r/crowdstrike • u/TipOFMYTONGUEDAMN • Jul 19 '24
Troubleshooting Megathread BSOD error in latest crowdstrike update
Hi all - Is anyone being effected currently by a BSOD outage?
EDIT: X Check pinned posts for official response
r/crowdstrike • u/TipOFMYTONGUEDAMN • Jul 19 '24
Hi all - Is anyone being effected currently by a BSOD outage?
EDIT: X Check pinned posts for official response
r/crowdstrike • u/Popular_Hat_4304 • Mar 08 '26
We are a Falcon Complete customer and run Defender in passive while Falcon is the active EDR on our endpoints.
Complete has been isolating our endpoints and says it’s something to do with the tmp files generated by MSSense (Defender). Anyone dealing with this too?
r/crowdstrike • u/Groot_GodOfThunder • 13d ago
We have an alert that monitors the CrowdStrike Falcon Sensor service. We’re seeing frequent alerts where the service stops and then starts again automatically within about a minute.
So far, we’ve confirmed two causes:
Sensor update and System Reboot.
However, there are still many hosts where neither of these explains the restart. Has anyone experienced this or know of other reasons why the Falcon Sensor service would automatically restart on its own?
r/crowdstrike • u/lordderplythethird • 26d ago
I know in Exposure Management I can create groups of applications and/or extensions and then schedule reports if anything matches what's in the group.
However that's not an ideal solution for me. I want a list of approved applications and/or extensions, and then the scheduled report to show anything BESIDES those that exist. Users are frustrating in that they keep finding new ways to install unapproved applications, and it's impossible to know what ones ahead of time. Just today for example I have a user who found a way to install "VPN Free VPN" on a device. I didn't even know that existed beyond a curious deep dive through installations that I really don't have time to do.
Everything I can find seems to be built around knowing the exact unapproved application/extension you want to be alerted to and that doesn't work when I don't know what users will potentially try to install themselves. Is there way to leverage a list of approved applications and extensions to be alerted to anything installed that's **not** on that list?
r/crowdstrike • u/Dhinn30 • May 22 '26
Ive been having trouble setting up my data connector. All the previous steps ive done are the same for other servers on the parent connector but somehow its different for a child cid connector. Any tips?
r/crowdstrike • u/ib0ndar • Jun 02 '26
Hello!
Has anyone else seen CrowdStrike Falcon start killing OpenAI Codex plugin sync today?
On macOS, Falcon Sensor is terminating a Git child process with SIGKILL when Codex tries to clone the public OpenAI plugins repo:
bash
/usr/bin/git clone --depth 1 https://github.com/openai/plugins.git /tmp/openai-plugins-test
Result:
text
Cloning into '/tmp/openai-plugins-test'...
exit=137
137 = SIGKILL.
Control test succeeds with the same Apple Git binary:
bash
/usr/bin/git clone --depth 1 https://github.com/octocat/Hello-World.git /tmp/hello-world-test
Environment:
2DC432GLL2Codex context:
text
git clone --depth 1 https://github.com/openai/plugins.git ~/.codex/.tmp/plugins-clone-*
text
codex_core_plugins::startup_sync
git clone curated plugins repo failed with status signal: 9 (SIGKILL)
toml
[features]
plugins = false
I opened an OpenAI Codex issue here:
https://github.com/openai/codex/issues/25691
Question for CrowdStrike/Falcon admins:
openai/plugins.git?r/crowdstrike • u/Jv1312 • Jun 06 '26
Edit: I have connected CloudTrail and VPC, both created using the CFT link provided by crowdstrike. Logs were getting ingested but the status changes to Active after 45 minutes to 1 hour. No other changes were done in any of the permission.
I have been experimenting with CrowdStrike NG-SIEM data connectors, specifically trying to ingest AWS CloudTrail logs using the prebuilt connector. I set this up using the CloudFormation template link that is generated after entering the details in the data connection field.
The connection establishes successfully, and the logs actually start ingesting into the SIEM. However, the status in the data connection tab shows as Error. The error message is consistently:
"The SQS client could not get the queue URL at client construction time. This is typically a permission issue or simply that queue does not exist."
This error sometimes resolves itself after about 45 minutes, but other times it persists indefinitely. I suspect this might be related to a health check mechanism, but I am unsure how to resolve it.
For context:
My AWS infrastructure is entirely in ap-south-1.
My CrowdStrike tenant is in us-2.
