CrowdStrike unveiled SafeMind, an agentic system aimed at automating enterprise threat detection and response, at its Fal.Con conference on September 1. Chief executive George Kurtz called it the first fully agentic cybersecurity platform the company has shipped. At its core sit a pair of models built alongside Nvidia, one playing the adversary in controlled tests and one hunting down and repairing whatever its counterpart exposes.

CrowdStrike names the defensive model Blue Solano and describes it as encoding the response playbooks its own security teams already use in the field. The paired model, Red Tempest, exists to stress-test those defenses against simulated intrusion patterns inside a digital twin, a virtual replica of a customer’s environment, rather than the live network itself. Nvidia’s open Nemotron family is the base for both, and CoreWeave’s cloud carries the training and inference load.

What they learned from belongs to CrowdStrike alone. The company lists the ingredients as Falcon sensor telemetry, its threat-intelligence archive, events annotated by the Falcon Complete managed-detection team, and fifteen years of casework responding to incidents. That proprietary dataset, not the underlying Nemotron architecture, is CrowdStrike’s actual differentiation claim: any vendor can license a foundation model, but few hold a comparable volume of labeled enterprise intrusion history.

Operationally, SafeMind runs as a closed loop inside the digital twin. The simulated-adversary model searches for gaps, the defense model closes them, and the cycle repeats until the simulation clears. CrowdStrike says the same testing harness works with third-party proprietary and open-source models, not only its own pair, positioning SafeMind as infrastructure rather than a single closed product.

This is adversarial self-play, the same training pattern that let game-playing systems improve by competing against copies of themselves, now applied to enterprise security. The open question CrowdStrike does not address is transfer: whether a defense model that gets better at stopping its own paired attack model also gets better at stopping real attackers who never trained against that twin, or whether it only learns to beat an opponent shaped by its own assumptions.

On benchmarks CrowdStrike ran itself, SafeMind is credited with detecting 29 percent more, remediating six times quicker, and costing 99 percent less, though the frontier and open-source models it was measured against go unnamed. The company has not published independent verification of any of the three figures, and the release does not name the comparison models or the test conditions.

SafeMind runs natively inside the existing Falcon platform. A programme called Project QuiltWorks opens the models and the testing harness to teams outside CrowdStrike’s customer base who want the tooling without adopting the whole platform.

Security teams evaluating SafeMind or Project QuiltWorks should ask CrowdStrike for the benchmark methodology and comparison baselines before budgeting around the 29 percent, 6x, or 99 percent figures, and should treat digital-twin performance as a floor, not a guarantee, against attackers operating outside that simulation.

CrowdStrike announced SafeMind and its benchmark figures in its own press release dated September 1, 2026.