How and why of 19 July ’ s global IT outage
Security vendor CrowdStrike has shared details on how its content configuration update impacted its Falcon Sensor and the Windows Operating System resulting in a Blue Screen crash . Executives from Acronis , BeyondTrust , Coveware by Veeam , Dynatrace , Endava , Gartner , Gigamon , Kaseya , NETSCOUT , Ombori , Positive Technologies , SandboxAQ , Semperis , SolarWinds , Strategy , Veeam , Zeus Cloud , share their post event comments and recommendations .
According to CrowdStrike ’ s preliminary Post Incident Review , on Friday , July 19 , 2024 at 04:09 UTC , as part of regular operations , CrowdStrike released a content configuration update for the Windows sensor to gather telemetry on possible novel threat techniques .
These updates are a regular part of the dynamic protection mechanisms of the Falcon platform . The problematic Rapid Response Content configuration update resulted in a Windows system crash with BSOD .
Microsoft first introduced BSOD or Blue Screen Of Death , to users of Windows 3.0 way back in 1993 . Blue screen of death is formally known as stop error and it is a critical error that has caused the Windows Operating System to crash .
Systems in scope include Windows hosts running sensor version 7.11 and above that were online between Friday , July 19 , 2024 04:09 UTC and Friday , July 19 , 2024 05:27 UTC and received the update . With this update Mac and Linux hosts were not impacted .
The defect in the content update was reverted on Friday , July 19 , 2024 at 05:27 UTC . Systems coming online after this time , or that did not connect during the window , were not impacted .
CrowdStrike delivers security content configuration updates to its sensors in two ways . Sensor Content that is shipped with CrowdStrike sensor directly , and Rapid Response Content that is designed to
The channel file responsible for system crashes on Friday , July 19 , 2024 beginning at 04:09 UTC was identified and deprecated on operational systems .
40 www . intelligenttechchannels . com