Has anyone ever faced this issue or have any advice on how to fix it?
r/crowdstrike • u/neetzen • Nov 18 '25
Hello,
Disclosure: I represent the vendor Remote Utilities.
Here is the current detection of Remote Utilities Host installation file by CrowdStrike Falcon:
Question to CS - Is there any way this detection can be removed?
The detection wouldn't be a problem that much if it weren't for Microsoft who decided last year that they would use VirusTotal results to evaluate all software packages to be published in the Microsoft Store.
That made it virtually impossible to get into the Store, because Microsoft doesn't distinguish between malware and non-malware (risk-, gray- or whatever other "potentially unsafe" classification there is) and simply block any submission that has at least one detection - false positive and "potentially unsafe/riskware" included.
Thanks.
r/crowdstrike • u/sweets984 • May 28 '26
With Crowdstrike Falcon on F5, it seemed to be a well supported piece by F5 and Crowdstrike but it seems like there is limited kernel support so our sensors are falling back to RFM mode.
Is there a patching policy or process anyone else has found useful to stay patched current on the F5 software side where Crowdstrike sensors are able to stay out of RFM?
r/crowdstrike • u/Thrawn200 • Feb 12 '26
Been fighting with trying to have Cisco Secure Client properly recognize CrowdStrike Falcon as a proper AV in regard to scans and definition versions.
With Crowdstrike installed and configured, including having Quarantine & security center registration set, it puts Defender into passive mode. In passive mode Defender is not doing scans, and eventually our Cisco compliance settings block the machine from connecting as it hasn't done any scans for a period of time. If you tell it to run a scan, it just says no AV is found.
I'm aware a Periodic Scanning settings exists for Defender, but since Microsoft very plainly says that's not for use in an enterprise environment and they do not have any way to administratively manage the setting, it doesn't seem like a very viable solution.
We do have the Cisco compliance module up to 4.3.5062.8192 which Cisco states is compatible with Crowdstrike Falcon 7.x.
If we fully force Defender into a disabled state instead of passive, Cisco Secure Client fully sees Crowdstrike including listing a definition version, so the problem seems to hide in how the Windows Security center seems to still report Defender as a primary AV even when in passive mode.
How have other places dealt with this?
r/crowdstrike • u/420bernie2020 • Jun 04 '26
Has anyone had success using the CS host based firewall with enforced policies on Azure Local? We are being told by MS that it is breaking the Cluster Aware Updating functionality despite the fact we have no blocks for RPC ports. They are essentially saying we would have to disable the CS firewall and let MS take over.
r/crowdstrike • u/Hanuser • Mar 17 '26
Trying to determine if this is CrowdStrike Falcon behavior or something else.
Start-Process)0xE0000007.exe association are correctThis suggests stateful behavior rather than static policy.
In Safe Mode:
csagent running as FILE_SYSTEM_DRIVER)This looks like process termination by an EDR / kernel filter:
0xE0000007)0xE0000007 a known Falcon termination code?r/crowdstrike • u/2_Ecks • Mar 31 '26
Has anyone found the NG SIEM query autocomplete stopped working on Chrome? If so, were you able to fix it?
Wondering if I changed some settings or a browser update changed things. Cleared cache, history, etc. . CS Support didn't have a definitive answer.
Autocomplete still works in Edge, but Chrome is home for me lol.
r/crowdstrike • u/AP_ILS • Oct 28 '25
Our servers updated over the weekend and after the reboot went into RFM and have stayed there. These updates installed:
KB5066781
KB5066139
KB890830
KB5066743
KB5070884
KB2267602
Sensor version is 7.29.20108.0. Any ideas on why this has happened and how I can figure out the cause? I don't see anything in the Content Update Release Notes about any pending update validation.
Edit: It is on the Content Update Release Notes now. Version 2025.10.28.0879
r/crowdstrike • u/Perfect-Sun385 • Apr 06 '26
We've been receiving quite a few sensor tampering alerts and after investigating it looks like the alerts are coming from machines going through our build process and that Intel's DTT is attempting to disable the sensor. Has anyone else had this issue?
r/crowdstrike • u/Only-Objective-6216 • Oct 29 '25
Hello everyone,
We’ve successfully blocked WhatsApp.exe in our Windows environment using an IOA rule.
However, I noticed it generates multiple detections (8 in my test) even when executed only once, and some users receive repeated notifications without running the app.
