Events 0
En
Ua Ru
Events 0
Search result:
AIDR: A New Cybersecurity Category for Protecting AI Agents- image 1

AIDR: A New Cybersecurity Category for Protecting AI Agents

Each fundamental stage of computing technology development has led to the emergence of a new category of cybersecurity. The Internet created the need for network security, the development of workstations in Endpoint Detection & Response (EDR), and the popularization of cloud technologies in solutions for protecting cloud environments. Each subsequent technological transition occurred faster than the previous one. And none of them compares in pace to the development of artificial intelligence.

AIDR: A New Cybersecurity Category for Protecting AI Agents - image 1
AI Security

The new era of cybersecurity begins with AI

The attack surface associated with artificial intelligence fundamentally differs from anything cybersecurity teams have previously had to protect. Its key element has become AI agents – autonomous systems capable of running code, using tools, invoking APIs, accessing credentials, and performing critical tasks at machine speed, leveraging the privileges of the user who deployed them. Autonomous AI agents, such as Claude Code, OpenAI Codex, and OpenClaw, are already operating directly on endpoint devices.

AIDR: A New Cybersecurity Category for Protecting AI Agents - image 2

Figure 1. SaaS, endpoint, and cloud environments form the three main planes where AI systems operate.

Agentic AI

AI agents create new business risks

The autonomy of AI agents opens up new opportunities but simultaneously creates new risks. Malicious actors can compromise an agent, and the agent itself, through configuration errors or incorrect task execution, can unintentionally create a security threat or even lead to data leakage. For example, at the beginning of 2026, attackers executed a supply chain attack on ClawHub—a public skill registry for OpenClaw. As a result, agents using the compromised skill received hidden modules for data exfiltration.

The proactive threat hunting team CrowdStrike Falcon® Adversary OverWatch™ closely monitors detections initiated by AI agents. Today, their number on monitored endpoints is 2.5 times the number of detections initiated by users. In one case, the team recorded how an AI agent, trying to perform a data-sharing task, attempted to upload confidential corporate files to a public file storage.

AI agents are uncompromisingly focused on achieving the set goal. We are rapidly approaching a world where they, rather than humans, will become the primary users of software. The given examples of agent threats are only the beginning of forming a new landscape of cyber risks that will define the security of corporate environments for decades to come.

Traditional cybersecurity tools were not created for such an environment and do not provide protection for the most critical component—the AI agent execution environment. A prompt injection attack is not logged in AI management reports. A compromised agent using inherited credentials might not trigger the data leakage prevention (DLP) system rules. Detecting a threat without the ability to intervene during its execution is merely observation, not protection.

That is why AI Detection & Response (AIDR) as a new category of cybersecurity solutions must detect threats and stop them directly at the moment of execution, before they spread to other systems.

AI Detection & Response

What is AIDR

AI Detection & Response (AIDR) is a new category of solutions for protecting AI execution environments, providing detection, investigation, and response to threats aimed at or originating from AI systems, regardless of where they operate: on endpoints, SaaS applications, or cloud environments.

AIDR forms a new security architecture for the era of AI agents—a unified platform focused on controlling and protecting AI agent actions in real-time.

The AIDR platform differs from related solution categories by three key principles:

  1. Protection during execution, not security posture assessment.
    Security configuration management solutions assess risks before or after the execution of actions. Instead, AIDR works directly during execution, analyzing each request, tool call, and every AI agent action with millisecond precision, as modern autonomous attacks develop with such speed.
  2.  A single platform instead of a set of separate tools
    During the execution of a single task, an AI agent can simultaneously interact with endpoints, cloud infrastructure, and SaaS applications. Using separate specialized security tools for each level only creates fragmented security signals that do not provide a comprehensive understanding of the attack chain in real-time.
  3. Action-oriented control, not observation.
    AIDR is not limited to threat detection. It ensures a full cycle of protection, allowing the blocking of dangerous actions, concealing confidential data, isolating compromised components, and revoking accesses directly during the execution of potentially dangerous operations.

