cd /news/artificial-intelligence/crowdstrikes-safemind-puts-red-team-… · home topics artificial-intelligence article
[ARTICLE · art-121581] src=mlq.ai ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

CrowdStrike’s SafeMind puts red-team and blue-team AI inside Falcon

CrowdStrike introduced SafeMind, an agentic cybersecurity system that pairs Red Tempest, an offensive AI model, with Blue Solano, a defensive AI model, inside its Falcon platform, announced September 1 at Fal.Con in Las Vegas. Built with NVIDIA's Nemotron 3 Ultra and a fine-tuned Nemotron 3 Super, SafeMind automates attack simulation, detection generation, and validation, though pricing, production customers, and autonomy limits remain undisclosed.

read5 min views2 publishedSep 4, 2026
CrowdStrike’s SafeMind puts red-team and blue-team AI inside Falcon
Image: Mlq (auto-discovered)
  • SafeMind combines Red Tempest, an offensive model, with Blue Solano, a defensive model, and software harnesses that coordinate their actions inside CrowdStrike Falcon. <sup>[1]</sup>
  • NVIDIA says Nemotron 3 Ultra handles orchestration while a fine-tuned Nemotron 3 Super generates and repairs detection rules in the evaluated configuration. <sup>[2]</sup>
  • CrowdStrike is soliciting early-access users, but has not disclosed SafeMind-specific pricing, named production customers or detailed production autonomy limits. <sup>[3]</sup><sup>[4]</sup>
  • The companies report higher detection, faster remediation and lower cost than frontier-model baselines, while the public evaluation remains limited and company-produced. <sup>[1]</sup><sup>[2]</sup><sup>[5]</sup>

CrowdStrike has introduced SafeMind, an agentic cybersecurity system that uses separate artificial-intelligence models to simulate attacks, generate defenses and test those defenses in a continuing loop. The system was announced September 1 at CrowdStrike’s Fal.Con conference in Las Vegas and is intended to operate natively inside the Falcon security platform. [1]

SafeMind is built around Red Tempest, which CrowdStrike describes as an offensive model for emulating attack scenarios, and Blue Solano, a defensive model for protecting enterprise assets. Specialized software harnesses provide the runtime layer for context, memory, tools, permissions, orchestration, model routing, safety controls and feedback. [1][3]

A red-team model and a blue-team model #

The architecture separates the reasoning models from the operational layer that determines what they can access and what actions they can take. In NVIDIA’s published evaluation, a red-agent harness selected attack paths inside an isolated environment modeled on NVIDIA’s accelerated-computing infrastructure. Falcon sensors captured the resulting telemetry, after which the blue-agent harness analyzed the activity, generated candidate detections and replayed them against recorded events. [2]

NVIDIA says Nemotron 3 Ultra orchestrated the defensive workflow, while a customized Nemotron 3 Super handled detection generation and repair. CrowdStrike trained the specialized model with cybersecurity knowledge, supervised fine-tuning and reinforcement learning based on executable LogScale queries. The published training process used 9,349 examples covering 59 programmatically generated error types. [2]

The harnesses are not limited to NVIDIA’s open models. CrowdStrike says they can also work with frontier and open-source models, giving customers a way to choose models while retaining the orchestration and validation layer. [1]

Early access, with no public SafeMind price #

CrowdStrike’s Cyber Superintelligence Lab page invites organizations to request SafeMind early access. It identifies CoreWeave as a design partner and NVIDIA as CrowdStrike’s AI-compute design partner. The page also says NVIDIA is investing $100 million over five years in the lab. [3]

The public materials reviewed for this article do not identify an enterprise customer using SafeMind in production. NVIDIA says it tested the system on a digital twin of its own infrastructure, while CrowdStrike says CoreWeave provides cloud infrastructure for training and inference. Those disclosures establish development and evaluation relationships, not a list of production customers. [1][2]

CrowdStrike’s public pricing page lists standard Falcon bundles, including Falcon Go, Pro and Enterprise, but does not list a SafeMind price. The company has not disclosed whether SafeMind will be priced per endpoint, by workload, through usage credits or as part of Falcon Flex. [4]

The data and autonomy questions remain open #

CrowdStrike says SafeMind’s training data includes Falcon sensor telemetry, threat intelligence, Falcon Complete managed-detection annotations and 15 years of incident-response work. NVIDIA says CrowdStrike post-trained Nemotron with its own threat data without sending that data to an outside provider. The announcements do not specify whether customer telemetry is used for model training by default, how long prompts and agent traces are retained, or what customer-controlled data-isolation options will be available. [1][6]

CrowdStrike describes SafeMind as capable of autonomous, long-running security workflows, while the technical evaluation kept the attack-and-defense loop inside an isolated environment. The public materials do not specify which production actions require human approval, whether a generated detection can be promoted automatically, or what rollback and audit controls apply when an agent changes a customer environment. [2][3][5]

An independent review from Kaleido Field said the companies established the architecture and Falcon integration, but not production incident reduction, false-positive rates, missed-detection rates, containment times or autonomous-action limits. That distinction matters because SafeMind’s operational authority resides in the harness as much as in the underlying model. [5]

Performance claims are still company-reported #

CrowdStrike says internal evaluations found a 29% higher detection rate, six-times-faster end-to-end remediation and 99% cost savings against leading frontier and open-source baselines. The launch materials do not publish the full workload, model list, pricing assumptions or an independent reproduction of those figures. [1]

NVIDIA’s technical case study reports that an optimized Nemotron pipeline achieved a 41.9% mean backtest detection rate, compared with 16.5% for Nemotron 3 Ultra using a default harness. In live-fire testing against eight unseen attacks, five of 11 open-model detections fired, compared with 10 of 35 detections from a frontier system; three open-model detections passed the study’s stricter “gold” review. [2]

NVIDIA also says the evaluation covered one scenario family, used limited benign traffic and experienced harness failures in three of eight live-fire runs. It characterizes the results as a directional system-level case study rather than a general benchmark. [2]

Brad Ebley of solution provider Blackwood told CRN that open models could make agentic security more economically sustainable, particularly as organizations seek to avoid premium frontier-model costs. That supports the commercial rationale for SafeMind, but it does not independently validate CrowdStrike’s detection or remediation results. [7]

Companies mentioned #

Further sources #

The stories that matter, in one email. Free — unsubscribe anytime.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @crowdstrike 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/crowdstrikes-safemin…] indexed:0 read:5min 2026-09-04 ·