions, which were previously exclusive to kernel drivers. The protection is no longer exclusively reliant on our callbacks. Pretty cool, right? They took our kernel callbacks away, but the malware still didn't run. Now, let me be straight with you because my background is one of a security researcher, and I know that some of you in the room come from a pen testing environment as well. Yes, a determined nation-state-level adversary could still find a way to go after WESP as well. I'm not going to stand up here and tell you that we've built something unbreakable. But what we did is we raised the bar. We forced additional exploitation attempts. We increased the detection signal. The customer is better off running a more hardened configuration, and that's what resilience actually means. On the other hand, you just watched an EDR killer get a vulnerable driver in the kernel. It failed to tamper with our process blocking capabilities, but it still got in. Once it's in, it can do other kinds of damage. So really, it would be even better if we could just stop it from getting in. On Windows, we do exactly that using a platform capability called Early Launch Anti-Malware, or ELAM. It is part of our existing malicious and vulnerable driver blocking feature set, which blocks thousands of malicious drivers and commands. But in a world where endpoint security products are built on top of WESP and run in user mode, this brings up a question I get every single time I talk about it. Customers ask it, analysts ask it. "Alex, if you're up in user mode, who's watching the kernel?" It is the right question. Because the adversary does not agree to move out of the kernel just because endpoint security products have to. As such, any technology we adopt must be able to, by design, to let us monitor and control the kernel as well. Let me show you how that class of attack actually works. It is called BYOVD, Bring Your Own Vulnerable Driver. Windows will not load an unsigned driver. That bar was set decades ago. The adversary doesn't bring an unsigned driver. They bring a legitimately signed one. Some utility driver from years ago signed by a real vendor with a real vulnerability in it. Validly signed, known CVE. The signature checks out, so the driver loads, and now the attacker has and uses a vulnerability in that legitimate driver to get their own code running in kernel mode. They didn't break the signing model, they just rented it. From there, traditionally, game over. They are underneath your security stack, so they blind it. This is how EDR killers work, the tools ransomware crews use to shut down endpoint protection before they detonate. Almost every major ransomware operator that we track has a BYOVD variant in its toolkit. Notice who just died in that picture? The traditional EDR. Being in the kernel did not save it, because the attacker is also in the kernel. Fal.Con, by leveraging ELAM and our other suite of malicious and vulnerable driver blocking technologies, blocks this attack. That is because our ELAM capability gets us to be notified about all other drivers on a system that are attempting to load before they get a chance to run. If we detect a malicious or vulnerable driver, we block it right then and right there. Traditionally on Windows, this requires operating in the kernel because we are fighting against the kernel. Let us run that again on the same machine with the same signed vulnerable driver, the same attack, except this time Fal.Con is here, and Fal.Con has no ELAM kernel driver at all, but it is using the new WESP capability instead. The driver load is now denied. The new platform gives us a control point from user mode while Fal.Con brings the intelligence about which drivers are being used as weapons. That is the answer to the question on the slide two minutes ago. With WESP, just like with eBPF and the macOS Endpoint Security Framework, you can be in user mode and still be the one deciding what gets into the kernel. Which is not a tear down of protection, it is the same authority from an even better seat. Windows is finally meeting the modern OS endpoint security stack that Linux and Apple have set. Let me stop drawing it and show it to you instead. We are going to build this from scratch, starting from a machine that doesn't have Fal.Con, and you will see what happens when a malicious driver tries to load. First, we'll start with an unprotected machine. No WESP, no Falcon sensor. But a vulnerable driver, say a third-party device driver, is present. Now the Falcon sensor is installed. In a normal environment, it would load thousands of rules into WESP. But for this demo, we're focusing specifically on this driver to showcase the functionality. The Falcon sensor is able to stop threats without a reboot, but this driver is already loaded. While terminating malicious processes that might try to use it is something we can do, a reboot is necessary at the OS level to prevent the driver from loading. Post reboot, let's see if this driver is still present. We can see that Windows reports the driver is stopped. It's giving us exit code 31. Let's go see what that means. We have a failure code that tells us the