Settings

Theme

CrowdStrike Incident Analysis

twitter.com

19 points by daenney a year ago · 6 comments

Reader

vr-wannabe a year ago

Neither Tavis Ormanady's, Patrick's or the C++ professional's posts go into detail of how the bug works in CrowdStrike's Falcon sensor. All of it just pointing to a debugger/disassembly output and casting some predictions. (for me personally I trust Tavis' analysis because ... well its his field of specialty over the last decade or so).

But still, none of the tweets mentioned come close to even explaining the issue (as in why the .sys channel update file being filled with zeros leading the CS driver to actually crash, the actual bug in the driver and what how it would've functioned normally before the faulty .sys file was pushed).

for reference, to see the whole tweet without twitter account:

https://twitter-thread.com/t/1814762302337654829

  • notepad0x90 a year ago

    it isn't filled with zeroes, why are people saying that?

    • nubinetwork a year ago

      Some people on twitter and mastodon were saying that, but they also said the file's contents weren't identical across machines... chances are the zeroed-out files were preallocated and not written to because the system crashed.

      • kchr a year ago

        Some comments theorise that the NUL-file was deployed to fix the issue with the corrupt file that caused the crashes.

irundebian a year ago

I don't like his style of communication.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection