Question

CrowdStrike - best practice

  • 22 October 2023
  • 3 replies
  • 587 views

Userlevel 1
Badge +5

Hi,

I couldn’t find any crowdstrike best practices 

I could only find the antivirus exclusions - https://documentation.commvault.com/2023e/essential/8665_antivirus_exclusions_for_windows.html

Is there any specific best practice for crowdstrike?

 

Best regards,


3 replies

Userlevel 4
Badge +11

Hello @LiorRN 

The files/folders mentioned in the document you shared that are used by Commvault should be excluded from crowd strike.

In cases of stubbing we have seen Crowd strike causing issues and we advise to not run it on the clients where recall/stubbing feature is enabled. Sometimes while installations, crowd strike does not let the installer to go through and appears to be blocking the ports. 

So basically, the admin is advised to properly exclude the ports/files/folders/binaries used by Commvault on crowd strike just like any other AV.

Best,

Rajiv Singal

Userlevel 1
Badge +5

thanks 

Badge +1

Hi All,

I would just like to ask this as well. We have CrowdStrike EDR in our environment and need to know if there are any exclusions that need to be put in place. EDR is different to your normal Anti Virus as it does not scan files and folders.

Business will not accept that we must just exclude everything as there is No vendor specific information or clear explanations on why things are excluded and what negative impact could result from which interactions (weird sentence sorry, but I think you get what I mean!).

 

Reply