Additionally, AIDR should ensure the protection of the entire seven-layer AI ecosystem, which includes data, models, prompts, AI agents, digital identities, infrastructure, and interactions.
Each of these layers forms its own attack surface and creates new challenges for cybersecurity.

AIDR: A New Cybersecurity Category for Protecting AI Agents - image 3

Figure 2. The AI ecosystem consists of seven layers: data, models, prompts, AI agents, digital identities, infrastructure, and interactions.

The operational foundation of AIDR is the AI Control Plane—a unified AI security control plane that provides the execution of four key protection functions in real-time:

  • control of digital identities through continuous verification and authorization;
  • data protection by blocking dangerous operations, masking confidential information, and encryption;
  • control of AI agent execution, allowing the stopping of threats directly during their implementation;
  • incident response, including isolation, localization, and elimination of threats.

This control plane should encompass all seven levels of the AI ecosystem and provide unified protection across all environments where artificial intelligence operates: on endpoints, in SaaS applications, and cloud infrastructure.

AI Protection

What Falcon AIDR already provides today

CrowdStrike is forming a new category, AIDR, with the solution CrowdStrike Falcon® AI Detection and Response, which provides unified visibility, real-time threat detection, data protection, access control, and automated threat response in endpoint, SaaS application, and cloud infrastructure environments.

The platform protects both the use of AI by employees and corporate AI agents and AI workloads directly during their execution.

AIDR: A New Cybersecurity Category for Protecting AI Agents - image 4

Figure 3. The Falcon AIDR monitoring dashboard provides complete visibility into users, AI applications, and underlying AI models used within the organization, and displays AI token consumption statistics.

Key capabilities of Falcon AIDR include:

  • Protecting employee use of AI
    Falcon AIDR helps detect shadow AI by ensuring full visibility of employee use of AI agents and services on endpoints, through AI gateways, MCP servers, in cloud environments, and Microsoft Copilot ecosystems.
    The solution allows the application of detailed attribute-based access control (ABAC) policies according to corporate AI governance requirements. For example, policies can consider the user’s role or the AI model version.
    Additionally, Falcon AIDR automatically detects and blocks the transfer of confidential information, personal data (PII), secrets, cryptographic keys, and other regulated data before disclosure. Multiple data masking mechanisms, including format-preserving encryption (FPE), are supported to protect information without reducing AI performance.
  •  Protecting AI development processes during execution
    Falcon AIDR prevents prompt injection and jailbreak attacks, detecting over 200 attack techniques that form the industry’s most comprehensive AI prompt attack taxonomy supported by CrowdStrike.
    The platform checks interactions with MCP servers to prevent unauthorized tool execution and, in real-time, detects malicious URLs, domains, IP addresses, and other potentially dangerous objects in AI responses.
    Falcon AIDR also forms a complete AI activity audit trail, used for regulatory compliance, digital forensics, and continuous security process improvement.
    All detected events and analysis results are automatically forwarded to CrowdStrike Falcon® Next-Gen SIEM, providing a unified platform for cybersecurity operations and event correlation across different environments.
AI Innovation

What’s next

The most critical direction for AI security development is the protection of endpoint devices, as it is on them that the most powerful AI agents run.

Execution processes, tool invocations, file operations, and interactions via Model Context Protocol (MCP) occur directly on the endpoint device and largely remain beyond the visibility of traditional network and application level control tools. There is only one point that allows the observation, control, and response to such activity—the endpoint device.

That is why CrowdStrike will expand the capabilities of Falcon AIDR with deep integration with Falcon Sensor, the same kernel-level operating system sensor that has been protecting endpoints from modern cyber threats for over a decade.
This will allow detecting, identifying, and continuously monitoring AI agent operations directly at the operating system level. Organizations will not need integrations with third-party vendors, specialized SDKs, or additional deployment procedures, significantly simplifying the introduction of a new layer of protection.

