Skip to main content
Logo GMV

Main navigation

  • Sectors
    • Icono espacio
      Space
    • Icono Aeronáutica
      Aeronautics
    • Icono Defensa y Seguridad
      Defense and Security
    • Icono Sistemas Inteligentes de Transporte
      Intelligent Transportation Systems
    • Icono Automoción
      Automotive
    • Icono Ciberseguridad
      Cybersecurity
    • Icono Servicios públicos Digitales
      Digital Public Services
    • Icono Sanidad
      Healthcare
    • Icono Industria
      Industry
    • Icono Financiero
      Financial
    • Icono Industria
      Services
    • All Sectors

    Highlight

    Slopsquatting
    Slopsquatting: A silent threat born from the hallucinations of LLMs
  • Talent
  • About GMV
    • Get to Know the Company
    • History
    • Management Team
    • Certifications
    • Corporate Social Responsibility
  • Communication
    • News
    • Events
    • Blog
    • Magazine GMV News
    • Press Room
    • Media library
    • Latest from GMV

Secondary navigation

  • Products A-Z
  • GMV Global
    • Global (en)
    • Spain and LATAM (es - ca - en)
    • Germany (de - en)
    • Portugal (pt - en)
    • Poland (pl - en)
    • All branches and all GMV sites
  • Home
  • Communication
  • News
Back
New search
Date
  • Cybersecurity

CrowdStrike BSoD, what happened and how can I be prepared?

26/07/2024
  • Print
Share

On July 19th a faulty configuration in CrowdStrike Falcon agent rendered thousands of Windows systems inoperative.

Do you want to know what happened?

And most importantly, do you want to know how you could have recovered easily from it?

Remote recovery

CrowdStrike Falcon

CrowdStrike is a global security leader and the manufacturer of one of the world's best-selling malware protection platforms. Its CrowdStrike Falcon platform is specifically designed to stop security breaches through a unified set of technologies delivered in the cloud known as CrowdStrike Security Cloud service. This platform includes among other modules a next-generation antivirus (NGAV) that features machine learning technology to detect and prevent cyber-attacks. CrowdStrike contains several product modules covering multiple aspects such as threat intelligence, detection, automatic protection and remediation, etc., but for convenience it is deployed on Windows systems via a single agent, known as CrowdStrike Falcon Sensor.

On 19 July 2024 at 04:09 UTC, as part of routine operations, CrowdStrike released a configuration update to CrowdStrike Falcon Sensor for Windows systems. Sensor configuration updates are a part of the Falcon platform's protection mechanisms. This configuration update triggered a logic error that resulted in a system crash and a blue screen (BSoD) on affected Windows systems. 

A preliminary incident report may be found here: Falcon Content Update Preliminary Post Incident Report | CrowdStrike

A detailed discussion can be found here: Windows Security best practices for integrating and managing security tools

BSoD

The term ‘Blue Screen of Death’ or BSoD is a colloquialism that refers to the blue screen that results from a catastrophic failure of the Windows operating system. Such errors can be caused by a variety of hardware and software issues. The blue screen appears when the Windows system needs help in order to recover from an error that it has been unable to recover from on its own. When we see this blue screen, the Windows system is not running, and therefore all the usual means of remote recovery based on Windows applications are useless. Although Microsoft provides instructions on how a user can recover their computer to a state before the failure has occurred, usually in a corporate environment this is the responsibility of the systems department, who must physically access the computer to boot it into safe mode and proceed to diagnose the failure and repair the Windows system. Of course, this is a reasonable procedure only when a single computer or only a few computers have failed simultaneously.

Disaster Recovery

Disaster Recovery refers to the process of recovering from a massive contingency (a disaster), and usually includes protocols for recovering the functionality and data of the affected systems in the shortest possible time. The contingencies contemplated in recovery plans usually include natural elements such as fires or earthquakes, accidental ones such as the loss of power supply, or provoked ones such as cyber-attacks. 

The consequences of the disruption of a company's critical systems may vary depending on a number of factors, but always include financial losses resulting from the total or partial inactivity of the company for a certain period of time and/or the impossibility of recovering business-critical data.

In the case of the situation caused by the CrowdStrike incident, most recovery protocols failed to adequately manage the recovery of thousands of affected Windows systems, because the simultaneous occurrence of these BSoDs is not a common occurrence. Depending on each company's IT architecture, the level of business disruption may have ranged from an inconvenience to a catastrophic event.

The tool that most affected corporations lacked is a platform for remote, massive recovery of Windows computers in BSoD state, such as GMV's resQit solution. This solution is often used as a tool to improve the efficiency of recovering crashed Windows systems by enabling a remote recovery mechanism, which is so important in today's distributed and teleworking environments. However, in the event of a massive incident such as the one that occurred in the CrowdStrike case, this platform can save hundreds of thousands or even millions of euros by enabling a simple, remote recovery scenario for all affected systems in a minimal amount of time, a scenario that would be unfeasible without such a tool.

MORE INFO: resQit Remote Recovery
How to solve Blue Screen of Death (BSoD) with resQit Remote Recovery?
https://www.youtube.com/watch?v=M-MuX0cp2qI
  • Print
Share

Related

Ciberseguridad Andalucía 2025
  • Cybersecurity
GMV analyzes European cyberdefense challenges at the Andalusia Cybersecurity Conference
GMV participa en la Jornada de presentación de la Estrategia de Tecnologías Cuánticas de España 2025-2030
  • Cybersecurity
GMV participates in the presentation of the Quantum Technologies Strategy for Spain 2025-2030
CCI La Voz de la Industria Andalucia
  • Industry
  • Cybersecurity
CCI The Voice of the Industry of Andalusia (Seville)
15 May

9:00 AM - 3:30 PM

Contact

Alameda dos Oceanos, 115
1990-392 Lisbon, Portugal

Tel. +351 308801495
Fax. +351 213866493

Contact menu

  • Contact
  • GMV around the world

Blog

  • Blog

Sectors

Sectors menu

  • Space
  • Aeronautics
  • Defense and Security
  • Intelligent Transportation Systems
  • Automotive
  • Cybersecurity
  • Digital Public Services
  • Healthcare
  • Industry
  • Financial
  • Services
  • Talent
  • About GMV
  • Shortcut to
    • Press Room
    • News
    • Events
    • Blog
    • Products A-Z
© 2025, GMV Innovating Solutions S.L.

Footer menu

  • Contact
  • Legal Notice
  • Privacy Policy
  • Cookie Policy

Footer Info

  • Commitment to the Environment
  • Financial Information