Skills
CrowdStrike RSAC: EDR AI Runtime Protection + Shadow AI Discovery Scans Endpoints for MCP Servers, LLM Runtimes, and AI Dev Tools
At RSAC 2026, CrowdStrike announced three new Falcon capabilities. EDR AI Runtime Protection provides runtime visibility of agentic application behavior at the endpoint — capturing commands, scripts, file activity, and network connections. Shadow AI Discovery automatically discovers AI applications, agents, LLM runtimes, MCP servers, and development tools across all endpoints, linking them to asset context and privilege exposure. AIDR for Endpoint extends prompt inspection to desktop apps (ChatGPT, Claude, Cursor, Copilot) detecting injection attacks and data leaks in real time.
Source
↳ Follow the thread