Justin Ward’s Post

View profile for Justin Ward, graphic

Senior Site Reliability Engineer @Radicle Health | Uptime, IaC, Cloud Solutions, Security, DevOps, Network Security

CrowdSrike remediation was to delete all files matching 00000291*.sys by entering windows recovery mode… Because they were all compiled to null values… sigh… 1) How much of CrowdStrike’s software could be disabled by anyone with access to boot time.. 2) Why didn’t those files, compiled to an endless list of nulls catch any eyes?? Software running as the kernel should probably be verified… Make the null pointer dereference something actually malicious and…. Bad things happen.

To view or add a comment, sign in

Explore topics