CrowdStrike¤Ï7·î19Æü(Êƹñ»þ´Ö)¡¢¡ÖStatement on Falcon Content Update for Windows Hosts - crowdstrike.com¡×¤Ë¤ª¤¤¤Æ¡¢Windows¥Û¥¹¥È¸þ¤±¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤ËÉÔ¶ñ¹ç¤¢¤ê¡¢±Æ¶Á¤ò¼õ¤±¤¿Windows¤Ç¥¯¥é¥Ã¥·¥å¤¬È¯À¸¤¹¤ë¤³¤È¤òÌÀ¤é¤«¤Ë¤·¤¿¡£Æ±¼Ò¤Ï»öÂ֤νÅÂ礵¤òÍý²ò¤·¤Æ¤¤¤ë¤ÈÀâÌÀ¤·¡¢ÉÔÊؤÈÌÂÏǤò¤«¤±¤¿¤³¤È¤ò¿¼¤¯¼Õºá¤·¤Æ¤¤¤ë¡£

Statement on Falcon Content Update for Windows Hosts - crowdstrike.com

¡ûÀ¤³¦Ãæ¤ÇWindows¤¬¥¯¥é¥Ã¥·¥å

CrowdStrike¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤òŬÍѤ·¤¿¤Î¤Á¡¢Windows¤¬¥Ö¥ë¡¼¥¹¥¯¥ê¡¼¥ó(BSoD: Blue Screen of Death)¤Ë¤Ê¤êÍøÍѤǤ­¤Ê¤¤¾õ¶·¤Ë¤Ê¤ë¤È¤¤¤¦È¯É½¤¬Á꼡¤¤¤À¡£CrowdStrike¤Ï¥¢¥Ã¥×¥Ç¡¼¥È¤Î°ìÉô¤Ë·ç´Ù¤¬¤¢¤ê¡¢±Æ¶Á¤ò¼õ¤±¤¿Windows¤Ç¥¯¥é¥Ã¥·¥å¤¬È¯À¸¤¹¤ë¤³¤È¤òǧ¤á¤ëȯɽ¤ò¹Ô¤Ã¤¿¡£

CrowdStrike¤Ï¾õ¶·¤Î¾ÜºÙ¤È¤·¤Æ¡¢°Ê²¼¤òÅÁ¤¨¤Æ¤¤¤ë¡£

Falcon¥»¥ó¥µ¡¼¤Ë·ç´Ù¤¬¤¢¤ê¥·¥ã¥Ã¥È¥À¥¦¥ó(¥Ö¥ë¡¼¥¹¥¯¥ê¡¼¥ó)¤¬È¯À¸¤¹¤ë¥Û¥¹¥È¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë

±Æ¶Á¤ò¼õ¤±¤Æ¤¤¤Ê¤¤Windows¤Ë¤ª¤¤¤Æ¤Ï¡¢ÌäÂê¤Î¤¢¤ë¥Õ¥¡¥¤¥ë¤¬¸µ¤ËÌᤵ¤ì¤Æ¤¤¤ë¤¿¤á¤¹¤Ç¤Ë¥¢¥¯¥·¥ç¥ó¤ÏɬÍפʤ¤

0527 UTC°Ê¹ß¤Ë¥ª¥ó¥é¥¤¥ó¤Ë¤Ê¤Ã¤¿Windows¥Û¥¹¥È¤Ï±Æ¶Á¤ò¼õ¤±¤Ê¤¤

¤³¤ÎÌäÂê¤ÏMac¤Þ¤¿¤ÏLinux¥Ù¡¼¥¹¤Î¥Û¥¹¥È¤Ë¤Ï±Æ¶Á¤·¤Ê¤¤

¥¿¥¤¥à¥¹¥¿¥ó¥×¤¬0409 UTC¤Î¥Õ¥¡¥¤¥ë¡ÖC-00000291*.sys¡×¤¬ÌäÂê¤Î¤¢¤ë¥Ð¡¼¥¸¥ç¥ó¤Ç¤¢¤ë

¥¿¥¤¥à¥¹¥¿¥ó¥×¤¬0527 UTC°Ê¹ß¤Î¥Õ¥¡¥¤¥ë¡ÖC-00000291*.sys¡×¤¬¸µ¤ËÌᤵ¤ì¤¿Àµ¾ï¤Ê¥Ð¡¼¥¸¥ç¥ó¤Ç¤¢¤ë

