-
- Novice
- Posts: 8
- Liked: never
- Joined: Feb 14, 2022 4:03 pm
- Full Name: Zachary Lee
- Contact:
Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hello everyone,
I would like to create an antivirus XML configuration file for our company's antivirus program, CrowdStrike Falcon Sensor. I notice that in the Veeam help center, the default configuration file "only" has configurations for Symantec Protection Engine, ESET, Windows Defender, and Kaspersky Security 10. https://helpcenter.veeam.com/docs/backu ... ml?ver=110
We want this so that we can enable the antivirus scan option within our SureBackup jobs.
I approached our IT SecOps team, who then approached our third-party security provider, who then in turn approached CrowdStrike with the request. It turns out that CrowdStrike has not yet supported this/does not know of the solution for any customer.
I opened a Veeam case (05273309) and the support agent informed me that Veeam does not create custom scripts of configuration files. But he suggested that I open a case here on the Veeam forums to see if other users have faced the same thing and have a solution.
Does anyone have experience with creating the antivirus XML configuration file for a non-default antivirus program such as CrowdStrike?
I would like to create an antivirus XML configuration file for our company's antivirus program, CrowdStrike Falcon Sensor. I notice that in the Veeam help center, the default configuration file "only" has configurations for Symantec Protection Engine, ESET, Windows Defender, and Kaspersky Security 10. https://helpcenter.veeam.com/docs/backu ... ml?ver=110
We want this so that we can enable the antivirus scan option within our SureBackup jobs.
I approached our IT SecOps team, who then approached our third-party security provider, who then in turn approached CrowdStrike with the request. It turns out that CrowdStrike has not yet supported this/does not know of the solution for any customer.
I opened a Veeam case (05273309) and the support agent informed me that Veeam does not create custom scripts of configuration files. But he suggested that I open a case here on the Veeam forums to see if other users have faced the same thing and have a solution.
Does anyone have experience with creating the antivirus XML configuration file for a non-default antivirus program such as CrowdStrike?
-
- VP, Product Management
- Posts: 7081
- Liked: 1511 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
When the vendor support a command line interface for scanning of files and gives back feedback on this, then it is not complicate to write this. It is usually a one liner for the command and some configuration + text for the UI when virus or no virus found.
https://helpcenter.veeam.com/docs/backu ... ml?ver=110
If CrowdStrike is interested to help you with this, let me know here and we can chat about the right contact details. There is even an option to integrate them in one of the next versions if they are willing to help with this.
https://helpcenter.veeam.com/docs/backu ... ml?ver=110
If CrowdStrike is interested to help you with this, let me know here and we can chat about the right contact details. There is even an option to integrate them in one of the next versions if they are willing to help with this.
-
- Novice
- Posts: 8
- Liked: never
- Joined: Feb 14, 2022 4:03 pm
- Full Name: Zachary Lee
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hi Andreas,
Many thanks for your fast response.
I have emailed our IT SecOps team with this information for them to relay to CrowdStrike. Unfortunately in the position I am in, I need to go through them, they need to go through our 3rd-party who then goes to CrowdStrike. In case this thread becomes inactive/disabled before they respond, is there a support engineer that I would be able to email once I get someone from CrowdStrike lined up after working with our internal security guys?
Many thanks for your fast response.
I have emailed our IT SecOps team with this information for them to relay to CrowdStrike. Unfortunately in the position I am in, I need to go through them, they need to go through our 3rd-party who then goes to CrowdStrike. In case this thread becomes inactive/disabled before they respond, is there a support engineer that I would be able to email once I get someone from CrowdStrike lined up after working with our internal security guys?
-
- VP, Product Management
- Posts: 7081
- Liked: 1511 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Just PN me here in the forum.
-
- Novice
- Posts: 8
- Liked: never
- Joined: Feb 14, 2022 4:03 pm
- Full Name: Zachary Lee
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Per CrowdStrike support:
"The EDR (Endpoint Detection and Response) solution from CrowdStrike does not work like traditional AV solutions.
Traditional AV products hook the file system via low-level drivers in order to enable the on-access scanning (OAS) of files written to and/or read from storage - interrupting those same writes as part of the process - hence the concern about file contention with other applications and potential data corruption, and thus the need for scanning exclusions in such products.
CrowdStrike on the other hand doesn’t scan files at rest. Instead it looks at executing processes for malicious activities.
"
Our company will be trying to integrate Windows Defender in conjunction with CrowdStrike as the next measure for trying to implement this feature within SureBackup.
"The EDR (Endpoint Detection and Response) solution from CrowdStrike does not work like traditional AV solutions.
Traditional AV products hook the file system via low-level drivers in order to enable the on-access scanning (OAS) of files written to and/or read from storage - interrupting those same writes as part of the process - hence the concern about file contention with other applications and potential data corruption, and thus the need for scanning exclusions in such products.
CrowdStrike on the other hand doesn’t scan files at rest. Instead it looks at executing processes for malicious activities.
"
Our company will be trying to integrate Windows Defender in conjunction with CrowdStrike as the next measure for trying to implement this feature within SureBackup.
-
- VP, Product Management
- Posts: 7081
- Liked: 1511 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
-
- Lurker
- Posts: 1
- Liked: never
- Joined: May 02, 2023 7:18 pm
- Full Name: Jeremiah Zeigler
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
I would be very interested if you have been able to make Crowdstrike work with Surebackups or if you have figured out how to make Microsoft Defender work in conjunction with Crowdstrike. Would you mind informing me on how you were able to make this happen?
-
- Novice
- Posts: 8
- Liked: never
- Joined: Feb 14, 2022 4:03 pm
- Full Name: Zachary Lee
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hi JZeigler,
In our case, as long as Windows Defender is enabled on the backup server + mount server, then Veeam will know to use Windows Defender with the default settings. We did not find a way to make CrowdStrike work with SureBackup.
In our case, as long as Windows Defender is enabled on the backup server + mount server, then Veeam will know to use Windows Defender with the default settings. We did not find a way to make CrowdStrike work with SureBackup.
-
- Veeam Software
- Posts: 688
- Liked: 150 times
- Joined: Jan 22, 2015 2:39 pm
- Full Name: Stefan Renner
- Location: Germany
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hi JZeigler,
With that, Crowdstrike can't work today with SecureRestore.
Thanks
This is the correct answer, to get scanner work with SecureRestore and SureBackup they would need to have a cli based scan engine available which some of the new ones don't have anymore as they don't scan files but monitor the process execution.zacharylee wrote: ↑Feb 24, 2022 8:56 pm CrowdStrike on the other hand doesn’t scan files at rest. Instead it looks at executing processes for malicious activities.
With that, Crowdstrike can't work today with SecureRestore.
Thanks
Stefan Renner
Veeam PMA
Veeam PMA
-
- Novice
- Posts: 4
- Liked: 1 time
- Joined: Mar 25, 2019 6:00 pm
- Full Name: Steve Mannix
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hello,
CrowdStrike now has a CLI scanner CSScanCLI.exe, but they have you rerun the command with a --status command and optional status ID (no ID returns all scan results).
They did say that the results are sent to their console.
Is there a way to get Veeam to run the status command afterward and report the results?
Thanks
CrowdStrike now has a CLI scanner CSScanCLI.exe, but they have you rerun the command with a --status command and optional status ID (no ID returns all scan results).
They did say that the results are sent to their console.
Is there a way to get Veeam to run the status command afterward and report the results?
Thanks
-
- Veeam Software
- Posts: 688
- Liked: 150 times
- Joined: Jan 22, 2015 2:39 pm
- Full Name: Stefan Renner
- Location: Germany
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hi
Thanks for the update on CSScanCLI.exe.
No, currently there is no way to re-check a status with a second command after initial scan started.
I’ll take your feedback into some discussions.
Thanks
Thanks for the update on CSScanCLI.exe.
No, currently there is no way to re-check a status with a second command after initial scan started.
I’ll take your feedback into some discussions.
Thanks
Stefan Renner
Veeam PMA
Veeam PMA
-
- Novice
- Posts: 3
- Liked: never
- Joined: Mar 11, 2024 4:19 am
- Full Name: Daniel Hernández
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hello Stefan.
Hey is there an update regarding your latest comment?
Thanks.
Hey is there an update regarding your latest comment?
Thanks.
-
- Veeam Software
- Posts: 688
- Liked: 150 times
- Joined: Jan 22, 2015 2:39 pm
- Full Name: Stefan Renner
- Location: Germany
- Contact:
Re: Antivirus XML Configuration File for CrowdStrike Falcon Sensor
Hi Daniel,
No update as of today.
But we are regulary reviewing additional vendors to potentially add to the default XML.
Will update here once there are news.
No update as of today.
But we are regulary reviewing additional vendors to potentially add to the default XML.
Will update here once there are news.
Stefan Renner
Veeam PMA
Veeam PMA
Who is online
Users browsing this forum: No registered users and 37 guests