CrowdStrike BSOD incident and how Wazuh avoids similar risks
![Post icon](https://wazuh.com/uploads/2024/07/crowdstrike-bsod-incident-logo.webp)
Recently, CrowdStrike, a prominent XDR (Extended Detection and Response) provider, encountered a significant technical issue that affected numerous organizations. This article examines the CrowdStrike incident and details how the architecture of Wazuh avoids similar risks.
On July 18, 2024, a Blue Screen of Death (BSOD) issue associated with CrowdStrike’s Falcon sensor update caused widespread disruptions to its users. The BSOD is a critical system error in Windows operating systems that forces a restart, often leading to data loss and operational downtime. In this case, the usual restart did not resolve the problem, leaving systems in a continuous crash loop. The error impacted hundreds of thousands of devices globally, affecting sectors such as healthcare, banking, transportation, and government services. Organizations relying on CrowdStrike for endpoint protection experienced system crashes, leading to significant operational disruptions.
This issue is not the first for CrowdStrike; a similar BSOD problem occurred in July 2023 with their Falcon sensor version 6.58.
CrowdStrike has acknowledged the issue and is actively working on a resolution. They have identified the problem with their Falcon sensor and have provided interim solutions, such as booting in Safe Mode to delete or rename the problematic driver file and modifying the registry to prevent the faulty service from starting automatically. Full recovery efforts are ongoing, with patches and updates being developed and deployed to affected systems.
Unlike CrowdStrike, Wazuh is designed to operate primarily in the user space, eliminating the risk of failures like BSODs. Here are the key aspects of the approach Wazuh uses:
Operating in the user space offers several benefits:
Being an open source platform, Wazuh offers additional advantages that help mitigate issues similar to the CrowdStrike BSOD incident:
The recent CrowdStrike BSOD incident highlights the risks of kernel drivers in security software. The architecture of Wazuh emphasizes on user space operations and standard kernel APIs, providing a safer and more reliable alternative. This approach provides security monitoring and threat protection without compromising system stability. Additionally, the open source nature of Wazuh fosters transparency, community collaboration, and flexibility, further enhancing its reliability and security.