Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: Windows 7.3.0 Sensors May Hang After Windows Patches

EDR: Windows 7.3.0 Sensors May Hang After Windows Patches

Environment

  • EDR Windows Sensors: 7.3.0

Symptoms

After applying Windows updates or security patches, Windows may hang during the shutdown part of restarting their system.

Cause

The hang isn't wholly due to the updates, necessarily, but to changes made between EDR 7.2.2 and 7.3.0 with regard to how the sensor locks files during the time it processes* them. The security updates result in overwriting core files (e.g., user32.dll) that are not usually modified, which reveals the overly-aggressive file locking.

*"process the files": refers to copying to store directory, updating on-disk catalog, re-hashing the files (after them having been overwritten by the patch)


Resolution

  • This issue is resolved in Windows Sensor 7.3.1 and Higher. If an upgrade is not possible, and you must remain on 7.3.0, then this Resolution can be followed instead. 
  • The file contention issue can be avoided by temporarily disabling the collection of certain events during the time of file contention (which can lead to the hang). 
1.  Prior to modifying Group Settings, note which Event Collections are currently being used. 
2.  After applying Windows updates and prior to restarting, in Sensor Group Settings, disable "Binary module loads", "Binaries" and "Binary info".   Disabling these settings prevents the rehashing of the files, which will avoid the locking. 
This is a article attached imageThis is a article attached image
3.  Reboot the endpoints as required by Windows.
4.  Re-enable the settings back to the original settings and remember to save the Group Settings.

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-31-2022
Views:
872
Contributors