<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz" -->

---
title: Building an Adaptive Agentic Cybersecurity System with...
description: NVIDIA and CrowdStrike built and evaluated an agentic offense-defense cybersecurity loop where red and blue AI agents continuously attack and defend a...
canonical: https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron | daily.dev
og:description: NVIDIA and CrowdStrike built and evaluated an agentic offense-defense cybersecurity loop where red and blue AI agents continuously attack and defend a...
og:url: https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz
og:image: https://api.daily.dev/og/posts/0EZt6KxdZ.png
og:image:alt: Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron

**[NVIDIA Developer](https://daily.dev/sources/nvidiadev)** · 9 min read · 1 upvotes · 0 comments

## Summary

NVIDIA and CrowdStrike built and evaluated an agentic offense-defense cybersecurity loop where red and blue AI agents continuously attack and defend a representative infrastructure environment. On the defensive side, NVIDIA Nemotron 3 Ultra handled orchestration while a fine-tuned Nemotron 3 Super, customized as CrowdStrike's NL2LogScale model, generated and repaired detections. The defensive harness combined schema grounding, telemetry replay, artifact linting, and independent review to validate detections before deployment. In backtesting, adding the tuned harness and specialized model raised detection success from 16.5% to 41.9% versus a default Nemotron setup. In live-fire testing against unseen attacks, the open Nemotron pipeline generalized better than a frontier proprietary model system, producing three 'gold' detections covering all eight attacks versus zero for the frontier system, though the evaluation covered only one scenario family and is described as a directional case study rather than a general benchmark.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://developer.nvidia.com/blog/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron>

## Questions this post answers

### How much did a specialized harness and fine-tuned model improve automated detection generation compared to a default agent setup?

Adding a tuned harness, customized Nemotron 3 Super detection-authoring model, domain context, tools, and validation raised the average share of generated detections that caught a recorded attack from 16.5% (using Nemotron 3 Ultra with a default harness) to 41.9%, a 2.5x improvement, measured across independently seeded backtesting sessions.

_daily.dev surfaces engineering deep dives like this for teams evaluating agentic detection pipelines._

### How did an open Nemotron-based detection pipeline compare to a frontier proprietary model system in live-fire cybersecurity testing?

The open Nemotron pipeline generalized better: 45% of its backtest-passing detections caught at least one unseen attack versus 29% for the frontier system, and it averaged 2.6 detections per detection versus 1.1. After quality review for noise and behavioral grounding, three open detections qualified as gold covering all eight attacks, while zero frontier detections qualified.

_Teams comparing open versus proprietary models for security automation can track results like these on daily.dev._

### What training data and method did CrowdStrike use to fine-tune Nemotron 3 Super for security detection generation?

CrowdStrike used Nemotron 3 Super as the base for its NL2LogScale model, applying continual pretraining on cybersecurity knowledge, supervised fine-tuning on 9,349 detection-generation and repair examples spanning 59 error types, and reinforcement learning with verifiable rewards using NVIDIA NeMo Gym for query validation in Falcon LogScale and NeMo RL for group relative policy optimization.

_Engineers fine-tuning open models for domain-specific agent tasks can follow developments like this on daily.dev._

## Similar posts on daily.dev

- [Building an Analysis AI Agent for Industrial Alarm Management with NVIDIA Nemotron](https://daily.dev/posts/building-an-analysis-ai-agent-for-industrial-alarm-management-with-nvidia-nemotron-fgfj0zbgq) · NVIDIA Developer · 1 upvotes · 0 comments
- [CrowdStrike Extends Agentic AI Alliance with NVIDIA](https://daily.dev/posts/crowdstrike-extends-agentic-ai-alliance-with-nvidia-7c6tbs0fk) · Security Boulevard · 1 upvotes · 0 comments
- [Open Secret: How NVIDIA Nemotron Models, Datasets and Techniques Fuel AI Development](https://daily.dev/posts/open-secret-how-nvidia-nemotron-models-datasets-and-techniques-fuel-ai-development-qkt1lg1yh) · NVIDIA · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#reinforcement-learning](https://daily.dev/tags/reinforcement-learning), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron","url":"https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz"},"datePublished":"2026-09-01T17:01:50.281Z","dateModified":"2026-09-02T02:54:43.744Z","description":"NVIDIA and CrowdStrike built and evaluated an agentic offense-defense cybersecurity loop where red and blue AI agents continuously attack and defend a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cc9fa95ff4eacbc20bcf45c17dab04fd?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cc9fa95ff4eacbc20bcf45c17dab04fd?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"NVIDIA Developer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"NVIDIA Developer","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/86e45aab42ba48ce83103d01b1119910","url":"https://daily.dev/sources/nvidiadev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,reinforcement-learning,agentic-ai","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"NVIDIA Developer","item":"https://daily.dev/sources/nvidiadev"},{"@type":"ListItem","position":3,"name":"Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron-0ezt6kxdz#faq","mainEntity":[{"@type":"Question","name":"How much did a specialized harness and fine-tuned model improve automated detection generation compared to a default agent setup?","acceptedAnswer":{"@type":"Answer","text":"Adding a tuned harness, customized Nemotron 3 Super detection-authoring model, domain context, tools, and validation raised the average share of generated detections that caught a recorded attack from 16.5% (using Nemotron 3 Ultra with a default harness) to 41.9%, a 2.5x improvement, measured across independently seeded backtesting sessions. daily.dev surfaces engineering deep dives like this for teams evaluating agentic detection pipelines."}},{"@type":"Question","name":"How did an open Nemotron-based detection pipeline compare to a frontier proprietary model system in live-fire cybersecurity testing?","acceptedAnswer":{"@type":"Answer","text":"The open Nemotron pipeline generalized better: 45% of its backtest-passing detections caught at least one unseen attack versus 29% for the frontier system, and it averaged 2.6 detections per detection versus 1.1. After quality review for noise and behavioral grounding, three open detections qualified as gold covering all eight attacks, while zero frontier detections qualified. Teams comparing open versus proprietary models for security automation can track results like these on daily.dev."}},{"@type":"Question","name":"What training data and method did CrowdStrike use to fine-tune Nemotron 3 Super for security detection generation?","acceptedAnswer":{"@type":"Answer","text":"CrowdStrike used Nemotron 3 Super as the base for its NL2LogScale model, applying continual pretraining on cybersecurity knowledge, supervised fine-tuning on 9,349 detection-generation and repair examples spanning 59 error types, and reinforcement learning with verifiable rewards using NVIDIA NeMo Gym for query validation in Falcon LogScale and NeMo RL for group relative policy optimization. Engineers fine-tuning open models for domain-specific agent tasks can follow developments like this on daily.dev."}}]}
```

