Igor Kozlov

Igor Kozlov

@iekozlov · Twitter ·

Congratulations to the CrowdStrike team on fine-tuning Nemotron 3 Nano 30B-A3B into a reasoning-enabled detection-triage classifier. What they did: • Input: Windows endpoint context, including process lineage, command lines, prevalence, ATT&CK mappings, severity, sensor metadata, and sometimes analyst context • Ground truth: analyst-assigned TP/FP labels • Training: prompt optimization, self-training, and RLVR using those labels as ground truth What does this mean for cyber defense? It demonstrates a locally deployable, specialized triage classifier. However, this is not a general-purpose cyber defense LLM, investigator, or threat-hunting agent whose primary goal is threat detection and retrieval. The model reasons over the context already provided. It does not retrieve new evidence, query security tools, correlate across data sources, or conduct an investigation. One result stands out: CrowdStrike reports that general-purpose models clustered around 55% to 71% accuracy on this task, roughly in line with an untrained NVIDIA Nemotron 3 Nano 30B-A3B. This looks different from our Cyber Defense Benchmark, where larger frontier models dominate the top ranks and Nemotron 3 Super places 24th out of 25 models. The results raise an interesting question: Would models excelling at threat hunting outscore smaller ones if they were given access to the environment logs? Cyber Defense Benchmark: https://simbian.ai/research/cyber-defense-benchmark CrowdStrike research: https://www.crowdstrike.com/en-us/blog/teaching-ai-to-reason-through-detection-triage/

CrowdStrike

CrowdStrike

Cyber defense is entering the superintelligence era. ⚡ Introducing the CrowdStrike Cyber Superintelligence Lab, the first frontier AI research organization built for cyberdefense and AI safety. The Lab delivers CrowdStrike SafeMind, a family of purpose-built security models and harnesses. SafeMind runs as one system designed to deliver AI safety: an offensive model that finds the attack path, a defensive model that closes it, and the harnesses that operate both in the same loop. Built using @nvidia Nemotron open models and using @CoreWeave’s AI Cloud for training and inference, SafeMind goes beyond AI that simply identifies threats, it defeats them. Learn more: https://crwdstr.ke/6012B178vu

Post media