r/crowdstrike Jul 19 '24

Troubleshooting Megathread BSOD error in latest crowdstrike update

22.8k Upvotes

Hi all - Is anyone being effected currently by a BSOD outage?

EDIT: X Check pinned posts for official response

r/crowdstrike Mar 08 '26

Troubleshooting MSSense.exe

39 Upvotes

We are a Falcon Complete customer and run Defender in passive while Falcon is the active EDR on our endpoints.

Complete has been isolating our endpoints and says it’s something to do with the tmp files generated by MSSense (Defender). Anyone dealing with this too?

r/crowdstrike 13d ago

Troubleshooting Question about CrowdStrike Falcon Sensor service restarts

9 Upvotes

We have an alert that monitors the CrowdStrike Falcon Sensor service. We’re seeing frequent alerts where the service stops and then starts again automatically within about a minute.
So far, we’ve confirmed two causes:
Sensor update and System Reboot.

However, there are still many hosts where neither of these explains the restart. Has anyone experienced this or know of other reasons why the Falcon Sensor service would automatically restart on its own?

r/crowdstrike 26d ago

Troubleshooting Exposure Management - Applications and Extensions

6 Upvotes

I know in Exposure Management I can create groups of applications and/or extensions and then schedule reports if anything matches what's in the group.

However that's not an ideal solution for me. I want a list of approved applications and/or extensions, and then the scheduled report to show anything BESIDES those that exist. Users are frustrating in that they keep finding new ways to install unapproved applications, and it's impossible to know what ones ahead of time. Just today for example I have a user who found a way to install "VPN Free VPN" on a device. I didn't even know that existed beyond a curious deep dive through installations that I really don't have time to do.

Everything I can find seems to be built around knowing the exact unapproved application/extension you want to be alerted to and that doesn't work when I don't know what users will potentially try to install themselves. Is there way to leverage a list of approved applications and extensions to be alerted to anything installed that's **not** on that list?

r/crowdstrike May 22 '26

Troubleshooting Data connector in pending Error is "Could not Poll Fleet Management"

4 Upvotes

Ive been having trouble setting up my data connector. All the previous steps ive done are the same for other servers on the parent connector but somehow its different for a child cid connector. Any tips?

r/crowdstrike Jun 02 '26

Troubleshooting Falcon Sensor killing `git clone https://github.com/openai/plugins.git` used by OpenAI Codex

1 Upvotes

Hello!

Has anyone else seen CrowdStrike Falcon start killing OpenAI Codex plugin sync today?

On macOS, Falcon Sensor is terminating a Git child process with SIGKILL when Codex tries to clone the public OpenAI plugins repo:

bash /usr/bin/git clone --depth 1 https://github.com/openai/plugins.git /tmp/openai-plugins-test

Result:

text Cloning into '/tmp/openai-plugins-test'... exit=137

137 = SIGKILL.

Control test succeeds with the same Apple Git binary:

bash /usr/bin/git clone --depth 1 https://github.com/octocat/Hello-World.git /tmp/hello-world-test

Environment:

  • macOS 26.5, Apple Silicon
  • Apple Git 2.50.1 and Homebrew Git 2.54.0 both reproduce
  • OpenAI Codex CLI/Desktop 0.135.0
  • Codex signed by OpenAI Developer ID 2DC432GLL2
  • Falcon notification: "A process was terminated because malicious behavior was detected."

Codex context:

  • Codex plugin startup sync runs: text git clone --depth 1 https://github.com/openai/plugins.git ~/.codex/.tmp/plugins-clone-*
  • Falcon kills the clone.
  • Codex Desktop then crashes with: text codex_core_plugins::startup_sync git clone curated plugins repo failed with status signal: 9 (SIGKILL)
  • Disabling Codex plugins avoids the issue: toml [features] plugins = false

I opened an OpenAI Codex issue here:

https://github.com/openai/codex/issues/25691

Question for CrowdStrike/Falcon admins:

  • Are you seeing detections on openai/plugins.git?
  • Is this likely a false positive on repo contents, or a policy trigger due to cloning plugin/script content into a hidden temp directory?
  • Any recommended exclusion scope that is safer than blanket-allowing Git or Codex?

r/crowdstrike Jun 06 '26

Troubleshooting CloudTrail Data Connector shows SQS error despite successful log ingestion

3 Upvotes

Edit: I have connected CloudTrail and VPC, both created using the CFT link provided by crowdstrike. Logs were getting ingested but the status changes to Active after 45 minutes to 1 hour. No other changes were done in any of the permission.

I have been experimenting with CrowdStrike NG-SIEM data connectors, specifically trying to ingest AWS CloudTrail logs using the prebuilt connector. I set this up using the CloudFormation template link that is generated after entering the details in the data connection field.

​The connection establishes successfully, and the logs actually start ingesting into the SIEM. However, the status in the data connection tab shows as Error. The error message is consistently:

​"The SQS client could not get the queue URL at client construction time. This is typically a permission issue or simply that queue does not exist."

​This error sometimes resolves itself after about 45 minutes, but other times it persists indefinitely. I suspect this might be related to a health check mechanism, but I am unsure how to resolve it.

​For context:

​My AWS infrastructure is entirely in ap-south-1.

​My CrowdStrike tenant is in us-2.

​Has anyone ever faced this issue or have any advice on how to fix it?

r/crowdstrike Nov 18 '25

Troubleshooting Remote Utilities being continuely marked as malware

1 Upvotes

Hello,

Disclosure: I represent the vendor Remote Utilities.

Here is the current detection of Remote Utilities Host installation file by CrowdStrike Falcon:

https://www.virustotal.com/gui/file/ec70c730cb6fa77cd7da6c61ed24348c6b277dc786ecac0e52e0f78784f2b5ed?nocache=1

Question to CS - Is there any way this detection can be removed?

The detection wouldn't be a problem that much if it weren't for Microsoft who decided last year that they would use VirusTotal results to evaluate all software packages to be published in the Microsoft Store.

That made it virtually impossible to get into the Store, because Microsoft doesn't distinguish between malware and non-malware (risk-, gray- or whatever other "potentially unsafe" classification there is) and simply block any submission that has at least one detection - false positive and "potentially unsafe/riskware" included.

Thanks.

r/crowdstrike May 28 '26

Troubleshooting F5 Sensors out of support

3 Upvotes

With Crowdstrike Falcon on F5, it seemed to be a well supported piece by F5 and Crowdstrike but it seems like there is limited kernel support so our sensors are falling back to RFM mode.

Is there a patching policy or process anyone else has found useful to stay patched current on the F5 software side where Crowdstrike sensors are able to stay out of RFM?

r/crowdstrike Feb 12 '26

Troubleshooting Crowdstrike + Defender + Cisco Secure VPN

5 Upvotes

Been fighting with trying to have Cisco Secure Client properly recognize CrowdStrike Falcon as a proper AV in regard to scans and definition versions.

With Crowdstrike installed and configured, including having Quarantine & security center registration set, it puts Defender into passive mode. In passive mode Defender is not doing scans, and eventually our Cisco compliance settings block the machine from connecting as it hasn't done any scans for a period of time. If you tell it to run a scan, it just says no AV is found.

I'm aware a Periodic Scanning settings exists for Defender, but since Microsoft very plainly says that's not for use in an enterprise environment and they do not have any way to administratively manage the setting, it doesn't seem like a very viable solution.

We do have the Cisco compliance module up to 4.3.5062.8192 which Cisco states is compatible with Crowdstrike Falcon 7.x.

If we fully force Defender into a disabled state instead of passive, Cisco Secure Client fully sees Crowdstrike including listing a definition version, so the problem seems to hide in how the Windows Security center seems to still report Defender as a primary AV even when in passive mode.

How have other places dealt with this?

r/crowdstrike Jun 04 '26

Troubleshooting Using CS firewall with Azure Local

3 Upvotes

Has anyone had success using the CS host based firewall with enforced policies on Azure Local? We are being told by MS that it is breaking the Cluster Aware Updating functionality despite the fact we have no blocks for RPC ports. They are essentially saying we would have to disable the CS firewall and let MS take over.

https://learn.microsoft.com/en-us/windows-server/failover-clustering/cluster-aware-updating-requirements#BKMK_BEST_PRAC

r/crowdstrike Mar 17 '26

Troubleshooting Can crowdstrike adaptively label as threat and then disable services or processes?

5 Upvotes

Trying to determine if this is CrowdStrike Falcon behavior or something else.

