‘Living Off the Land’
CF: What do you find most worrisome about the current threat landscape?
MR: Adversaries don’t sleep and CrowdStrike doesn’t either. When we looked across the spectrum, we saw nation-state adversaries, e-crime and significant increases last year in ransomware. Another interesting one is around malware. Of all of the detections in the CrowdStrike Security Cloud in the fourth quarter of 2021, nearly two-thirds of those were malware-free, which means traditional legacy antivirus solutions weren’t even going to come close to catching those. And so instead of using malware, the attackers are increasingly leveraging living off the land (LOTL), which is a lot of legitimate credentials and built-in tools. And it’s a deliberate effort to evade those legacy products. It’s certainly not going anywhere and the complexity continues to increase every single day.