CrowdStrike Threat Hunting Report 2023–2026: What Changed?
CrowdStrike's 2023–2026 Threat Hunting Reports trace a shift from endpoint intrusions to identity, cloud, AI and software supply chain abuse.

CrowdStrike’s Threat Hunting Report series shows a clear evolution in adversary behavior between the 2023 and 2026 editions. Across four reporting periods, the emphasis moves from identity abuse, vulnerable public-facing applications and remote management tools toward cross-domain intrusions, social engineering, cloud exploitation, AI-enabled operations and software supply chain attacks.
The reports also show continuity. Valid identities, trusted tools, unmanaged systems and legitimate administrative functions repeatedly appear as ways for adversaries to reduce their detectable footprint. What changes is the number of environments in which that trust can be abused: endpoint and Active Directory in 2023, cloud and identity systems in 2024, SaaS and next-generation SIEM data sources in 2025, and AI infrastructure, developer tooling and software registries in 2026.
This comparison covers CrowdStrike — Threat Hunting Report — 2023, 2024, 2025 and 2026. It is most useful for CISOs, SOC and threat hunting leaders, threat intelligence teams, identity and cloud security teams, vulnerability management teams, and researchers looking for a multi-year view of how CrowdStrike’s frontline observations have changed.
A methodological caution matters when reading the latest edition. The 2023–2025 reports primarily measure interactive, hands-on-keyboard intrusions. The 2026 report explicitly expands the scope to include automated attacks alongside interactive activity. Its intrusion-growth figure therefore should not be treated as directly comparable with the earlier interactive-intrusion growth rates.
Short answer
From 2023 to 2026, CrowdStrike’s Threat Hunting Reports describe a shift from endpoint-centered intrusion hunting toward attacks that exploit trust across identity, cloud, SaaS, developer and AI environments. Identity abuse remains a consistent foundation, but the techniques around it evolve from valid accounts and Kerberoasting to help-desk social engineering, vishing, device-code phishing and token-based cloud access. Cloud activity becomes progressively more important, while AI changes from a defensive technology and emerging adversary aid into both an operational force multiplier and a direct attack surface. The 2026 edition also places much greater emphasis on rapid vulnerability weaponization and software supply chain attacks.
What this report series covers
The series is built around observations from CrowdStrike OverWatch and the wider Counter Adversary Operations organization. The 2023 report covers July 1, 2022 through June 30, 2023; the 2024 report covers July 1, 2023 through June 30, 2024; the 2025 report covers July 1, 2024 through June 30, 2025; and the 2026 report covers July 1, 2025 through June 30, 2026.
Through 2025, the core dataset focuses on interactive intrusions: incidents in which human operators actively work inside a victim environment. The 2026 edition deliberately broadens the model because CrowdStrike argues that modern adversaries increasingly combine hands-on activity with automation.
That change is important for trend analysis. Earlier year-over-year increases measure interactive intrusions, while the 2026 figure measures a wider category of overall intrusion activity.
What changed across editions?
2023: Identity becomes the central control point
The 2023 edition makes identity the defining theme. CrowdStrike reports that 62% of interactive intrusions involved abuse of valid accounts and highlights a 583% year-over-year increase in Kerberoasting. Attempts to obtain secret keys and other credential material through cloud instance metadata APIs increased 160%.
The report also emphasizes two other developments that remain important later in the series. More than 20% of interactive intrusions involved exploitation of public-facing applications, while adversary use of remote monitoring and management tools increased 312% year over year.
Cloud proficiency is already visible. CrowdStrike writes that adversaries had become increasingly capable of navigating major cloud platforms, abusing misconfigurations and built-in management tools. Cross-platform capability across Windows, Linux and macOS is another major theme.
Interactive intrusion volume increased 40% year over year. Technology remained the most frequently targeted sector, while financial services saw more than an 80% increase in interactive intrusion activity.
In retrospect, 2023 establishes the foundations for the rest of the series: stolen identity, legitimate tooling, vulnerable edge applications, cloud credentials and the erosion of a simple endpoint perimeter.
2024: The problem becomes cross-domain
The 2024 edition retains identity as a core concern but changes the frame. The main operational concept is now the cross-domain threat: activity that spans identity, endpoint and cloud, leaving only partial signals in any one security control.
