GroovyBagel
GroovyBagel
20mo

Windows - Crowdstrike issue

The file that caused CrowdStrike to alert was

C-00000291-00000032.sys

, which was 42KB of null values.

The replacement file,

C-00000291-00000033.sys

, was 35KB and appeared to be a normal file.

Post image
20mo ago
PerkyWalrus
PerkyWalrus

Explanation please

GroovyBagel
GroovyBagel
20mo

A .sys file that crashed the windows is a raw binary file which has only 0s..!!

PerkyWalrus
PerkyWalrus

These are memory locations not 0s. My question was what are you implying with this?

Discover more
Curated from across