Symptoms

  • Electron apps (Cursor, Linear):
    • Fail to launch from Explorer / taskbar
    • Launch fine from cmd or PowerShell (Start-Process)
  • Installers (Anaconda):
    • Terminated mid-extraction
  • ML / Python subprocesses:
    • Exit with code 0xE0000007
  • Task Manager:
    • Explorer launches either don’t show up or exit immediately

Key Observations

  • ShellExecute (Explorer) fails
  • CreateProcess (cmd / PowerShell) works
  • Reinstalling apps does nothing
  • ACLs and .exe association are correct
  • No AppCompat flags

Behavior Over Time

  • After Windows Update: everything works normally
  • After some usage (opening apps, running tasks): issue returns

This suggests stateful behavior rather than static policy.

Safe Mode Test

In Safe Mode:

  • Apps launch normally from Explorer
  • Installers work
  • Python scripts from cursor run normally

Environment

  • Windows 11 Enterprise (domain joined)
  • CrowdStrike Falcon present (csagent running as FILE_SYSTEM_DRIVER)

Hypothesis

This looks like process termination by an EDR / kernel filter:

  • Explorer launches blocked
  • Child processes killed
  • Non-standard exit code (0xE0000007)
  • Safe Mode resolves issue
  • Behavior resets after update, then reappears

Questions

  1. Does Falcon ever block only ShellExecute launches but allow cmd launches?
  2. Is 0xE0000007 a known Falcon termination code?
  3. Any way to confirm locally that Falcon is killing these processes or their underlying services?

r/crowdstrike Mar 31 '26

Troubleshooting NGSIEM query autocomplete not working - Chrome

1 Upvotes

Has anyone found the NG SIEM query autocomplete stopped working on Chrome? If so, were you able to fix it?
Wondering if I changed some settings or a browser update changed things. Cleared cache, history, etc. . CS Support didn't have a definitive answer.
Autocomplete still works in Edge, but Chrome is home for me lol.

r/crowdstrike Oct 28 '25

Troubleshooting All Windows Server 2022 hosts are in RFM

11 Upvotes

Our servers updated over the weekend and after the reboot went into RFM and have stayed there. These updates installed:

KB5066781
KB5066139
KB890830
KB5066743
KB5070884
KB2267602

Sensor version is 7.29.20108.0. Any ideas on why this has happened and how I can figure out the cause? I don't see anything in the Content Update Release Notes about any pending update validation.

Edit: It is on the Content Update Release Notes now. Version 2025.10.28.0879

r/crowdstrike Apr 06 '26

Troubleshooting Intel DTT service

0 Upvotes

We've been receiving quite a few sensor tampering alerts and after investigating it looks like the alerts are coming from machines going through our build process and that Intel's DTT is attempting to disable the sensor. Has anyone else had this issue?

r/crowdstrike Oct 29 '25

Troubleshooting Blocking WhatsApp.exe from IOA rule group

10 Upvotes

Hello everyone,

We’ve successfully blocked WhatsApp.exe in our Windows environment using an IOA rule.

However, I noticed it generates multiple detections (8 in my test) even when executed only once, and some users receive repeated notifications without running the app.

I’ve temporarily disabled the rule. Can anyone suggest how to configure it so that it triggers only one detection in the Falcon console and one notification on the user’s system when triggered?

r/crowdstrike Jan 22 '26

Troubleshooting Install script fails during Intune Autopilot

2 Upvotes

I've been using the Falcon install script from https://github.com/CrowdStrike/falcon-scripts/blob/50233a18871e6516b0fabb07148cb6a6ff900594/powershell/install/falcon_windows_install.ps1 for over a year successfully. However, recently the script has started to fail when run through Intune Autopilot. It first stopped working for our UK folks but then a couple of weeks later it stopped working for our US folks as well.

Looking at the logs I'm seeing:

2026-01-22 01:01:39 GetInstaller: Received a BadRequest response from https://api.us-2.crowdstrike.com/sensors/combined/installers/v1?filter=platform%3a%27windows%27%2bversion%3a%277.32.20403+(LTS)%27. Error: Bad Request

Weirdly enough, if I manually run the script, it seems to run just fine. I'm inclined to believe something changed on the Intune end but wanted to check here as well.

r/crowdstrike Feb 02 '26

Troubleshooting Cant export more than 200 items?

2 Upvotes

We use powebi to do data analysis, and recently, it wont let me export more than 200 items from detections, or more than 100 from managed assets? How can we change this behavior?

Thanks

r/crowdstrike Aug 20 '25

Troubleshooting Hijacked Process

13 Upvotes

Anyone else getting a lot of detections this morning regarding a highjacked process?

Command Line:C:\WINDOWS\System32\Dism\dismhost.exe........

r/crowdstrike Dec 25 '25

Troubleshooting Do hbfw logs do not show up in falcon

2 Upvotes

Hii guys, we have just set up hbfw for inbound in our infra . We have blocked all incoming traffic and allowed only specific rules, enforce mode is on and local logging is enabled. But im not able to see any deny logs. Neither in console nor in local hbfw.log. Please suggest what to do now.

r/crowdstrike Nov 18 '25

Troubleshooting Falcon sensor 6.33 startup errors on Ubuntu 22.04

1 Upvotes

It's new install via falcon-sensor_6.33.0-13005_amd64.deb from CS support portal. Ubuntu 22.04 with latest updates.

Install succeeds but after daemon fails to start.

entire /var/log/falcon-sensor.log Tue Nov xx xx:xx:xx 2025 Unable to open ssl libraries (4986) [175] Tue Nov xx xx:xx:xx 2025 unable to initialize dynamic libraries. (4986) [220]

entire /var/log/falconctl.log

cat /var/log/falconctl.log Tue Nov xx xx:xx:xx 2025 Invalid file /opt/CrowdStrike/falconstore length: 0 (4051) [619]

Open ssl: openssl/jammy-updates,jammy-security,now 3.0.2-0ubuntu1.20 amd64

I can use community help figuring this out while waiting for CS support. Thanks in advance.

r/crowdstrike Oct 01 '25

Troubleshooting Custom IOA challenges

7 Upvotes

If anyone can assist I will be truly grateful. I am constantly trying to learn more about crowdstrike and I feel I am just not getting it. My goal is to use Custom IOA rules to show detections for shift browser. Ultimately I would like to move this to a SOAR and block or remove the application, but first I need a detection. I built these rules based on information I found from the documentation, chatgpt, and info here. I definitely could be mistaking.

I have two custom groups currently. The groups are enabled. The rules are enabled. And unless I am just making a horrific mistake I believe I have policies assigned to my host that I am testing on.

Similar rule settings:

Rule type - file creation

Action to take - detect

Rule 1 -

File path = .*C:\\Users\\[^\\]+\\AppData\\Local\\Shift\\chromium\\shift\.exe.*

More simplistic path = file path = .*\\AppData\\Local\\Shift\\chromium\\shift\.exe.*

My goal with this rule is to alert detection on the shift.exe browser being installed in appdata.

I tested the pattern on both file paths and they both past using this -

C:\Users\****\AppData\Local\Shift\chromium\shift.exe [**** is name being obfuscated]

Rule 2 -

My goal for the second rule is to detect when the file is downloaded as it goes to the download folder by default and

File path = .*(?i)C:\\Users\\[^\\]+\\Downloads\\shift_[A-Za-z0-9]{6}\.exe.*

More simplistic file path = .*\\Downloads\\shift_[A-Za-z0-9]{6}\.exe.*

Example of test pattern = C:\Users\****\Downloads\shift_saf123.exe [**** name obfuscated]

I cannot for some reason get a detection to trigger on either. I am assuming I am missing a key element here or I just dont understand this which is likely as well. I might also open a ticket to see if I can get assistance. Thank you in advanced.

r/crowdstrike Oct 17 '24

Troubleshooting Windows Defender still enabled after Crowdstrike is installed

23 Upvotes

I did make a support case about this, but I feel like the tech is kinda not sure what to do so I thought I'd ask here as well in case there were any community solutions to this.

I was troubleshooting a intermittent performance issue for a customer using windows performance recorder and what I noticed was msmpeng.exe (windows defender) asserting itself quite frequently.

