Crowdstrike Falcon v6 not recognised by Global Protect HIP

Reply
Highlighted
L0 Member

Crowdstrike Falcon v6 not recognised by Global Protect HIP

Hi everyone!

I believe this is a new one here, but due to upgrading to Mac OS BigSur soon, we need to upgrade GlobalProtect version 5.1.1 to the latest one 5.1.7.

However, we have a double constraint here.

At the moment, we're checking that Crowdstrike v5 is running as part of our HIP checks. When moving to BigSur, we have to upgrade Crowdstrike into v6, but GlobalProtect is not seeing it as part of the HIP reports.

We've been able to "fool" GlobalProtect by inserting plist files from Crowdstrike in /Library/LaunchDaemons but this is not making GlobalProtect detect Crowdstrike.

Is there still compatibility updates that need to be done in GlobalProtect to recognise Crowdstrike v6?

Highlighted
L0 Member

Similar issue. We don't check for a specific version just that CS is installed and Real Time Protection is running. All was good at first and still is if its a Windows device, but v6.1x on Macs while detected no longer has Real Time Protection running. Its most likely due to Apple moving away from kernel extensions, but we have cases opened with Palo and Falcon.

 

Got this from Falcon, but last thing I want to do is run custom checks. I just want it working automagically like before...

 

Custom health check scripts or VPN compliance checks may need to be updated using these new processes.
To check for sensor health, run /Applications/Falcon.app/Contents/Resources/falconctl stats

Highlighted
L0 Member

Yes, at the moment we've been able to workaround it using plists but that does not allow us to check that the Crowdstrike is running and protecting the endpoint.

We still don't have a final solution for this and we may need to either put the BigSur rollout on hold or not using the Crowdstrike check as a condition

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!