Cybersecurity Research

CrowdStrike's SafeMind Pits AI Attacker Against AI Defender to Build Smarter Security

CrowdStrike · 17 Sept 2026
Key Takeaway As AI driven attacks grow faster and more automated, small businesses should prioritise security vendors and tools that are tested against realistic, evolving attack simulations rather than static defences.

CrowdStrike has introduced SafeMind, a new approach to AI security that moves away from running offensive and defensive AI tools separately. Traditionally, one AI agent hunts for weaknesses while another catches threats, but the two rarely interact, leaving a gap that fast moving, AI generated attacks can exploit.

SafeMind closes that gap by running an offensive agent (Red Tempest) and a defensive agent (Blue Solano) against each other continuously in realistic, simulated enterprise environments built from real network data. This ongoing contest, which CrowdStrike calls adversarial co-evolution, allows the defensive side to learn directly from the attacking side's tactics. Red Tempest simulates full attack chains, including network discovery, exploitation, privilege escalation, and data theft, across more than 1,000 scenarios covering 155 known attack techniques, with each scenario run thousands of times to ensure reliable results.

According to CrowdStrike, this method has produced a 70% improvement in detection accuracy, a 99% reduction in cost, and detection capabilities created six times faster than before, all achieved autonomously and at scale.

AI security CrowdStrike threat detection adversarial AI cybersecurity innovation
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from CrowdStrike. We link back to every original so you can read it yourself.