CrowdStrike has announced multi-cloud threat hunting capabilities for its Cloud Native Application Protection Platform (CNAPP). These capabilities help organizations hunt for threats in cloud environments and workloads and reduce the mean time to respond.The multi-cloud threat hunting capabilities are delivered via CrowdStrike's Falcon endpoint protection platform, the company said. They combine CrowdStrike's Falcon Horizon cloud security posture management (CSPM) and Falcon Cloud Workload Protection (CWP) modules into a cloud activity dashboard to help security and development and operations teams prioritize cloud security issues, address runtime threats and perform cloud threat hunting.In addition, CrowdStrike has announced the following new capabilities for Falcon CWP:The new CNAPP capabilities will be generally available in May 2022.
CrowdStrike Unveils New Capabilities for Falcon Horizon, Falcon CWP
Along with introducing multi-cloud threat hunting capabilities for CNAPP, CrowdStrike has announced the following new capabilities for Falcon Horizon:- Automated Amazon Web Services (AWS) remediation workflows that provide context and guidance to fix security issues and reduce time to resolve incidents.
- Identity access analyzer for Microsoft Azure that ensures Azure Active Directory groups, users and apps have permissions enforced based on least privilege.
- Custom indicators of misconfigurations for Google Cloud Platform with custom security policies that align with business goals.
- Container detection that uses artificial intelligence, machine learning, indicators of attack, deep kernel visibility, custom indicators of compromise and behavioral blocking to defend against malware and other threats.
- Rogue container detection that helps an organization maintain an up-to-date inventory as containers are deployed and decommissioned.
- Drift container prevention that allows an organization to discover new binaries created or modified at runtime to secure its containers.




