11 ms·
It's crowdstrike: https://www.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_error_in_latest_crowdstrike_update/ https://www.reddit.com/r/crowdstrike/comments/1
by scriptsmith 2y ago
It's crowdstrike: https://www.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_error_in_latest_crowdstrike_update/ https://www.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_e...
> 7/18/24 10:20PT - Hello everyone - We have widespread reports of BSODs on windows hosts, occurring on multiple sensor versions. Investigating cause. TA will be published shortly. Pinned thread.
> SCOPE: EU-1, US-1, US-2 and US-GOV-1
> Edit 10:36PT - TA posted: https://supportportal.crowdstrike.com/s/article/Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19 https://supportportal.crowdstrike.com/s/article/Tech-Alert-W...
> Edit 11:27 PM PT:
> Workaround Steps:
> Boot Windows into Safe Mode or the Windows Recovery Environment
> Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
> Locate the file matching “C-00000291*.sys”, and delete it.
> Boot the host normally.
- ineptech 2y agoCan you post a summary? We're affected but I don't have access to that portal.
- scriptsmith 2y agoSomeone posted this in the thread, but I also can't log in to verify > Summary > CrowdStrike is aware of reports of crashes on Windows hosts related to the Falcon Sensor. > Details > Symptoms include hosts experiencing a bugcheck\blue screen error related to the Falcon Sensor. > Current Action > Our Engineering teams are actively working to resolve this issue and there is no need to open a support ticket. > Status updates will be posted below as we have more information to share, including when the issue is resolved. > Latest Updates > 2024-07-19 05:30 AM UTC | Tech Alert Published. > Support > Find answers and contact Support with our Support Portal
- nofinator 2y agoThey've bumped this support info to a blog post that's linked from their home page: https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/ https://www.crowdstrike.com/blog/statement-on-falcon-content... It includes PDFs of some relevant support pages that someone printed with their browser 5 hours ago. That's probably the right thing to do in such a situation to get this kind of info publicly available ASAP, but still, oof. Looks like lots of people in the Reddit thread had trouble accessing the support info behind the login screen.
- unixhero 2y ago"Start your free trial now." Hahahahah you have got to ne kidding me :)
- Neil44 2y agoRight after you enter the bit locker recovery key. You do have your bit locker recovery key, right? .....right?
- tamimio 2y agoI doubt most of the clients who use CS know what BitLocker is, let alone how to back it up, assuming it wasn’t backed up automatically by Windows.
- Fire-Dragon-DoL 2y agoDoesn't that get backed up automatically to the Microsoft account?
- tamimio 2y agoI know it does for personal accounts once linked to your machine. Years ago, I used the enterprise version and it didn’t, probably because it was “assumed” that it should be done with group policies, but that was in 2017.
- dist-epoch 2y agoThat's opt-in. In Enterprise setups the key should be backed somewhere in Active Directory.
- mrhhaacckk 2y agoYes you should be able to pull it from your domain controllers. Unless they're also down, which they're likely to be seeing as Tier 0 assets are most likely to have crowdstrike on them. So you're now in a catch 22.
- mavhc 2y agoLog into hypervisor, rollback VM
- templ2 2y ago[dead]
- sva_ 2y agoHappy weekend to everyone who works there.
- deleted 2y ago[deleted]
- 2OEH8eoCRo0 2y agoThey had me at "crowdstrike engineering" So engineer-like.