Interactive intrusions increased 55% year over year, faster than the 40% growth reported in 2023. eCrime accounted for 86% of interactive intrusions.
The earlier RMM trend also continues rather than disappearing. CrowdStrike reports a further 70% year-over-year increase in adversary use of RMM tools, with RMM present in 27% of all interactive intrusions. ConnectWise ScreenConnect surpassed AnyDesk as the most observed RMM tool, illustrating that the tactic persisted even as preferred products changed.
Cloud targeting becomes more explicit. Citing the 2024 Global Threat Report, the report notes a 75% increase in cloud environment intrusions from 2022 to 2023 and discusses adversaries pivoting between cloud control planes and hosted virtual machines. SCATTERED SPIDER is presented as a prominent cloud-conscious adversary able to move across email, cloud management and virtual machines.
A major new actor-specific development is FAMOUS CHOLLIMA. CrowdStrike says DPRK-linked operatives applied to or actively worked at more than 100 companies, turning recruitment and legitimate employee access into an intrusion path. This expands the identity problem beyond compromised credentials: the “valid user” can now be an adversary who was deliberately hired.
2025: Social engineering, AI and cloud acceleration
The 2025 edition describes the “enterprising adversary,” but the underlying development is more concrete: attackers are combining identity compromise, unmanaged systems, cloud access and social engineering more efficiently.
Interactive intrusions still increase, but the year-over-year rate slows to 27%. eCrime accounts for 73% of interactive intrusions, down from 86% in the prior edition.
Cloud growth accelerates sharply. CrowdStrike reports that cloud intrusions identified in the first half of 2025 were 136% higher than all of 2024, while suspected cloud-conscious China-nexus intrusions increased 40% year over year.
Vishing becomes a major identity-access technique. The report says vishing attacks had increased 442% from the first to the second half of 2024 and that the first half of 2025 had already surpassed the total observed in 2024. SCATTERED SPIDER is a central example: help-desk social engineering is used to reset passwords or MFA methods, after which compromised identities are used to pivot rapidly into SaaS, IAM and other environments.
The report also quantifies SCATTERED SPIDER’s increased speed. In one 2025 intrusion, the actor moved from account takeover to ransomware deployment in about 24 hours, compared with approximately 35.5 hours in 2024 and 85 hours in 2023.
GenAI becomes a dedicated threat-hunting topic. CrowdStrike describes adversaries using GenAI to improve phishing, reconnaissance, scripting, malware development, translation and identity fabrication. FAMOUS CHOLLIMA is highlighted as the most mature example: the report says its insiders infiltrated more than 320 companies during the reporting period, a 220% year-over-year increase, and used GenAI across application, interview and day-to-day employment workflows.
Vulnerability hunting also moves closer to the center of the report. CrowdStrike highlights internet-exposed applications, zero-days and post-exploitation hunting as a compensating control when defenders cannot patch fast enough.
2026: Trust shifts into AI, software supply chains and cloud authentication
The 2026 edition changes both the threat picture and the measurement model. CrowdStrike expands the report beyond interactive intrusions to include automated attacks, arguing that adversaries increasingly combine automated scale with hands-on execution.
Overall intrusion activity increases approximately 4%. This is much lower than the 27% increase in the 2025 edition, but the report explicitly warns against interpreting the plateau as reduced adversary intent. Because the scope changes, the number is not a clean continuation of the earlier interactive-intrusion series.
The identity theme remains, but the technique mix evolves. Vishing intrusions doubled in the first half of 2026 compared with the second half of 2025. CORDIAL SPIDER and SNARKY SPIDER use vishing to compromise SSO identities and move directly into SaaS data. In one example, SNARKY SPIDER moves from account takeover to data theft in under five minutes.
Device-code phishing adds another cloud-native identity technique. CrowdStrike reports a 15-fold increase in monthly device-code phishing attempts over six months, showing how trusted OAuth authentication flows can be abused without following a traditional phishing pattern.
Cloud activity also remains on the same upward trajectory. eCrime cloud-conscious activity rises 171%, with financially motivated actors targeting credentials, cryptomining opportunities, LLM access and digital financial assets.
The most visible new area is the software development ecosystem. Malicious npm packages account for 87% of identified malicious software registry threats in the first half of 2026. CrowdStrike highlights STARDUST CHOLLIMA and ALTERED SPIDER, with the latter reportedly compromising more than 300 software dependencies in one day and using stolen credentials to pivot into cloud environments.
AI also moves from “tool used by adversaries” to “tool, target and force multiplier.” CrowdStrike reports an 89% increase in AI-enabled adversary activity in 2025, describes LLMJacking and cost harvesting, and maps AI-related behaviors to MITRE ATLAS in addition to MITRE ATT&CK.
Vulnerability exploitation becomes markedly faster. CrowdStrike reports a 42% year-over-year increase in zero-day exploitation from 2024 to 2025. From January through June 2026, 88% of observed exploitation involving a vulnerability with a public proof of concept occurred within 48 hours of PoC release. VAULT PANDA and GENESIS PANDA are described exploiting a critical web application vulnerability within 24 hours of public disclosure.
The multi-year shift at a glance
| Area | 2023 | 2024 | 2025 | 2026 |
|---|---|---|---|---|
| Core intrusion measure | Interactive intrusions +40% YoY | Interactive intrusions +55% YoY | Interactive intrusions +27% YoY | Overall intrusions ~+4%; scope expanded to automated attacks |
| Identity | Valid accounts, Kerberoasting, credential material | Identity hunting across unmanaged and cross-domain activity | Help-desk social engineering and vishing | Vishing, SSO compromise, device-code phishing and token abuse |
| Cloud | Growing proficiency and metadata credential targeting | Cloud/endpoint/control-plane pivots | Cloud intrusions accelerate; China-nexus cloud growth | eCrime cloud-conscious activity +171%; cloud monetization |
| Legitimate tools | RMM use +312% | RMM use +70%; 27% of interactive intrusions | Less prominent as a headline theme | Not a headline metric; trust abuse broadens into SaaS and developer tooling |
| AI | Mainly platform/defensive context | Limited adversary focus | GenAI becomes an adversary-enablement theme | AI is tool, target and attack surface; MITRE ATLAS added |
| Vulnerabilities | Public-facing exploitation and faster N-day exploitation | Present but less central | Dedicated vulnerability hunting and zero-day cases | 42% rise in zero-day exploitation; 88% of public-PoC exploitation within 48h |
| Supply chain | 3CX illustrates cross-platform supply-chain risk | Not a central theme | Not a central headline theme | Major focus on registries, CI/CD, IDEs and malicious packages |
| Actor examples | VICE SPIDER, INDRIK SPIDER, SCATTERED SPIDER, LABYRINTH CHOLLIMA | SCATTERED SPIDER, FAMOUS CHOLLIMA, HORDE PANDA, STATIC KITTEN | FAMOUS CHOLLIMA, SCATTERED SPIDER, BLOCKADE SPIDER, OPERATOR PANDA, GENESIS PANDA | ALTERED SPIDER, STARDUST CHOLLIMA, CORDIAL SPIDER, SNARKY SPIDER, VAULT PANDA, GENESIS PANDA |
Which earlier trends were confirmed by later editions?
Cloud proficiency: strongly confirmed
The 2023 report says CrowdStrike was observing adversaries become more proficient in major cloud platforms and notes that this was consistent with expectations from the prior year. Within the four editions reviewed here, the subsequent reports reinforce that direction repeatedly.
The 2024 edition emphasizes cross-domain cloud activity and cites a 75% increase in cloud environment intrusions. The 2025 edition reports a 136% increase in cloud intrusions in the first half of 2025 compared with all of 2024. The 2026 report records a 171% rise in eCrime cloud-conscious activity.
The metrics are not identical and should not be combined as one statistical series, but the qualitative prediction is clearly supported: cloud expertise moves from an emerging capability to a routine part of adversary tradecraft.
Identity as the new perimeter: confirmed, but transformed
The 2023 report argues that identity has become a pivotal control point. That framing remains valid in every later edition.
What changes is the form of identity abuse. Kerberoasting and credential theft dominate the 2023 discussion. By 2024, identity telemetry is used to detect activity on unmanaged hosts and cross-domain pivots. In 2025, help-desk social engineering and vishing become central. By 2026, vishing, SSO compromise, OAuth device-code phishing and application tokens extend identity attacks further into SaaS and cloud workflows.
The later editions therefore confirm the 2023 identity thesis, while showing that “identity security” can no longer be reduced to password theft or Active Directory.
RMM abuse: confirmed in 2024, then de-emphasized
The 2023 report records a 312% increase in adversary use of RMM tools. The 2024 edition confirms that this was not a one-year anomaly: RMM use rises another 70%, and 27% of interactive intrusions involve RMM tools.
Later editions devote much less headline attention to RMM. That does not establish that the technique declined. Based on the provided reports, the supported conclusion is that RMM abuse remained important through 2024 and was subsequently overtaken editorially by broader cross-domain, identity, cloud, SaaS and supply-chain themes. The later reports do not provide a comparable RMM metric that would prove a decline.
GenAI-enabled operations: direction confirmed
The 2025 report predicts that threat actors of different motivations and skill levels will continue increasing their use of GenAI, particularly for social engineering, while also warning that enterprise AI adoption creates a growing attack surface.
The 2026 edition supports both directions. It reports an 89% surge in AI-enabled adversary activity during 2025, describes AI-assisted payload and command generation, and documents direct targeting of AI systems through AI-related server exploitation and LLMJacking.
This is one of the clearest cases where a 2025 outlook becomes an operational theme in the next report.
Faster vulnerability exploitation: confirmed and intensified
The 2023 report already warns about expanded zero-day use and the speed with which actors develop N-day exploits. The 2025 report gives vulnerability hunting a dedicated role and argues that post-exploitation behavior must be hunted when patching cannot happen fast enough.
The 2026 report substantially strengthens that concern. It reports a 42% year-over-year rise in zero-day exploitation from 2024 to 2025 and says 88% of observed exploitation with a public PoC in the first half of 2026 occurred within 48 hours of PoC release.
The series therefore moves from warning about shortening exploit timelines to treating hours-scale weaponization as a central defensive constraint.
The 2025 vishing forecast: direction supported, exact forecast not verifiable
The 2025 edition says vishing had already exceeded the prior year’s total in the first half of 2025 and was on track to double 2024 volume by year end.
The 2026 report confirms that vishing continued to accelerate, reporting a twofold increase in vishing intrusions in the first half of 2026 compared with the second half of 2025. However, the provided 2026 material does not state the final full-year 2025 total relative to 2024.
It is therefore reasonable to say that the upward trend was confirmed, but the specific “double 2024” projection cannot be verified from these four reports alone.
Which techniques became less prominent?
Some topics recede from the report narrative, but that should not automatically be interpreted as a decline in real-world use.
Kerberoasting is the clearest example. It receives extensive attention in 2023 after a 583% increase, but it is not a major theme in the 2024–2026 reports. The available material does not provide comparable later-year Kerberoasting statistics, so the evidence supports editorial de-emphasis, not a measured decline.
RMM tools follow a similar pattern. They remain highly prominent in 2024 after strong growth in both 2023 and 2024, but later reports put more emphasis on SaaS, unmanaged systems, identity, cloud and supply-chain access. Again, the provided material does not establish a numerical decline.
By contrast, traditional malware as the defining unit of an intrusion clearly becomes less useful as an analytical frame. The series repeatedly emphasizes malware-free activity, legitimate administrative tooling, valid accounts, living-off-the-land behavior and trusted services. By 2026, CrowdStrike explicitly broadens the report to account for automated activity and attacks that cross multiple trusted environments.
Which actors emerged or changed most visibly?
FAMOUS CHOLLIMA: from insider anomaly to AI-enabled operating model
FAMOUS CHOLLIMA is one of the strongest multi-year developments.
In 2024, CrowdStrike reports that operatives had applied to or worked at more than 100 companies. The 2025 edition says more than 320 companies were infiltrated during the reporting period, a 220% year-over-year increase, and describes GenAI as integrated across job applications, interviews and employment.
In 2026, FAMOUS CHOLLIMA remains prominent but expands into software supply chain activity involving AI-centric development environments and cryptocurrency or blockchain targets. The progression illustrates how an identity and insider-access model can evolve into a broader developer-ecosystem threat.
SCATTERED SPIDER: from RMM and cloud tradecraft to faster identity-led ransomware
SCATTERED SPIDER appears in the 2023 report as an example of RMM abuse. In 2024, CrowdStrike uses the actor to illustrate sophisticated cross-domain cloud tradecraft.
The 2025 edition shifts the emphasis again. SCATTERED SPIDER uses help-desk social engineering and identity compromise to move through SaaS and privileged systems, while reducing time on heavily monitored endpoints. CrowdStrike reports a progression from account takeover to ransomware in roughly 24 hours in one 2025 case, down from average timelines of 35.5 hours in 2024 and 85 hours in 2023.
