Index / Vendors / CrowdStrike
Product Record

CrowdStrike

Publicly-reported techniques recorded as bypassing CrowdStrike. Each entry is sourced to its original disclosure. This is a factual tally, maintained on the same basis for every vendor in the Index.

19
recorded bypasses
8
distinct techniques

Techniques recorded against CrowdStrike

TechniqueEntriesHigh-confidenceMost recent
Disable or Modify Tools 532025-09-29
BYOVD (Vulnerable Driver) 432026-04-05
EDR Unhooking 422025-12-07
Process Injection 222025-03-05
Valid Accounts 112025-10-07
Exploitation for Priv-Esc 112024-08-19
Tamper-Protection Bypass 102025-06-12
AMSI Bypass 112025-04-15

All entries

TechniqueConfidenceDisclosedSource
BYOVD (Vulnerable Driver) high 2026-04-05threatlabsnews.xcitium.com record →
BYOVD (Vulnerable Driver) high 2026-02-24blog.silentforce.io record →
BYOVD (Vulnerable Driver) high 2026-02-10www.gblock.app record →
EDR Unhooking high 2025-12-07github.com record →
EDR Unhooking medium 2025-10-18www.brinztech.com record →
Valid Accounts high 2025-10-07cve.akaoma.com record →
Disable or Modify Tools high 2025-09-29prevent-ransomware.com record →
Disable or Modify Tools high 2025-08-28beierle.win record →
EDR Unhooking medium 2025-07-13github.com record →
Tamper-Protection Bypass medium 2025-06-12github.com record →
BYOVD (Vulnerable Driver) medium 2025-05-30threatlabsnews.xcitium.com record →
AMSI Bypass high 2025-04-15github.com record →
Disable or Modify Tools high 2025-03-06securityaid.co.uk record →
Process Injection high 2025-03-05finalfrontiersecurity.com record →
Exploitation for Priv-Esc high 2024-08-19securityaffairs.com record →
Process Injection high 2023-12-08securityaffairs.com record →
Disable or Modify Tools medium 2023-09-13labs.infoguard.ch record →
EDR Unhooking high 2023-07-06inbits-sec.com record →
Disable or Modify Tools medium 2023-06-01www.threatlocker.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file, not that a product is unaffected.