driver never even loaded. Falcon, thanks to WESP, prevented this early boot vulnerable driver from loading without needing a kernel component of its own. On WESP systems, we don't need ELAM anymore. The kernel attack that headlines every ransomware postmortem is stopped cold by a sensor which does not need anything to be running in the kernel at all. Now let me be clear about where these demos sit, just so nobody leaves the room with the wrong idea. Everything that I've shown you is functionality that our engineering teams have generally built. It runs. You just watched it run. It is also directional. Neither of these capabilities is generally available yet, and it can't be because they ride on WESP, and WESP isn't quite yet available. When it's ready, which will be soon, we will be ready with it. And you'll hear that from Microsoft and the wider Windows Endpoint Security ecosystem soon enough. So where does WESP actually stand? Today, it's in private preview. That's what everything you just watched was running on. Not a mock-up. Private preview code on a real machine. GA is coming. And when it lands, CrowdStrike will be there supporting WESP-delivered functionality for customers who want to start that journey with us. Day one is not a marketing posture for us. We've done this twice already. On Linux, we joined eBPF Foundation and put our own engineers deep into that community. Today, essentially our entire Linux customer base runs on eBPF. On macOS, Apple came to us and asked what would they have to build for us to run in user mode, and we helped co-develop the Endpoint Security Framework with them, and we shipped it on the day it was available. WESP is the third time we've done this, not the first. We're in Microsoft's engineering conversations multiple times a month. So are several other vendors. This is an industry-wide evolution, not a race. Let me kill a headline while I am here one more time. Nobody is getting kicked out of the kernel. This is a partnership, and we are at the front of it. Now, here is the part that we all have to be honest about. Maturing a product like WESP will take years, not months. eBPF did not mature in a year. ESF did not mature in a year. There are millions of drivers in the Windows ecosystem. WESP is not going to mature in a year either. That is a given. There are still event types yet to come, capabilities still missing, performance envelopes to tighten, and edge cases across the enormous surface area of Windows. WESP, for now, will require the latest versions of Windows 11. Now, I know your fleet. Your fleet is not all Windows 11, which means for years, real fleets are going to be hybrid, WESP-capable systems and everything else, side by side. Here is what actually matters. We are not tied down by any of this. Falcon protects the machine you imaged last week and the one that has been running since 2016 at the same level through the same console. Every supported version of every supported OS. WESP is just one more path it will deliver that protection through. It has never been and likely never will be the only one. Let me say something that some of you might be thinking right now. None of this is us trading protection for anything else. You just watched us block a process after an EDR killer stripped our callbacks, then you saw us deny a driver load at boot with nothing of ours needing to be in the kernel at all. Those are things that used to require a kernel driver. We happen to do them now without one. That is not a step back from the kernel. That is just reach we did not have before. That is where the ecosystem is going. I want to tell you our own story, because while Microsoft has been building their framework, we have been building, too. Our own innovations on our own track aimed at three things: simplify what we depend on, increase resiliency, and improve performance. Two projects. Ascent, building the sensors plumbing with the whole modern toolbox instead of only what the kernel allowed. Standard protocols, standard delivery, standard management. Taking advantage of the increased capabilities in the operating system runtime environments to build even better and stronger detections. Modularity, internal freedom with none of the things you like taken away. The ability to add as you go, to reach systems previously unreachable with tighter resource constraints, to do more for your unmanaged devices and for your contingent employees. Let us start with Ascent. When we built the Falcon sensor in 2011, we had to run in the kernel, and I want to be precise about that word. We had to. In 2011, there was no user-mode security framework on Windows. On macOS, ESF was still eight years away from existing. On Linux, eBPF was not ready, and most of our customers were not running distros that could support it. If you wanted to stop a threat before it executed, the kernel was the only place that work could be done. If you watched my keynote last year, you saw the history lesson. It was not a matter of preference. It was the only option on the board, and every endpoint product on the market took it. What is different about us is what we did next. We did not wait for the platforms