¡û±Æ¶Á¤ò¼õ¤±¤ëWindows¤«¤É¤¦¤«Ä´¤Ù¤ëÊýË¡

CrowdStrike¤Ï±Æ¶Á¤ò¼õ¤±¤ëWindows¤«¤É¤¦¤«Ä´¤Ù¤ëÊýË¡¤È¤·¤Æ¡¢¼¡¤Î¥É¥­¥å¥á¥ó¥È¤ò³Îǧ¤¹¤ë¤³¤È¤òµá¤á¤Æ¤¤¤ë¡£

How to identify hosts possibly impacted by Windows crashes

¤Þ¤¿¤Ï¡Ö¥µ¥Ý¡¼¥È¡¦¥Ý¡¼¥¿¥ë¡×¤Ë¥í¥°¥¤¥ó¤¹¤ë¤è¤¦µá¤á¤Æ¤¤¤ë¡£

¡û¥¯¥é¥Ã¥·¥å¤·¤Æ¤¤¤ëWindows¤Ë¤ª¤±¤ë²óÈòÊýË¡

¥¯¥é¥Ã¥·¥å¤·¤Æ¤¤¤ëWindows¤Î²ò·èºö¤È¤·¤Æ¡¢CrowdStrike¤ÏWindows¤òºÆµ¯Æ°¤·¤ÆÀµ¾ï¤Ë¤Ê¤Ã¤¿¥Õ¥¡¥¤¥ë¤ò¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¤³¤È¤òµá¤á¤Æ¤¤¤ë¡£Windows¤¬ºÆÅÙ¥¯¥é¥Ã¥·¥å¤¹¤ë¾ì¹ç¤Ï¡¢¼¡¤Î¼ê½ç¤ÇÁàºî¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£

Windows¤ò¥»¡¼¥Õ¥â¡¼¥É¤Þ¤¿¤ÏWindows²óÉü´Ä¶­¤Çµ¯Æ°¤¹¤ë¡£¤³¤ÎºÝ¡¢ÌµÀþLAN¤Ç¤Ï¤Ê¤¯Í­ÀþLAN¤ò»È¤¦¤³¤È¤¬¿ä¾©¤µ¤ì¤ë

%WINDIR%\System32\drivers\CrowdStrike¥Ç¥£¥ì¥¯¥È¥ê¤Ë°ÜÆ°¤¹¤ë¡£WinRE/WinPE¤Ç¤ÏOS¥Ü¥ê¥å¡¼¥à¤ÎWindows\System32\drivers\CrowdStrike¥Ç¥£¥ì¥¯¥È¥ê¤Ë°ÜÆ°¤¹¤ë

¡ÖC-00000291*.sys¡×¤Ë°ìÃפ¹¤ë¥Õ¥¡¥¤¥ë¤ò¸«¤Ä¤±¤Æºï½ü¤¹¤ë

¥Û¥¹¥È¤òÄ̾ï¤É¤ª¤êµ¯Æ°¤¹¤ë

¤Ê¤ª¡¢BitLocker¤Ç°Å¹æ²½¤µ¤ì¤¿¥Û¥¹¥È¤Ç¤Ï¡¢²óÉü¥­¡¼¤¬É¬Íפˤʤë¾ì¹ç¤¬¤¢¤ë¤È¤¤¤¦¡£

¥Ñ¥Ö¥ê¥Ã¥¯¥¯¥é¥¦¥É¤Þ¤¿¤Ï²¾Á۴Ķ­¤ò´Þ¤àƱÍͤδĶ­¤Ë¤ª¤±¤ë²óÈòÊýË¡¤È¤·¤Æ¤Ï¡¢¼¡¤Î¼ê½ç¤¬¼¨¤µ¤ì¤Æ¤¤¤ë¡£

±Æ¶Á¤ò¼õ¤±¤ë²¾ÁÛ¥µ¡¼¥Ð¡¼¤«¤é¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¥·¥¹¥Æ¥à¤Î¥Ç¥£¥¹¥¯¥Ü¥ê¥å¡¼¥à¤òÀÚ¤êÎ¥¤¹

