Crowdstrike release - IOCTLBlockVulnDriver detections are incorrecly validated

Incident Report for Kudelski Security

Resolved

The cause of the incident has been resolved and our services are back to normal.

Few SLA could be breached and that this has an influence in your reports.

We thank you for your understanding.
Posted Oct 18, 2023 - 16:28 UTC

Monitoring

On Oct 17 (07:00 PM - UTC+0), Crowdstrike made a release that generated a sensor logic error caused the Indicator of Attack (IOA) IOCTLBlockVulnDriver to be incorrectly validated.

The cause of the incident has been identified and we have implemented an internal work-around that should resolve most of the service disruption you might be experienced.
Posted Oct 18, 2023 - 16:28 UTC
This incident affected: Security Alert / Event Ingestion Pipeline / Managed System Access.