Skip to content

EDRCheck CrowdStrike Check #2

@pollackb

Description

@pollackb

Hey,
Wanted to let you know that CrowdStrike drivers can sometimes be found in their own directory:
C:\Windows\System32\drivers\CrowdStrike
You might want to add a check for that directory or use the '-Recurse' switch in Get-ChildItem to make sure you are capturing those directories as well (in my instance you need to be in the Administrators group to read what is in that directory so adding '-Recurse' will cause an error for non-admins). Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions