{"id":583,"date":"2024-07-24T11:22:50","date_gmt":"2024-07-24T16:22:50","guid":{"rendered":"https:\/\/cmitsolutions.com\/austin-tx-1075\/?p=583"},"modified":"2024-08-05T10:08:55","modified_gmt":"2024-08-05T15:08:55","slug":"why-crowdstrike-is-not-a-one-time-thing","status":"publish","type":"post","link":"https:\/\/cmitsolutions.com\/austin-tx-1075\/blog\/why-crowdstrike-is-not-a-one-time-thing\/","title":{"rendered":"Why CrowdStrike is not a onetime thing"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignnone size-medium wp-image-587\" src=\"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/fc6fc7b1-ea1b-42cb-a8d1-cf42c2d45ecd-300x300.jpeg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/fc6fc7b1-ea1b-42cb-a8d1-cf42c2d45ecd-300x300.jpeg 300w, https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/fc6fc7b1-ea1b-42cb-a8d1-cf42c2d45ecd-150x150.jpeg 150w, https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/fc6fc7b1-ea1b-42cb-a8d1-cf42c2d45ecd-768x768.jpeg 768w, https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/fc6fc7b1-ea1b-42cb-a8d1-cf42c2d45ecd.jpeg 1024w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Who hasn\u2019t heard about the recent global outage impacting everyone? Concerns about our digital environment and the impact of a single piece of software are widespread.<\/p>\n<p><strong>Details:<\/strong><\/p>\n<p>Microsoft complied with EU anti-trust rules by allowing other malware tools to be present in their OS kernel. In contrast, Apple avoided this, and it\u2019s likely they\u2019ll face EU scrutiny again. Apple\u2019s approach keeps third-party cybersecurity tools outside the OS kernel, accessing them at the API layer instead.<\/p>\n<p>Microsoft signs the drivers released by CrowdStrike, which are essentially configuration files for updates. This is common practice, with responsibility for driver releases shared between the software vendor and the recipient. Due to the privileged state of CrowdStrike Falcon Sensor (the offending software), it could cause a Blue Screen of Death. Imagine the threat if malware were embedded in the configuration file.<\/p>\n<p>Without changes to this process and CrowdStrike having kernel access like Microsoft\u2019s Defender program, issues during kernel execution will persist.<\/p>\n<p>At CMIT, we are researching various EDR (Endpoint Detection and Response) software options. We will also compare features like ease of rollbacks and fixes.<\/p>\n<p><strong>More to come.<\/strong><\/p>\n<p>For a comprehensive inventory discovery of your endpoints and checks on privileged access, please schedule a 30-minute device assessment. We\u2019ll identify vulnerabilities, solutions, LAN\/WAN integration, and product security.<\/p>\n<p><strong>Incidents will always happen; the key is having a robust incident response plan.<\/strong>\u00a0This plan is crucial for addressing various points of failure and ensuring quick recovery.<\/p>\n<p>Please contact me directly at 512.691.1954 or leave a message with my live reception at 512.520.2766. Email: psingh@cmitsolutions.com.<\/p>\n<p>&nbsp;<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-medium wp-image-586\" src=\"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/85808236-5202-4b54-8fdc-a1f96faa5a5a-300x300.jpeg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/85808236-5202-4b54-8fdc-a1f96faa5a5a-300x300.jpeg 300w, https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/85808236-5202-4b54-8fdc-a1f96faa5a5a-150x150.jpeg 150w, https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/85808236-5202-4b54-8fdc-a1f96faa5a5a-768x768.jpeg 768w, https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-content\/uploads\/sites\/130\/2024\/07\/85808236-5202-4b54-8fdc-a1f96faa5a5a.jpeg 1024w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Who hasn\u2019t heard about the recent global outage impacting everyone? Concerns&#8230;<\/p>\n","protected":false},"author":187,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-583","post","type-post","status-publish","format-standard","hentry","category-local-it"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/posts\/583","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/users\/187"}],"replies":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/comments?post=583"}],"version-history":[{"count":0,"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/posts\/583\/revisions"}],"wp:attachment":[{"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/media?parent=583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/categories?post=583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cmitsolutions.com\/austin-tx-1075\/wp-json\/wp\/v2\/tags?post=583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}