r/crowdstrike 2d ago

Troubleshooting Recent issues with CSNpcap.sys

I am about to create a ticket, but wanted to kick it around here real quick. We are getting a lot of issues with the CrowdStrike agent is triggering a service and the CSFalconContainer around the 'CSNpcap.sys' located in '\Device\HarddiskVolume3\Windows\System32\drivers\CSNpcap.sys'

This has happened over the last couple of days. I just marked it as a possible update as we have the probe running for at least 6 months now. However today, we are starting to see the same hostnames starting to come up with detections.

1 Upvotes

10 comments sorted by

1

u/Andrew-CS CS ENGINEER 2d ago edited 2d ago

Hi there. Exposure Management uses this driver to conduct network vulnerability scanning when your policy is configured to use that capability. I hope that helps! Let us know if there is a specific issue you’re seeing.

1

u/MSP-IT-Simplified 1d ago

Sorry that I was not more clear in my statement. The Falcon agent is flagging this as a high detection.

And our SOAR workflow will auto isolate a device with a detection of High or Critical.

1

u/Andrew-CS CS ENGINEER 1d ago

Got it. Let me see if I can reproduce and get someone on it.

1

u/MSP-IT-Simplified 1d ago

We have 4 CID's we are disabling the Network scanning on now. Working to corralate the data and submit a ticket.

We are also seeing some possible other false positives, that I am not blaming the network scanning, but started at the same time as this. On some random devices, OneDrive service is getting flagged as attempting to modify the Crowstrike regkeys as well. I am just saying it is weird it is happening at the same time.

1

u/yankeesfan01x 14h ago

The OneDrive or OneDriveSync FP's were addressed a while ago. Are you sensors up-to-date that this is happening on?

1

u/MSP-IT-Simplified 12h ago

We are running the 7.40.21306 version currently sitting on 'Auto N-1'.

1

u/MSP-IT-Simplified 12h ago

Communication with support, this is possible a new (and maybe) known issue. They were asking if we are seeing this same issues with device detections with Outlook[.]exe and some other applications.

1

u/yankeesfan01x 8h ago

Good to know and thanks for updating the community!

1

u/MSP-IT-Simplified 1d ago

u/Andrew-CS - Ticket created with all the details. Case ID: 02621858

2

u/Andrew-CS CS ENGINEER 1d ago

TY