CrowdStrike used its Fal.Con keynote on 1 September to launch SafeMind, a pair of cybersecurity models built with Nvidia that are designed to attack and defend the same network — and to keep doing it to each other.

Two models, opposite jobs

Red Tempest is the offensive half. It probes for attack paths and emulates adversary behaviour. Blue Solano is the defensive half, remediating what Red Tempest finds.

Both are built on Nvidia’s open Nemotron models. CrowdStrike says it trained them on Falcon sensor telemetry, its threat intelligence, event annotations from its Falcon Complete managed detection service, and fifteen years of incident response fieldwork.

Network cabling running between racks in a server room.
SafeMind runs its two models against a digital twin of the customer's own environment. panumas nikhomkhai · pexels · Pexels License

The loop is the product

What CrowdStrike is selling is not either model on its own. The two run against a digital twin of a customer’s environment: Red Tempest looks for a way in, Blue Solano closes it, and the cycle repeats until nothing is left to find.

That framing follows from the problem the company keeps pointing at — breakout time, the gap between an intruder landing and moving laterally, has compressed to the point where CrowdStrike now describes it as runtime. A defence that needs a human in the loop does not fit inside that window.

The numbers are the vendor’s own

CrowdStrike reports a 29% higher detection rate, six times faster end-to-end remediation, and 99% cost savings on detection and remediation.

Every one of those figures comes from CrowdStrike’s evaluation of CrowdStrike’s product. They are worth reading as a claim about the architecture’s direction, not as a reproduced result. The 99% cost figure in particular is a comparison against frontier models the company chose and has not named in the release — a benchmark that cannot be checked from the outside.

Where it runs

SafeMind operates natively inside the Falcon platform. The individual models and the harnesses that pit them against each other are available separately through a programme CrowdStrike calls Project QuiltWorks.

Lines of code and a terminal window on a computer display.
The individual models are available separately through a programme CrowdStrike calls Project QuiltWorks. Tima Miroshnichenko · pexels · Pexels License

CoreWeave is providing compute for both training and inference, its chief executive Michael Intrator said in the release. The company did not publish pricing or a general-availability date.

What to watch

Whether an offensive model trained on fifteen years of real incident data stays inside the digital twin. CrowdStrike is shipping a system whose stated purpose is to find exploitable paths in customer environments, one week after OpenAI classified its own model at the Critical cybersecurity capability level. The industry is converging on the same capability from two directions, and the safeguards are being designed after the capability, not before it.