to change. We went and helped change them on all three. Here is what living in the kernel actually means for an engineer. You cannot write a kernel driver in Go. You cannot use modern C++ with a standard library. No rich frameworks, no standard tooling. The kernel is a brilliant, unforgiving place, and it gives you nothing for free. We built everything ourselves, our own networking protocol, our own file transfer, our own management plumbing. Necessity is the mother of invention, and we invented a lot. These inventions have been protecting the world for over 15 years, and I am proud of every single one of them. But the best reason to own something yourself is that nobody else offers it. For the first time since 2011, that is no longer true. Our custom wire protocol can become gRPC. Standard, documented, inspectable by a network team that has never met us. Our custom file transfer, LFO, can become content delivered over HTTPS through CDNs using local caches on your network. Our bespoke management becomes real integration with the out-of-band management tools you already run. Kernel C with no SDL and no Go becomes modern languages and modern frameworks. This means we can build faster on tooling the entire industry already knows. Bespoke by necessity, transition to standards. Because now every major operating system provides a user-mode security framework, which means for the first time since we founded this company, we get to ask a question that we were never allowed to ask. If we could build a sensor with the plumbing of the entire modern toolbox, what could we build, and what would that open up? This whole right-hand column is the type of change Ascent will bring over time as the platform matures. Of course, nothing will shift underneath you. We take our change controls and requirements seriously. As things move in a given direction, this will be a journey in lockstep with you. But for the first time, the direction is now open. When you get there, for the average Falcon customer, Ascent will largely be invisible. Day to day, you will not see it. That is by design. But if you have ever had to troubleshoot our traffic through a proxy or write a firewall rule for a protocol you cannot name, got asked for a kernel dump, or had to explain our logging to a desktop experience tool, then you might notice. I think you are going to smile. Modularity, this is the second unlock. When we built the sensor in 2011, it was meant to do EDR. That was a product. That was a whole product. Today, look at what rides on that single agent. EDR, data protection, identity, exposure management, cloud, Falcon for IT, and now Guardian. Dozens of modules, one sensor. It is genuinely incredible how much this platform does through one agent. Those capabilities share a lot of internal machinery today because they grew up together. That is what happens when a platform succeeds. Each new mission builds on the last one. Modularity gives them room to move on their own schedule and run at their own pace, which means each one gets better and faster. Think of the sensor today as a single home with a single large room. With modularity, the same single home now has separate rooms because you do not all lead with the same thing. Some of you are SOC first. EDR is the crown jewel, everything else supports it. Some of you are IT first. You deployed us so you could finally see and patch the fleet, and security came along with it. Some of you want lean, one or two missions, nothing else. Minimum footprint on an embedded device or an unmanaged device for a contractor. Or perhaps you have contracts on EDR and data protection with a competitor that is still running the clock. But you have budget for AI security or exposure management. Three very different customers, same platform. Now let me say clearly what is not changing. The monolithic release, not changing. The single deployment package with a single update process, not changing. No reboots, not changing. One sensor, one agent on the box, not changing. These are the pillars of why Falcon wins, and we would be fools to give them up. In fact, combined with Ascent, we will have the ability to more easily deploy a sensor that is fully pre-provisioned to run in your environment from the start for those 30-second developer container workflows that need the sensor to start right away. So modularity changes how the sensor is built on the inside. Fewer interdependencies, cleaner internal boundaries, the freedom for each team to deliver capabilities on their own terms. For those who want it, the ability to decouple and simplify when and where that makes sense. For everyone else, nothing changes except the things you care about get better year after year. So let me make that concrete. Last year, we acquired Seraphic, the best enterprise browser technology we found anywhere. Now we call it the Falcon Seraphic Enterprise Browser. Here is a problem it solves. You have a contractor, part-time, employed by another company, assigned to your project. They need access to your internal resources. Those resources sit behind a VPN, which requires a host configuration profile, which requires installing the Falcon sensor. On