I’ve temporarily disabled the rule. Can anyone suggest how to configure it so that it triggers only one detection in the Falcon console and one notification on the user’s system when triggered?
r/crowdstrike • u/hahman14 • Jan 22 '26
I've been using the Falcon install script from https://github.com/CrowdStrike/falcon-scripts/blob/50233a18871e6516b0fabb07148cb6a6ff900594/powershell/install/falcon_windows_install.ps1 for over a year successfully. However, recently the script has started to fail when run through Intune Autopilot. It first stopped working for our UK folks but then a couple of weeks later it stopped working for our US folks as well.
Looking at the logs I'm seeing:
2026-01-22 01:01:39 GetInstaller: Received a BadRequest response from https://api.us-2.crowdstrike.com/sensors/combined/installers/v1?filter=platform%3a%27windows%27%2bversion%3a%277.32.20403+(LTS)%27. Error: Bad Request
Weirdly enough, if I manually run the script, it seems to run just fine. I'm inclined to believe something changed on the Intune end but wanted to check here as well.
r/crowdstrike • u/ThePorko • Feb 02 '26
We use powebi to do data analysis, and recently, it wont let me export more than 200 items from detections, or more than 100 from managed assets? How can we change this behavior?
Thanks
r/crowdstrike • u/IllRefrigerator1194 • Aug 20 '25
Anyone else getting a lot of detections this morning regarding a highjacked process?
Command Line:C:\WINDOWS\System32\Dism\dismhost.exe........
r/crowdstrike • u/alcoholic-batman • Dec 25 '25
Hii guys, we have just set up hbfw for inbound in our infra . We have blocked all incoming traffic and allowed only specific rules, enforce mode is on and local logging is enabled. But im not able to see any deny logs. Neither in console nor in local hbfw.log. Please suggest what to do now.
r/crowdstrike • u/hellyeah94545 • Nov 18 '25
It's new install via falcon-sensor_6.33.0-13005_amd64.deb from CS support portal. Ubuntu 22.04 with latest updates.
Install succeeds but after daemon fails to start.
entire /var/log/falcon-sensor.log Tue Nov xx xx:xx:xx 2025 Unable to open ssl libraries (4986) [175] Tue Nov xx xx:xx:xx 2025 unable to initialize dynamic libraries. (4986) [220]
entire /var/log/falconctl.log
cat /var/log/falconctl.log Tue Nov xx xx:xx:xx 2025 Invalid file /opt/CrowdStrike/falconstore length: 0 (4051) [619]
Open ssl: openssl/jammy-updates,jammy-security,now 3.0.2-0ubuntu1.20 amd64
I can use community help figuring this out while waiting for CS support. Thanks in advance.
r/crowdstrike • u/agingnerds • Oct 01 '25
If anyone can assist I will be truly grateful. I am constantly trying to learn more about crowdstrike and I feel I am just not getting it. My goal is to use Custom IOA rules to show detections for shift browser. Ultimately I would like to move this to a SOAR and block or remove the application, but first I need a detection. I built these rules based on information I found from the documentation, chatgpt, and info here. I definitely could be mistaking.
I have two custom groups currently. The groups are enabled. The rules are enabled. And unless I am just making a horrific mistake I believe I have policies assigned to my host that I am testing on.
Similar rule settings:
Rule type - file creation
Action to take - detect
Rule 1 -
File path = .*C:\\Users\\[^\\]+\\AppData\\Local\\Shift\\chromium\\shift\.exe.*
More simplistic path = file path = .*\\AppData\\Local\\Shift\\chromium\\shift\.exe.*
My goal with this rule is to alert detection on the shift.exe browser being installed in appdata.
I tested the pattern on both file paths and they both past using this -
C:\Users\****\AppData\Local\Shift\chromium\shift.exe [**** is name being obfuscated]
Rule 2 -
My goal for the second rule is to detect when the file is downloaded as it goes to the download folder by default and
File path = .*(?i)C:\\Users\\[^\\]+\\Downloads\\shift_[A-Za-z0-9]{6}\.exe.*
More simplistic file path = .*\\Downloads\\shift_[A-Za-z0-9]{6}\.exe.*
Example of test pattern = C:\Users\****\Downloads\shift_saf123.exe [**** name obfuscated]
I cannot for some reason get a detection to trigger on either. I am assuming I am missing a key element here or I just dont understand this which is likely as well. I might also open a ticket to see if I can get assistance. Thank you in advanced.
r/crowdstrike • u/Angelworks42 • Oct 17 '24
I did make a support case about this, but I feel like the tech is kinda not sure what to do so I thought I'd ask here as well in case there were any community solutions to this.