AIDR: A New Cybersecurity Category for Protecting AI Agents - image 5

Figure 4.Falcon AIDR interface displaying AI agents operating in a corporate environment. AI agents with an elevated risk level are highlighted in red.

The combination of Falcon AIDR and Falcon Sensor capabilities will unveil a new level of protection for AI agents during their execution, including:

  • Complete real-time AI agent inventory
    Falcon AIDR will form an up-to-date map of all AI agents operating within an organization, including Claude Code, Cursor, Microsoft Copilot, Kiro, OpenAI Codex, as well as unknown or unauthorized Shadow AI agents.
    The platform will show exactly where each agent is deployed, who is using it, and its current risk level. For a large enterprise, the extensive volume of legitimate AI activity creates an ideal environment for hiding malicious actions, making full visibility critically important.
  • Risk assessment of AI agents and behavioral threat detection
    Falcon AIDR will correlate numerous security indicators across the entire AI agent execution chain, detecting behavioral anomalies and automatically assigning risk ratings to agents. This will help analysts quickly prioritize and focus on the most dangerous incidents.
    Upon identifying a high-risk AI agent, specialists can review the complete attack chain, combining the sequence of AI agent actions and the operating system process tree into a single cause-and-effect graph. Such an approach allows tracking the path from each prompt to all its consequences at the operating system level, including file readings, credential access, or other potentially dangerous actions. Analysts can also investigate individual elements of this graph, like a compromised AI skill, to determine the scope of its impact on the environment and promptly take measures to eliminate the threat.
  • From investigation to protection at machine speed
    From the same console, analysts can instantly transition from incident detection to response. For instance, creating a global blocking rule can immediately prohibit the execution of a malicious AI skill throughout the infrastructure. Such an approach allows simultaneously localizing the current incident and preventing the reuse of this threat in the future.

At the time of this publication, this functionality is in pre-beta stage. Its general availability (GA) release is scheduled for the third quarter of this year.

CrowdStrike Platform

Why CrowdStrike

The AI Detection & Response (AIDR) market is rapidly forming. The competitive advantage of CrowdStrike is fundamental: it is based on over a decade of experience in developing endpoint protection technologies and has gradually expanded to cloud and SaaS environments.

The Falcon sensor is already deployed on hundreds of millions of endpoints worldwide. When AI agents became a new challenge for cybersecurity, the existing telemetric infrastructure of CrowdStrike already provided visibility into processes and events at the operating system level, which are critical for their protection.
To date, no competitor can replicate such endpoint coverage on acceptable terms. This advantage will only be strengthened with the development of new Falcon AIDR capabilities within the CrowdStrike Falcon platform.
The prompt injection attack taxonomy supported by CrowdStrike will continuously expand through the research of the Falcon Adversary OverWatch team, which tracks new tactics, techniques, and procedures of malicious actors in artificial intelligence environments.
Every new attack scenario or abnormal AI agent behavior detected in one customer immediately strengthens the protection of all other organizations using the CrowdStrike platform. And even if competitors eventually create a similar telemetry collection infrastructure, they cannot restore the years of accumulated behavioral data and analytics that CrowdStrike already uses to detect threats.

With CrowdStrike, the AIDR solution works as a single platform, single sensor, and single management console.
For organizations already using the Falcon platform, this does not mean deploying a new solution or integrating with another provider. It is a natural extension of the capabilities of the already deployed platform that uses the same Falcon Sensor that today detects and stops cyber threats, and now also provides protection for AI agents directly during their execution.

Learn More

Learn more

Watch the webinar recording in Ukrainian dedicated to AI Detection & Response (AIDR) to learn more about the new category of cybersecurity and the capabilities of CrowdStrike Falcon AIDR.

 

NEWS

Current news on your topic

All news
All news