In 2026, SCATTERED SPIDER is no longer the main identity-social-engineering example. CORDIAL SPIDER and SNARKY SPIDER take that role, suggesting that techniques associated with SCATTERED SPIDER had spread into a broader eCrime pattern.
China-nexus actors: growing cloud and vulnerability specialization
China-nexus activity becomes progressively more prominent in the cloud and vulnerability portions of the series.
The 2025 report highlights OPERATOR PANDA exploiting network appliances and GENESIS PANDA operating across cloud environments. In 2026, VAULT PANDA and GENESIS PANDA are used to demonstrate rapid exploitation within 24 hours of public vulnerability disclosure, while the report also describes China-nexus adversaries as particularly fast in vulnerability weaponization.
This is less a story of one actor replacing another than of expanding specialization: network appliances, cloud control planes, telecom targets and rapid exploitation all become recurring China-nexus themes.
ALTERED SPIDER and STARDUST CHOLLIMA: the 2026 supply-chain shift
These actors represent one of the clearest new themes in the 2026 edition.
ALTERED SPIDER is described operating at software-registry and CI/CD scale, including a campaign that compromised more than 300 dependencies in one day. STARDUST CHOLLIMA is tied to malicious libraries, stolen maintainer credentials and developer-focused social engineering.
Their prominence reflects the report’s broader conclusion that developer ecosystems and trusted software distribution channels have become high-leverage initial access paths.
Themes that became more prominent
AI Security & AI Governance
AI is peripheral to adversary tradecraft in the 2023–2024 editions, becomes a dedicated operational topic in 2025, and becomes both a threat-enablement and attack-surface framework in 2026.
The 2026 addition of MITRE ATLAS mapping is particularly notable because it treats AI-targeted and AI-enabled activity as a distinct class of observable adversary behavior rather than an occasional supporting technique.
Cloud Security
Cloud security grows in importance every year. The emphasis progresses from cloud credentials and misconfigurations, to cloud control-plane pivots, to rapidly increasing cloud intrusions, and finally to direct financial exploitation of cloud identities, compute and LLM services.
Identity, Phishing & Access Security
Identity is the most consistent theme across the four editions. The techniques evolve, but the strategic idea stays stable: attackers prefer to look like legitimate users when possible.
The series moves from stolen credentials and Kerberos abuse to insider access, help-desk manipulation, vishing, SSO compromise and OAuth device-code phishing.
Vulnerability & Exposure Management
Vulnerability exploitation is important in 2023, quieter as a dedicated theme in 2024, returns strongly in 2025, and becomes one of the defining issues in 2026 because of the speed between disclosure and exploitation.
Software & Supply Chain Security
Supply chain risk appears in earlier cases, including the 3CX incident referenced in 2023, but it becomes a full strategic theme only in 2026. The focus shifts from a notable compromise to systematic abuse of package registries, CI/CD components, IDEs and developer identities.
Themes that remained consistent
Threat Actors, Geopolitics & Intelligence
Every edition organizes part of its analysis around named adversaries and their motivations. DPRK-, China-, Russia- and Iran-nexus operations remain recurring sources of targeted activity, while SPIDER groups dominate financially motivated examples.
SOC, Detection & Response
All four reports argue for continuous hunting based on behavior rather than reliance on malware signatures or isolated alerts. What changes is the required telemetry: endpoint in earlier editions, then identity and cloud, then SIEM/SaaS, and by 2026 AI and developer ecosystems.
Cybercrime, Malware & Attack Techniques
eCrime remains a major share of interactive activity, although its percentage changes: 86% in the 2024 reporting period and 73% in the 2025 reporting period. The 2026 methodology change makes simple continuation of that series more difficult.
Ransomware & Extortion
Ransomware persists, but the surrounding tradecraft evolves. Earlier reports focus on data theft, extortion, RMM and initial access brokers. The 2025 report highlights remote encryption, unmanaged systems and shifting ransomware-as-a-service ecosystems. Identity-led actors such as SCATTERED SPIDER demonstrate that ransomware can be the final step of a broader cross-domain intrusion rather than the defining technique from the start.
What this means for security teams
The four reports collectively argue for a broader definition of threat hunting.
