I wanted to summarize my tweets and replies to the Crowdstrike outage for anyone interested
This is the screenshot of a stack trace of the crash being shared on X.
The faulting driver in the stack trace is csagent.sys.
Now, Crowdstrike has got two mini filter drivers registered with Microsoft (for signing and allocation of altitude).
1) csagent.sys - Altitude (321410)
This altitude falls within the range for Anti-Virus filters.
2) im.sys - Altitude (80680)
This altitude falls within the range for access control drivers.
So, it is clear that the driver causing the crash is their AV driver, csagent.sys.
The workaround that CrowdStrike has given is to delete C-00000291*.sys files from the directory:
C:\Windows\System32\Drivers\CrowdStrike\
These files being suggested to be deleted are not driver files (.sys files) but probably some kind of virus definition database files.
The reason they name these files with the .sys extension is possibly to leverage Windows System File Checker tool's ability to restore back deleted system files.
This seems to be a workaround and the actual fix might be done in their driver, csagent.sys and the fix will be rolled out later.
Anyone having access a Falcon endpoint might see a change in the timestamp of the driver csagent.sys when the actual fix rolls out.
@SaitejaChallap1@ayushtweetshere Hi Sai,
Could you tell me what kind of legal entity did you establish (Pvt limited or something else) to get paid from clients outside of India. And how do you take payments from the foreign clients (the platform you use)?
@Toxicity_______ Basic etiquette missing! First ask and only if the owner allows, then park your vehicle inside his property.
Gate locked nahin tha to iska ye matlab nahin hai ki tum gate khol ke apni gaadi park kar lo! Aur jab owner ne object kiya to bahane banane lagi
@SarcasmSevak Here’s to the ones that we got!
Cheers to the wish you were here, but you’re not ’Cause the drinks bring back all the memories Of everything we’ve been through!
@ratnagiri31@nareshbahrain@chiragbarjatya This is what my mom told me as a kid (so take it with a pinch of salt 😉): cockroaches eat it for the sweet, milky taste and die a day or two later. Somehow the dying ones scare off the rest and you won’t see roaches for years. Oddly, not even dead ones.