AI is changing the pace of cybersecurity. Agentic systems can coordinate work and pursue complex objectives over long horizons. Security teams are beginning to apply agents across security operations, but many implementations remain anchored to existing alerts, predefined workflows, and known attack behaviors. The harder problem is identifying what defenses miss and turning those gaps into reliable coverage. This requires repeatedly testing adaptive attacks in an organization’s unique environment and validating candidate detections against normal enterprise activity.

Continuous offense-defense testing creates this feedback loop. Controlled attacks produce the telemetry and ground truth defensive agents need to expose gaps, improve coverage, and retest. However, the end-to-end cycle still requires significant manual effort. Could red and blue agents powered by open models and specialized harnesses operate this loop at machine speed and scale?

NVIDIA and CrowdStrike evaluated an agentic attack-defense system in an isolated environment modeled on NVIDIA accelerated computing infrastructure. On the defensive side, NVIDIA Nemotron models customized for cybersecurity operate within CrowdStrike SafeMind, its agentic cybersecurity system. CrowdStrike reports that its Blue Solano defensive model is more accurate than the leading proprietary frontier model tested, at 99% lower cost, in CrowdStrike internal evaluations. For this evaluation, the optimized open-model configuration paired NVIDIA Nemotron 3 Ultra for defensive orchestration with a fine-tuned Nemotron 3 Super for detection generation.