{"id":38959,"date":"2024-07-26T15:37:44","date_gmt":"2024-07-26T14:37:44","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=38959"},"modified":"2024-07-26T15:45:31","modified_gmt":"2024-07-26T14:45:31","slug":"crowdstrike-releases-preliminary-post-incident-review-into-global-microsoft-outage","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2024\/07\/26\/crowdstrike-releases-preliminary-post-incident-review-into-global-microsoft-outage\/","title":{"rendered":"CrowdStrike releases preliminary Post Incident Review into global Microsoft outage"},"content":{"rendered":"\n<p><em>Review identifies a defect in the Rapid Response Content that went undetected during validation checks.<\/em><\/p>\n\n\n\n<p>A preliminary Post Incident Review (PIR) by CrowdStrike into the global Microsoft outage has identified a defect in the Rapid Response Content &#8211; which went undetected during validation checks \u2013 as the cause.<\/p>\n\n\n\n<p>CrowdStrike is now adopting enhanced software testing procedures and independent reviews of end-to-end quality processes from development through deployment to prevent such an outage happening again.<\/p>\n\n\n\n<p>Other initiatives identified in the PIR include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Improved Rapid Response Content testing<\/li>\n\n\n\n<li>Introduction of additional validation checks in the Content Validator<\/li>\n\n\n\n<li>Enhanced Resilience and Recoverability<\/li>\n\n\n\n<li>Strengthening error handling mechanisms in the Falcon sensor<\/li>\n\n\n\n<li>Adoption of a staggered deployment strategy<\/li>\n\n\n\n<li>Enhanced monitoring of sensor and system performance during the staggered content deployment<\/li>\n\n\n\n<li>Providing customers with greater control over the delivery of Rapid Response Content updates<\/li>\n\n\n\n<li>Providing notifications of content updates and timing<\/li>\n\n\n\n<li>Conducting multiple independent third-party security code reviews<\/li>\n<\/ul>\n\n\n\n<p>According to the PIR, a content configuration update impacted the Falcon Sensor and the Windows Operating System (BSOD)<\/p>\n\n\n\n<p>\u201cBy regularly updating, security products can quickly adapt to emerging threats, ensuring robust protection for users and their systems,\u201d the report says.<\/p>\n\n\n\n<p>Outlining the sequence of events, the PIR confirms that on July 19, 2024, at 04:09 UTC, a Rapid Response Content update for the Falcon Sensor was published to Windows hosts running sensor version 7.11 and above.<\/p>\n\n\n\n<p>Such updates are a regular part of the dynamic protection mechanisms of the Falcon platform.<\/p>\n\n\n\n<p>On July 19, the update was to gather telemetry on new threat techniques observed by CrowdStrike, but triggered crashes (BSOD) on systems that were online between 04:09 and 05:27 UTC.<\/p>\n\n\n\n<p>The problematic Rapid Response Content configuration update resulted in a Windows system crash.<\/p>\n\n\n\n<p>Mac and Linux hosts were not impacted. Windows hosts that were not online, or did not connect during this period, were not impacted.<\/p>\n\n\n\n<p>The PIR confirms the crashes as due to a defect in the Rapid Response Content, which went undetected during validation checks. When the content was loaded by the Falcon Sensor, this caused an out-of- bounds memory read &#8211; leading to Windows crashes.<\/p>\n\n\n\n<p>George Kurtz<strong>, <\/strong>CrowdStrike Founder and CEO, again offered apologies for the outage saying all of CrowdStrike understood the gravity and impact of the situation.<\/p>\n\n\n\n<p>\u201cWe quickly identified the issue and deployed a fix, allowing us to focus diligently on restoring customer systems as our highest priority.\u201d<\/p>\n\n\n\n<p>CrowdStrike, said Kurtz, was operating normally and the issue does not affect the Falcon platform systems.<\/p>\n\n\n\n<p>Nor, he said, is there impact to any protection if the Falcon Sensor is installed with Falcon Complete and Falcon OverWatch services not disrupted.<\/p>\n\n\n\n<p>\u201cWe are working closely with impacted customers and partners to ensure that all systems are restored,&#8221; Kurtz said.<\/p>\n\n\n\n<p>Warnings against \u2018bad actors\u2019 exploiting the outage remain in place.<\/p>\n\n\n\n<p><br><br><p class=\"MsoNormal\"><\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Review identifies a defect in the Rapid Response Content that went undetected during validation checks. A preliminary Post Incident Review (PIR) by CrowdStrike into the global Microsoft outage has identified a defect in the Rapid Response Content &#8211; which went undetected during validation checks \u2013 as the cause. CrowdStrike is now adopting enhanced software testing [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":38960,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4982,1693,3488,17,4981,4934,1034,43],"tags":[338,121,361,6754],"class_list":["post-38959","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-africa","category-apac","category-cybersecurity","category-enterprise-security","category-europe","category-middle-east","category-north-america","category-top-stories","tag-crowdstrike","tag-cybersecurity","tag-microsoft","tag-systems-crash"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/38959","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=38959"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/38959\/revisions"}],"predecessor-version":[{"id":38965,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/38959\/revisions\/38965"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/38960"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=38959"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=38959"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=38959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}