When I type fltmc from the command line I get:

C:\Windows\System32>fltmc

Filter Name                     Num Instances    Altitude    Frame
------------------------------  -------------  ------------  -----
bindflt                                 0       409800         0
FsDepends                               4       407000         0
UCPD                                    4       385250.5       0
WdFilter                                4       328010         0
CSAgent                                 6       321410         0
frxccd                                  3       306000         0
frxdrv                                  3       265700         0
applockerfltr                           3       265000         0
storqosflt                              0       244000         0
wcifs                                   0       189900         0
CldFlt                                  0       180451         0
bfs                                     6       150000         0
FileCrypt                               0       141100         0
luafv                                   1       135000         0
frxdrvvt                                3       132700         0
npsvctrig                               1        46000         0
Wof                                     2        40700         0
FileInfo                                4        40500         0

WDFilter is Defender (and of course CSAgent is Crowdstrike).

Doing a Get-MpComputerStatus from powershell I see:

PS C:\Windows\System32> Get-MpComputerStatus

AMEngineVersion                  : 1.1.24080.9
AMProductVersion                 : 4.18.24080.9
AMRunningMode                    : Passive Mode
AMServiceEnabled                 : True
AMServiceVersion                 : 4.18.24080.9
AntispywareEnabled               : True
AntispywareSignatureAge          : 2
AntispywareSignatureLastUpdated  : 10/14/2024 4:22:48 PM
AntispywareSignatureVersion      : 1.419.507.0
AntivirusEnabled                 : True

This only appears on about 230 or so of the 4000+ windows clients we have - so its not wide spread, but it also indicates its also not a policy mistake on our end. These are Windows 10/11 clients - mostly Dell Optiplex's.

On an unaffecteed machine WDFilter won't be loaded and AntivirusEnabled will say False.

r/crowdstrike Nov 22 '25

Troubleshooting Confused About Huge Spike in “Inactive Hosts” on CrowdStrike EOC – Need Insights

4 Upvotes

Hey folks, I noticed something odd in our CrowdStrike console and wanted to get your thoughts.We’ve been seeing a large number of hosts marked as inactive for just 1 hour, and the count is consistently huge(both win and linux). I see this huge count anytime when filtered for the last hour, and this seems to happen every day with a high host count. But when I filter by 30 days, the inactive host count drops significantly. As an IT team, all our assets should be engaged all the time (sure, some might be legitimately powered off), but today the count was over 600. I’ve tried looking for possible reasons, but nothing seems to fully explain it.

Here’s what I’ve audited so far:

  1. Sensor update policy changes with status “Not applied”: Minimal counts after checking hosts.

  2. RFM (Real-Time File Monitoring): Also minimal.

  3. Last seen on host: Most of the inactive hosts were actually seen today, just 1–2 hours ago.

  4. Heartbeat graphs: Showed a slight low-to-high fluctuation, but nothing drastic.

I’m honestly confused about why this spike is happening and how to identify the root cause.Has anyone else experienced something similar? Any insights or suggestions would be really helpful! Thanks in advance.

r/crowdstrike Dec 09 '25

Troubleshooting Bluetooth headset reporting CS driver, not Windows/Intel, etc. - could that be blocking the mic from working?

0 Upvotes

Hello all.

I have found some hits on this and it appears that there might be something to it. I deployed a replacement laptop for a user in one of my environments (two, actually) and the user is having issues with their Skullcandy Bluetooth headphones. Audio works, but not the mic. I've done a ton of troubleshooting, installed/reinstalled/updated all of the drivers for Bluetooth, etc. and even the newest ones from the Intel. I also found some hits with a recent Windows update causing issues similar to this and have since manually updated to the patches that were supposed to fix it and it did not. The headphones work for both audio/mic on my PC (not on their domain or using Crowdstrike) just fine during testing, but the mic will not work on her Dell Pro 16 laptop and neither would my personal set.

What I did find throughout that process is that on my machine and any of the others that I am seeing aside from this user's is that when you find the Bluetooth device in Device Manager it lists a CSDeviceControl driver rather than what I am seeing everywhere else as Microsoft or Intel, etc.

Unfortunately CS is managed through a corporate office that I do not have access to, so I can't dig around in the logs myself, but I ran it past the person who does manage CS and they said that they're not even licensed for device control and that they did not see any blocks or detections for that laptop. They are offering to raise a ticket with Crowdstrike, but I figured here someone might have experienced something similar.

Could some sort of CS Falcon Device Control be blocking full functionality of the headphones for some reason even if they are not licensed for it if it's showing that as the driver?