business , compliances , email , o-s , security

Field notes – CrowdStrike DLP detection

August 22, 2023

At a high level

If a DLP threat is detected does Crowdstrike respond first?

  1. Crowdstrike does not offer any Data Loss Prevention services or DLP product modules at this time.
  1. Research shows that CrowdStrike is aligned with MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK(tm)) matrix to label our detections and related supporting events.
  • ATT&CK is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target.
  • ATT&CK is useful for understanding security risks against known adversary behavior, planning security improvements, and verifying that defenses work as expected.

https://attack.mitre.org/versions/v8