3 SEP 2026 — CrowdStrike has released two cybersecurity models built with Nvidia. Blue Solano defends. Red Tempest attacks, trained on fifteen years of the company's incident-response fieldwork and the telemetry its sensors collect. Blue Solano is the product CrowdStrike is selling. Red Tempest is the news, because access to it is controlled by an application process and not by a technical lock.

What was announced

The pair were unveiled at Fal.Con on 1 September and come out of a new Cyber Superintelligence Lab run with Nvidia. Both are built on Nvidia's open Nemotron models and trained on CrowdStrike's own corpus: Falcon sensor telemetry, Falcon Complete managed-detection annotations and fifteen years of incident response. Chief executive George Kurtz described that dataset as the largest in the world.

The two models run inside a system called SafeMind. It builds a digital twin of a customer's environment from Falcon sensor data, asset inventories, identity stores and threat intelligence. On that twin, Red Tempest attacks, Blue Solano learns from each attempt and deploys detections, and the loop repeats until the attacker runs out of moves.

SafeMind runs natively inside the Falcon platform. The individual models are also offered standalone through Project QuiltWorks, which CrowdStrike describes as a trusted access programme.

15 yearsOf incident-response fieldwork in the training corpus
2 modelsRed Tempest offensive, Blue Solano defensive
NemotronThe Nvidia open model both are built on
QuiltWorksThe programme through which the models are offered standalone

A vendor has shipped an offensive frontier model

Offensive tooling and red teaming are both old. The new part is the artefact: a model trained to find paths through a defended network, shipped by a security vendor to customers instead of staying inside a research team.

The stated safeguard is enrolment. Project QuiltWorks is a trusted access programme, so Red Tempest is controlled by deciding who gets admitted rather than by anything in the model itself. That is the same shape of control OpenAI described when it restricted Astra's cybersecurity capabilities, and we noted then that a perfect benchmark score says more about the benchmark than the capability.

The relevant question for a buyer is what the vetting is for, rather than whether CrowdStrike will do it. A model that reliably finds attack paths is worth as much to an attacker as to a defender. There is no version of this tool that helps only one of them.

Breakout time reaching zero is a claim about the simulation

The headline performance framing from the event was that breakout time, the window in which an intruder moves laterally before anyone reacts, has effectively hit zero at runtime.

Read where the zero applies. Inside the loop, the defence is generated in response to an attack the system itself performed against a replica, so the reaction time is the time between two components of the same product. That is an engineering achievement, but it does not measure response time to a human intruder trying something new.

The digital twin is the other boundary. It is built from what the Falcon sensors can see, so anything outside sensor coverage is outside the twin: an unmanaged contractor laptop, a forgotten appliance, a software-as-a-service tenant with its own identity store. Those are where intrusions start. A loop that exhausts every attack path in the twin has exhausted the paths through the inventory, which is a different set.

What fifteen years of incident response teaches

The training corpus is the moat, and it helps to be precise about what is in it. Incident-response fieldwork is a record of intrusions that were detected, investigated and written up, at organisations that had bought the product and called the vendor.

That shape has consequences. Intrusions nobody found are absent by construction, and so are those at organisations that never engaged an incident-response firm. A model trained on this data learns the patterns of attacks that got caught. Those are the right patterns for building detections and the wrong ones for guessing what a skilled adversary might try next.

None of that makes the corpus less useful. It makes the loop's stopping condition less reassuring than it sounds, because "no viable attack path remains" means no path the offensive model thought to attempt.

The security market is now buying models rather than rules

This is the second structural change in the category this year. We reported in August that AI security had become its own budget line, and the assumption then was that the spending would go on protecting AI systems.

SafeMind points somewhere else. The spending is going on models that do the security work, which changes what a customer is actually procuring. A human-written detection rule can be read, debated and disabled. A detection generated by a model attacking a replica of your network is a black box, and the logic behind it may not be recoverable.

None of that is an argument against the approach. It is a reminder to ask what the audit trail looks like before a regulator or an insurer does.

What to watch next

Three things would move this from an announcement to a result. Whether Red Tempest is ever made available outside a vetted programme, and on what terms. Whether the loop finds attack paths that human red teams missed, published as findings rather than as marketing. And whether anything the twin certified as closed is later used in a real intrusion at the same customer.

The third is the only one that tests the claim. Until then, what exists is a description of how the system is built rather than evidence of what it prevents. A security product's own simulation is never an independent verdict.