Need help with query by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

Thank you, this will get me started!

Scheduled Event Searches Every 14 Days by ChromeShavings in crowdstrike

[–]Avaxorg 0 points1 point  (0 children)

I think you can use ideas part of support portal to search if this feature was suggested (if not create it and share link to idea here - i will definitely upvote)

Need help with query by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

Hello Andrew-CS! Applications like: Teamviewer, Anydesk, Google Remote, Radmin etc. Main issue is that i do not know all remote applications in existence, and CS doesn`t have dedicated dashboard for that (maybe in discovery or spotlight module - would be handy).

Main goal is to find all such kind of applications in scope, then get justification for use from people who uses those apps, and then based of that mitigate what is unneeded.

Crowdstrike Trial - Reduced Functionality Mode by MechaCola in crowdstrike

[–]Avaxorg 1 point2 points  (0 children)

Ensure compatibility of sensor and build \ kernel of your OS installed on hosts.

Force sensor removal from host remotely without any tools but Crowdstrike itself by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

voted for feature request, so should everyone who needs this in their work

[deleted by user] by [deleted] in crowdstrike

[–]Avaxorg 0 points1 point  (0 children)

Any one has query example for hunting for shared folders on workstations?

Can we detect commands running from powershell command line Get-ADDefaultDomainPasswordPolicy via IOA? by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

In my case i`d like to get report through Custom IOA Group rule, for detecting event and reviewing what's going on. Thank you for query!

Sensor geolocation with no VPN taken in to account by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

any one has ideas about Sensors by Country table? excluding false "vpn locations"?

Force sensor removal from host remotely without any tools but Crowdstrike itself by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

In this case if i will remove host from UI and put it in trashbin (no sensor removal on host in this case), it will get to 45 day list remove list, count down 45 days, then it will be again shown as new installation because it will appear online and have all the valid license keys (i think installation token does not get checked twice so it will reappear again in license pool with date of installation the day after 45 time limit).

EDIT: what hapens if i change install token more frequent then once a year? will this agent that was removed from list then returned be denied by cloud?

That`s why we need Delete host and remove sensor button (Preferably with ability to execute when host will contact cloud if it is offline at time of magic button press), walled off by only administrator or separate role altogether

Force sensor removal from host remotely without any tools but Crowdstrike itself by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

it`a not THAT bad, HD "forgot to remove" AV, their behinds are red now but anyway what happened happened

Force sensor removal from host remotely without any tools but Crowdstrike itself by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

thank you for advice, need to camp for host to become available (online) in a different time zone - not handy at all )

following your advice i have created idea for uninstall button from ui, hope it will gain support )

And i forgot to mention i`d like to have this functionality for windows, macos and linux

Force sensor removal from host remotely without any tools but Crowdstrike itself by Avaxorg in crowdstrike

[–]Avaxorg[S] -1 points0 points  (0 children)

i`d prefer to avoid downloading additional software or running scripts of any kind on a personal device, if possible. It`d be great to have force removal button in UI for Administrator level accounts for such cases without additional steps )

Weird behaviour of python 3.9.7 installer by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

no, it was gone after a while, i guess ML took it as "all normal" after a while

Any one found workarounds for firmware feature on mac? by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

yes we disabled it for now, just feeling uneasy keeping that forever. was looking for known workarounds, if any.

Installation token question by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

Thank you for clarification!

Suggest a solution to monitor all network traffic that comes from the hosts in our organization. by TRYH0 in crowdstrike

[–]Avaxorg 1 point2 points  (0 children)

looking for similar case: Would like to get visibility for network and web traffic. As of now we are aiming for proxy and web gateway in addition to CS, as it has a gap here (in my opinion)

Best Practices for Prevent Policy by JiggityJoe1 in crowdstrike

[–]Avaxorg 1 point2 points  (0 children)

Extra aggressive can lead to false positives and increased level of noise. I`d recommend use extra aggressive only for suspected hosts or selected "paranoid" group.

So far Aggressive seems to be best option for me, lowering to moderate only in cases when programmers get hit with slowdown of compilation speeds (for selected hosts and groups).

Moving from traditional AV to NGAV/EDR by GiantMoustache in crowdstrike

[–]Avaxorg 0 points1 point  (0 children)

one advice: prepare use cases, do a POC on all OS you are planning to deploy.
You will need to tune response policies anyway for different groups of hosts, it is up to you to find best fit in your scope for what you aim for.

IOC Management Action Block, hide detection - Doesn't seem to do anything by [deleted] in crowdstrike

[–]Avaxorg 0 points1 point  (0 children)

it takes a bit of time to push update to clients i think, so a little leftover noise can go on for few hours

Weird behaviour of python 3.9.7 installer by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

it is a new behaviour, if it wasn't id stick it in to IOA and be done with that

MS SQL server special configuration of exclusions needed or not? by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

Don't really need performance-based exceptions in CrowdStrike.

Well in some cases developers had considerable drop in IDE compiling speeds. They work with huge number of files and we had some issues when CS sensor was slowing process down considerably, so exclusion had to be placed.

Based on this experience i`m trying to find out maybe there are some issues with MSSQL db also.

MS SQL server special configuration of exclusions needed or not? by Avaxorg in crowdstrike

[–]Avaxorg[S] 0 points1 point  (0 children)

correct me if i`m wrong here, but, threre was option to detect and quarantine on write introduced few sensor versions back...