a laptop you do not and cannot manage. So what does everyone actually do today? You ship them a laptop, an entire physical laptop in a box with a return label, because that is easier than securing theirs. Those days are over. When that contractor authenticates to your resources, they can get a prompt to download our secure browser. Here is the part I love. Unlike other enterprise browsers, we can wrap the browser that they already use. It does not force them to use a new browser. It can even wrap browser-based apps as well. So look what is actually running on that contractor's machine. The Falcon platform carrying exactly one module. It should not need a kernel driver. It should not need the EDR stack. But today, the full Falcon platform arrives with the whole stack on a machine managed by another company, possibly running another vendor's security software. That is friction nobody needs. With modularity, that friction disappears. One module, same console, same content life cycle your IT team already trusts, and your company resources can now be reached through it, managed, monitored, and revocable on a laptop you will never touch. That's the whole picture. No hardware shipped, no agent forced onto someone else's asset, no compromise on what you can see. Go one step further. Say the engagement gets deeper, and the day comes that you want more than just enterprise browsing on a machine. You add EDR, you add data protection, same platform, same console, no reinstall, no reboot. That's Modularity for those who need it and perfectly and deliberately invisible for those who don't. That's the software column. We're not doing all of this work just to polish our engine. We're lining it up with the rest of what's changing. The silicon the software runs on. This is where Bartley's world and the sensor combine. Last year, I told you that GPUs and NPUs were turning every endpoint into an inference machine and that security would follow the compute. Today, the first step in that direction is generally available in the latest Windows 8.10 sensor. Generally available, shipping. You can turn it on today. A local small language model running directly on your endpoint, not on the cloud, on your machine. It runs on a silicon that's already on the machines you bought. Most machines now have CPUs, GPUs, and NPUs, whether it's Intel, AMD, Qualcomm, or Apple's neural engine, whether it's integrated GPUs or powerful NVIDIA GPUs. The entire industry has built inference-optimized hardware now. In this case, we're running the model on your NPU. It's sitting right there in C2 next to your data. Its job is data protection and classification. It knows, for example, that a quarterly report is sensitive, that a customer list is PII and protected. This week's cafeteria lunch menu for Bring Your Kid to Work Day, irrelevant. Safe to forward to your home email inbox. All of that data and context got understood where it lives, and the model ran for a fraction of the resources and power consumption that a traditional classifier would burn. It rode the efficiencies built into modern silicon, and it did that with zero cloud round trip, the latency of a local call, and the power draw of a whisper. I'd rather you watched it run live than take my word for it. In this demo, an insurance company emails a hospital's record department to request medical data to process a claim. This is highly protected PHI data, which requires HIPAA compliance, as the email states. But the link points to an unsanctioned cloud storage provider. This entire email is likely an attacker attempting to obtain medical records illegally. The records clerk, not knowing this, begins uploading the patient's file. Let's see how Falcon and the system react. We can see CPU utilization is at a baseline of around 12% on its own, and while the CPU line holds steady, the NPU starts to activate. For the next 25 seconds or so, it's going to run at about 20% utilization, while the CPU and memory remain steady. When Falcon needs CPU time, we try to stay within a budget envelope not to affect system resources. The same happens for NPU usage. We stay below 20% because as software matures, we will not be the only ones needing to use it. Let us quickly see what the Falcon console shows. Jumping into the high-severity detections, we can see a Dropbox data upload detection with multiple content patterns that were detected through our AI model running on the NPU. 10 files of protected health information understood, classified, and stopped right there on the machine, on a chip that was already sitting on the laptop. Nothing left the endpoint. Nothing waited on a cloud. Notice what we did to ourselves on the clip. We held to a budget on the NPU on purpose, because over time, we are not going to be the only ones who need it. That is the silicon column running today in production. One model that classifies your documents is a useful thing, but it is not the end of the road. The point is that now we have a place to run local inference and a way to deliver it, and that changes what we are able to do about a problem that is coming at all of us very fast. Our endpoint protection architecture has