Interoperability with Crowdstrike
07/31/2019 1 People found this article helpful 392,396 Views
Description
To learn how to exclude files and folders please see Capture Client Interoperability Issues with Third Party Applications.
Resolution
For SentinelOne versions lower than 3.0, applications that run using WOW64 will not work when both SentinelOne and Crowdstrike are installed on the same 64-bit device.
Starting from SentinelOne Windows Agent version 2.7, the protection against malicious WOW64 applications is achieved by injection into a WOW64 process using Deep Hook monitoring technique.
In their latest agent release, Crowdstrike introduces an injection to WOW64 processes as well.
When SentinelOne Agents run side-by-side with the latest Crowdstrike agents, having both agents inject to the same WOW64 process causes an invalid address access violation and prevents WOW64 applications from running.
Recommendations:
- Upgrade your SentinelOneWindows Agents to version 3.0.
- Contact Crowdstrike support and ask them to disable Crowdstrike's native WOW64 injection of their DLL umppc8104.dll residing in system32. If they are NOT able to do this, continue to the next option.
- Contact Sonicwall support to temporarily disable the WOW64 injection for your affected endpoints. **Caution**This is not intended as a long term solution as it lowers the ability to provide complete protection from applications that run using WOW64.
Related Articles
Categories
Was This Article Helpful?
YESNO