°ÂÁ´ºö¤È¤·¤Æ¥Ç¥£¥¹¥¯¥Ü¥ê¥å¡¼¥à¤Î¥¹¥Ê¥Ã¥×¥·¥ç¥Ã¥È¤Þ¤¿¤Ï¥Ð¥Ã¥¯¥¢¥Ã¥×¤òºîÀ®¤¹¤ë

¥Ü¥ê¥å¡¼¥à¤ò¿·¤·¤¤²¾ÁÛ¥µ¡¼¥Ð¤ËÀܳ¡¦¥Þ¥¦¥ó¥È¤¹¤ë

%WINDIR%\System32\drivers\CrowdStrike¥Ç¥£¥ì¥¯¥È¥ê¤Ë°ÜÆ°¤¹¤ë

¡ÖC-00000291*.sys¡×¤Ë°ìÃפ¹¤ë¥Õ¥¡¥¤¥ë¤ò¸«¤Ä¤±¤Æºï½ü¤¹¤ë

¿·¤·¤¤²¾ÁÛ¥µ¡¼¥Ð¤«¤é¥Ü¥ê¥å¡¼¥à¤òÀÚ¤êÎ¥¤¹

±Æ¶Á¤ò¼õ¤±¤¿²¾ÁÛ¥µ¡¼¥Ð¤Ë¸ÇÄê¥Ü¥ê¥å¡¼¥à¤òºÆÀܳ¤¹¤ë

¤Þ¤¿¡¢¤¹¤Ç¤Ë¥¹¥Ê¥Ã¥×¥·¥ç¥Ã¥È¤¬ºîÀ®¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ï¡¢0409 UTC¤è¤êÁ°¤Î¥¹¥Ê¥Ã¥×¥·¥ç¥Ã¥È¤Ë¥í¡¼¥ë¥Ð¥Ã¥¯¤¹¤ëÊýË¡¤â¤¢¤ë¤È¤µ¤ì¤Æ¤¤¤ë¡£

¡ûAWS¤Þ¤¿¤ÏAzure¤ò»È¤Ã¤Æ¤¤¤ë¾ì¹ç

Amazon Web Services (AWS)¤ª¤è¤ÓMicrosoft¤Ï¡¢°ìÏ¢¤ÎÌäÂê¤ËÂФ·¤Æ¡¢¼¡¤Î¥É¥­¥å¥á¥ó¥È¤ò¸ø³«¤·¤ÆÂнèÊýË¡¤òÅÁ¤¨¤Æ¤¤¤ë¡£

Recover AWS resources affected by the CrowdStrike Falcon agent | AWS re:Post

Azure status

¤³¤ÎÌäÂê¤Ï¡¢¤µ¤Þ¤¶¤Þ¤Ê¥Ù¥ó¥À¡¼¤¬¼«¼ÒÀ½Éʤ˴ØÏ¢¤¹¤ë´ÑÅÀ¤«¤é¾ðÊó¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢¤½¤ì¤¾¤ì¤Î¾ðÊó¤òŬÀÚ¤ËÍý²ò¤·Âбþ¤¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£

¡û¥µ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£¹¶·â¤Ç¤Ï¤Ê¤¤

CrowdStrike¤Ï¤³¤ÎÌäÂê¤ò¥¢¥Ã¥×¥Ç¡¼¥È¤ËÉÔ¶ñ¹ç¤¬´Þ¤Þ¤ì¤Æ¤¤¤¿¤³¤È¤¬¸¶°ø¤Ç¤¢¤ê¡¢Æ±¼Ò¤ËÂФ¹¤ë¥µ¥¤¥Ð¡¼¹¶·â¤¬¸¶°ø¤Ç¤Ï¤Ê¤¤¤ÈÀâÌÀ¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢±Æ¶Á¤ò¼õ¤±¤ë¤Î¤ÏWindows¤Ç¤¢¤êMac¤äLinux¤Ï±Æ¶Á¤ò¼õ¤±¤Ê¤¤¤È¤âÀâÌÀ¤·¤Æ¤¤¤ë¡£

¤³¤ÎÌäÂê¤ÏÀ¤³¦Ãæ¤ÇWindows¤Î¥¯¥é¥Ã¥·¥å¤ò°ú¤­µ¯¤³¤·¤Æ¤ª¤ê¡¢ÆüËܤˤª¤¤¤Æ¤âÌäÂ꤬ȯÀ¸¤·¤Æ¤¤¤ë¡£CrowdStrike¤òÍøÍѤ·¤Æ¤ª¤ê¡¢CrowdStrike¤Î¥¢¥Ã¥×¥Ç¡¼¥È¸å¤Ë¥Ö¥ë¡¼¥¹¥¯¥ê¡¼¥ó¤¬È¯À¸¤¹¤ë¤è¤¦¤Ë¤Ê¤Ã¤¿¾ì¹ç¤Ï¡¢¤³¤ÎÌäÂê¤Î±Æ¶Á¤ò¼õ¤±¤ë²ÄǽÀ­¤¬¤¢¤ë¡£CrowdStrike¤ÎÄ󶡤¹¤ë¾ðÊó¤ò³Îǧ¤¹¤ë¤È¤È¤â¤Ë¡¢Ä󼨤µ¤ì¤Æ¤¤¤ë²óÈòÊýË¡¤Ê¤É¤òŬÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤ë¡£