First, identity telemetry is no longer optional context. The series repeatedly shows adversaries using valid accounts, authenticating through legitimate services, resetting MFA, registering devices and accessing SaaS directly. A hunting program focused only on malicious endpoint processes will miss part of the attack path.
Second, cloud telemetry needs to be treated as primary security data. Cloud activity moves from an emerging capability in 2023 to a major target and monetization environment by 2026.
Third, defenders should separate technique prevalence from report prominence. Kerberoasting and RMM become less visible in later editions, but the reports do not provide sufficient evidence to conclude that they disappeared. Newer concerns are layered on top of older ones.
Fourth, vulnerability response windows are compressing. The 2026 finding that most observed exploitation with a public PoC occurred within 48 hours suggests that conventional periodic patch cycles alone cannot cover the highest-risk periods. Exposure prioritization and post-exploitation hunting become complementary controls.
Fifth, software development environments now need to be treated as part of the security perimeter. Package registries, CI/CD workflows, source-control identities, IDE extensions and cloud credentials can form one connected attack path.
Finally, AI security has become operational rather than speculative. The 2025 report describes attackers augmenting existing methods with GenAI; the 2026 report shows AI services being abused directly, adversary operations mapped through MITRE ATLAS, and AI-related systems becoming intrusion targets.
Which edition should you read?
Read CrowdStrike — Threat Hunting Report — 2023 if you want the clearest foundation for the identity shift. It is particularly useful for valid-account abuse, Kerberoasting, RMM growth, access brokers, public-facing application exploitation and early cloud proficiency.
Read CrowdStrike — Threat Hunting Report — 2024 for cross-domain hunting. It connects identity, endpoint and cloud telemetry and provides strong examples involving SCATTERED SPIDER, FAMOUS CHOLLIMA and RMM persistence.
Read CrowdStrike — Threat Hunting Report — 2025 for the transition to GenAI-enabled operations, vishing, faster identity-led ransomware, cloud acceleration, unmanaged systems and vulnerability hunting.
Read CrowdStrike — Threat Hunting Report — 2026 for the current picture in this set. It is the strongest edition for software supply chain attacks, AI as an attack surface, rapid vulnerability weaponization, cloud monetization, device-code phishing and the blending of automation with interactive intrusion activity.
For a historical view, the four are most useful together. The 2023 report explains why identity became central; 2024 shows why security domains must be correlated; 2025 shows attackers scaling social engineering and AI; and 2026 extends the same trust-abuse model into software development and AI infrastructure.
Reports mentioned in this article

CrowdStrike — CrowdStrike 2026 Threat Hunting Report
The 2026 Threat Hunting Report highlights the rapid evolution of cyber threats, driven by AI and automation, with a focus on supply chain attacks, cloud-based cybercrime, and the increasing use of AI by adversaries. It outlines key trends, findings, and recommendations for organizations to enhance their threat hunting and defensive strategies.

CrowdStrike — 2025 Threat Hunting Report
The 2025 Threat Hunting Report highlights a significant increase in cloud intrusions and voice phishing (vishing) attacks, with a 136% rise in cloud intrusions compared to all of 2024 and a 442% increase in vishing attacks from the first to the second half of 2024. The report underscores the growing use of generative AI (GenAI) by adversaries, particularly by FAMOUS CHOLLIMA, and the shift in threat actor strategies, including faster ransomware deployment and increased nation-state activity. It also emphasizes the need for cross-domain threat hunting and advanced security solutions to counter evolving threats.

CrowdStrike — CrowdStrike 2024 Threat Hunting Report
The 2024 CrowdStrike Threat Hunting Report highlights the evolution of cross-domain and hybrid threats, the rise of eCrime adversaries, and the increasing use of RMM tools and cloud environments by cybercriminals. It emphasizes the importance of proactive, intelligence-driven threat hunting and the role of AI in detecting and mitigating sophisticated attacks.

CrowdStrike — 2023 Threat Hunting Report
This report highlights the growing threat of identity-based attacks, particularly through Kerberoasting and environmental keying techniques. It also emphasizes the increasing use of RMM tools by adversaries and the importance of proactive threat hunting to detect and prevent breaches. The report covers insights from July 1, 2022, to June 30, 2023, and outlines the formation of the new CrowdStrike Counter Adversary Operations team to enhance threat detection and response.