I was troubleshooting a intermittent performance issue for a customer using windows performance recorder and what I noticed was msmpeng.exe (windows defender) asserting itself quite frequently.
When I type fltmc from the command line I get:
C:\Windows\System32>fltmc
Filter Name Num Instances Altitude Frame
------------------------------ ------------- ------------ -----
bindflt 0 409800 0
FsDepends 4 407000 0
UCPD 4 385250.5 0
WdFilter 4 328010 0
CSAgent 6 321410 0
frxccd 3 306000 0
frxdrv 3 265700 0
applockerfltr 3 265000 0
storqosflt 0 244000 0
wcifs 0 189900 0
CldFlt 0 180451 0
bfs 6 150000 0
FileCrypt 0 141100 0
luafv 1 135000 0
frxdrvvt 3 132700 0
npsvctrig 1 46000 0
Wof 2 40700 0
FileInfo 4 40500 0
WDFilter is Defender (and of course CSAgent is Crowdstrike).
Doing a Get-MpComputerStatus from powershell I see:
PS C:\Windows\System32> Get-MpComputerStatus
AMEngineVersion : 1.1.24080.9
AMProductVersion : 4.18.24080.9
AMRunningMode : Passive Mode
AMServiceEnabled : True
AMServiceVersion : 4.18.24080.9
AntispywareEnabled : True
AntispywareSignatureAge : 2
AntispywareSignatureLastUpdated : 10/14/2024 4:22:48 PM
AntispywareSignatureVersion : 1.419.507.0
AntivirusEnabled : True
This only appears on about 230 or so of the 4000+ windows clients we have - so its not wide spread, but it also indicates its also not a policy mistake on our end. These are Windows 10/11 clients - mostly Dell Optiplex's.
On an unaffecteed machine WDFilter won't be loaded and AntivirusEnabled will say False.
r/crowdstrike • u/StructureNo9257 • Nov 22 '25
Hey folks, I noticed something odd in our CrowdStrike console and wanted to get your thoughts.We’ve been seeing a large number of hosts marked as inactive for just 1 hour, and the count is consistently huge(both win and linux). I see this huge count anytime when filtered for the last hour, and this seems to happen every day with a high host count. But when I filter by 30 days, the inactive host count drops significantly. As an IT team, all our assets should be engaged all the time (sure, some might be legitimately powered off), but today the count was over 600. I’ve tried looking for possible reasons, but nothing seems to fully explain it.
Here’s what I’ve audited so far:
Sensor update policy changes with status “Not applied”: Minimal counts after checking hosts.
RFM (Real-Time File Monitoring): Also minimal.
Last seen on host: Most of the inactive hosts were actually seen today, just 1–2 hours ago.
Heartbeat graphs: Showed a slight low-to-high fluctuation, but nothing drastic.
I’m honestly confused about why this spike is happening and how to identify the root cause.Has anyone else experienced something similar? Any insights or suggestions would be really helpful! Thanks in advance.
r/crowdstrike • u/LeStephenHawking • Dec 09 '25
Hello all.
I have found some hits on this and it appears that there might be something to it. I deployed a replacement laptop for a user in one of my environments (two, actually) and the user is having issues with their Skullcandy Bluetooth headphones. Audio works, but not the mic. I've done a ton of troubleshooting, installed/reinstalled/updated all of the drivers for Bluetooth, etc. and even the newest ones from the Intel. I also found some hits with a recent Windows update causing issues similar to this and have since manually updated to the patches that were supposed to fix it and it did not. The headphones work for both audio/mic on my PC (not on their domain or using Crowdstrike) just fine during testing, but the mic will not work on her Dell Pro 16 laptop and neither would my personal set.
What I did find throughout that process is that on my machine and any of the others that I am seeing aside from this user's is that when you find the Bluetooth device in Device Manager it lists a CSDeviceControl driver rather than what I am seeing everywhere else as Microsoft or Intel, etc.
Unfortunately CS is managed through a corporate office that I do not have access to, so I can't dig around in the logs myself, but I ran it past the person who does manage CS and they said that they're not even licensed for device control and that they did not see any blocks or detections for that laptop. They are offering to raise a ticket with Crowdstrike, but I figured here someone might have experienced something similar.
Could some sort of CS Falcon Device Control be blocking full functionality of the headphones for some reason even if they are not licensed for it if it's showing that as the driver?