FeaturedFalconFlank: a CrowdStrike Falcon 0-day
A working local privilege-escalation proof-of-concept against CrowdStrike Falcon went public with no CVE and no vendor advisory. We reproduced it in the lab, mapped exactly what it leaves behind in endpoint telemetry, and shipped real-time detections on the Vega platform to defend our customers. We are also sharing the exact detection logic so any team can deploy or hunt with it directly.
3 Sept 20265 minYossi Donat, Netanel Golani