worked for 15 years and has worked well. The adversary produces attacks. They produce variants. They find vulnerabilities in operating systems, browsers, and other applications. We produce templates, IOAs, micro behaviors, classifications, an arsenal that we have been sharpening since 2011. Their variants hit those rules, and they are stopped. Sometimes the adversary evolves, or new research is published. A race begins between updating our arsenal and the attacker updating their malware. A race I feel we have been winning comfortably for the last decade. Now, the adversary gets an AI, exactly the open weight ablated model that George talked about, designed to produce malware at furious speeds. Now it is not one or two or even a dozen variants. It is 1,000 novel variants mutating faster than any human or automated process can answer. Eventually, one will get through. In a world of AI-driven attackers, we keep saying it, response has to be faster than human speed. With Bartley's new Cyber Superintelligence Lab running in our cloud that he showed you, we can deliver that. But one day, even those extra few milliseconds of a round trip will sometimes be too much, or the model will need too much data to be sent up at a single time. Before that day comes, we need to put the intelligence where the attack already is, on the endpoint, on the silicon, at machine speed. This is where everything in this talk converges to what you have seen this morning. Thanks to modularity in Ascent, we will be able to ship models that leverage the latest silicon capabilities, decoupled from a kernel EDR stack that requires careful updates. Model weights that can be delivered like today's content through the same customer-controlled, safe deployed life cycles, the same rings, the same discipline we apply to every piece of content we ship today because that is how the adversary gets outpaced. I said earlier that the endpoint is reigning again. Now, the endpoint is also reasoning at inference speed. Let me leave you with the shape of this whole week. George and Mike showed you how CrowdStrike is securing AI. Today, Bartley and I showed you how we are leveraging AI. Both halves, same platform, same sensor. Last year, I showed you where things are heading, and this year, I showed you those pieces running. West will ship in lockstep with Microsoft's public GA release, our first SLM model shipping today. We are just getting started. Thank you all so much. Please welcome back Michael Sentonas. Good morning. How was everybody's night last night? I can tell by the quietness maybe people stayed out quite late. Look, what a great few days. I cannot believe I am back on the stage talking about the wrap-up. As we wrap our final keynotes, I would like to thank all of you for joining us in Las Vegas this last week. I got an opportunity to speak to a lot of you over the last couple of days, and one of the big themes that stood out to me, a lot of you said you came to Fal.Con anxious, concerned, quite stressed. These were some of the words that people used about the challenges with regards to AI, the agents, and the complexity of the world that we are now in. A lot of you said, "We are trying to come here to get answers to go back to the office because our business is moving so quick. We want to know how to deal with this problem, and we need to go back to our executives to talk about how we can move quickly." George talked a lot about where AI is going. AI has taken us to what he called the inference speed, where breakout time has collapsed. We challenge some of these concepts, and I think as we all come here together, we all appreciate and understand the stakes have never been higher. It is not enough to respond to threats now. You need complete visibility. You need control. You need the information to manage, secure, and give your organization the confidence that they need today. This week, we made a lot of announcements. We talked about Falcon Guardian and released that, generally available for everybody to start using. I actually did speak to some people that got it activated same day. You heard about the Cyber Superintelligence Lab, SafeMind, Agentic Identity Provider, the supply chain policies, the Agentic SOC, and so much more. A lot of this available to you as part of the platform, not something new that you have to add in, and a lot of it new releases that we have been working to make sure that at the conference, we announce that as generally available. Our commitment is to make sure that we continue to innovate for today and for the future. I have to say, it has been absolutely amazing connecting with so many of you this week. I can say this sincerely, I think the 10,000 people that were here are the brightest minds in cybersecurity, and it was incredible to see so many people coming together. The community coming together, I think, is what is wonderful about our industry. Over 10,000 people came to Fal.Con this week to join that mission, to stop breaches, to secure trust, to do it together. That's our advantage together. It's the power of the crowd. Thank you for joining us, and we'll see you next year at Fal.Con 2027.
Loading workspace