Skip to content
Glamour Canada
World

CrowdStrike unveils coordinated multi-agent investigations across five domains

CrowdStrike says agents cut investigations from hours to minutes. NIS2 gives 24 hours from becoming aware, so faster verdicts shorten the window.

By Samie Lein

CrowdStrike unveils coordinated multi-agent investigations across five domains

CrowdStrike has announced coordinated multi-agent investigations on a shared context layer, with customers setting autonomy from human-in-the-loop approval to fully autonomous execution. NIS2 starts its 24-hour reporting clock from becoming aware of a significant incident, and holds management bodies liable for the measures they approve.

CrowdStrike says AI agents now run attacks across several systems at once, and that investigations have to move the same way. It has announced coordinated multi-agent investigations across endpoint, identity, SaaS, cloud and network, the company said.

Michael Sentonas, CrowdStrike’s president, put the pitch as a trust problem. Agents in the SOC are table stakes, he said, and the question every CISO is asking is how to trust what the agents found.

The claim is speed, hours turned into minutes. The market is crowded, and Databricks bought Panther Labs this year to challenge Splunk and CrowdStrike.

Agents run in parallel on a shared context layer, a persistent memory across every agent, investigation and tenant. Customers set the autonomy per workflow, from human-in-the-loop approval to fully autonomous execution.

In Europe that speed carries a second meaning. The NIS2 directive gives essential and important entities 24 hours to file an early warning, and 72 hours for the full notification.

The clock runs from becoming aware of a significant incident. It does not run from the moment an analyst finishes writing the incident up.

So compressing the investigation compresses the window. An agent converging on a verdict in minutes moves the moment of awareness earlier and leaves less of the 24 hours, not more.

The second meaning concerns who signs it off. Automating the analyst does not automate the person the directive names.

Article 20 requires management bodies to approve the cybersecurity risk-management measures and oversee their implementation, and says they can be held liable for infringements. Members are also required to follow training.

There is no autonomy slider for that. A board can approve fully autonomous execution and still owns the outcome of every action taken under it.

Sentonas is asking the right question, and Europe has a recent answer to it. Attackers poisoned the scanner the European Commission relied on, and its automated pipeline pulled the update.

That breach ran through a security tool behaving exactly as configured. Raising the autonomy raises what the same failure costs.

None of it is evenly in force yet. The transposition deadline passed in October 2024, and the Commission chased 23 member states before referring four to the Court of Justice this July.

Source link

Originally published by thenextweb.com. Syndicated material does not necessarily reflect the views of Glamour Canada.

More World