{
  "id": "case-crowdstrike-channel-291",
  "slug": "crowdstrike-falcon-channel-file-outage",
  "title": "CrowdStrike Falcon Sensor Channel File 291 Global Windows Outage",
  "summary": "Unprecedented global IT blackout triggered by an invalid content configuration update (Channel File 291) deployed to CrowdStrike Falcon sensor software, crashing 8.5 million Microsoft Windows devices into unbootable Blue Screen of Death loops, paralyzing commercial aviation, healthcare systems, and retail banks worldwide.",
  "case_number": "SEC-8K-0001535527-24-000028",
  "court": "U.S. House Committee on Homeland Security / SEC EDGAR",
  "district": "W.D. Tex.",
  "country": "United States",
  "opened_at": "2024-07-19",
  "status": "investigation",
  "victim_sector": "Information Technology & Cybersecurity",
  "victim_country": "International",
  "loss_amount_usd": 5400000000,
  "loss_amount_note": "Estimated direct economic losses incurred by Fortune 500 corporations (Delta Air Lines alone reported $500M+).",
  "first_seen_at": "2024-07-19T04:09:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "unattributed-cybercrime",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1195.002",
      "evidence_excerpt": "A Rapid Response Content update delivered via automated Falcon sensor channels contained out-of-bounds memory read logic, triggering kernel panics on Windows systems.",
      "evidence_locator": "CrowdStrike External Technical Root Cause Analysis",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CrowdStrike Falcon Content Issue Analysis",
      "source_url": "https://www.crowdstrike.com/blog/falcon-content-issue-technical-details/"
    },
    {
      "technique_id": "T1489",
      "evidence_excerpt": "Kernel crash bugcheck 0x50 halted operating system boot sequences, disabling critical infrastructure and enterprise workloads globally.",
      "evidence_locator": "Microsoft Analysis of CrowdStrike Outage Impact",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Microsoft Security Blog Analysis",
      "source_url": "https://blogs.microsoft.com"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-07-19",
      "description": "CrowdStrike releases Channel File 291 at 04:09 UTC, triggering immediate Windows kernel crashes globally."
    },
    {
      "event_type": "remediation",
      "event_date": "2024-07-19",
      "description": "CrowdStrike reverts the file at 05:27 UTC; Microsoft deploys automated USB and PE recovery tools."
    },
    {
      "event_type": "testimony",
      "event_date": "2024-09-24",
      "description": "CrowdStrike senior leadership testifies before U.S. House Homeland Security subcommittee."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Automated deployment of defective Rapid Response Content update (Channel File 291) to CrowdStrike Falcon sensor software on Windows devices worldwide.",
    "blast_radius": "8.5 million Microsoft Windows computers crashed into unbootable Blue Screen of Death loops, paralyzing commercial aviation, healthcare, and financial services with over $5.4 billion in direct losses.",
    "kill_chain": [
      {
        "phase": "Content Packaging",
        "title": "Rapid Response Content Creation",
        "description": "CrowdStrike engineers packaged Channel File 291 containing 21 input fields against an expected 20-field validation schema.",
        "technical_artifacts": [
          "Channel File 291 update package",
          "CrowdStrike Content Validator"
        ],
        "mitre_technique_id": "T1195.002"
      },
      {
        "phase": "Automated Delivery",
        "title": "Global Sensor Channel Synchronization",
        "description": "The defective configuration was pushed globally via automated Falcon sensor content channels without staged deployment rings.",
        "technical_artifacts": [
          "C:\\Windows\\System32\\drivers\\CrowdStrike\\C-00000291*.sys",
          "Sensor channel push"
        ],
        "mitre_technique_id": "T1195.002"
      },
      {
        "phase": "Kernel Panic",
        "title": "Out-of-Bounds Memory Read Crash",
        "description": "Upon loading the file, Falcon sensor CSAGENT.SYS executed an out-of-bounds memory read, triggering Windows bugcheck 0x50 (PAGE_FAULT_IN_NONPAGED_AREA).",
        "technical_artifacts": [
          "Windows BSOD bugcheck 0x50",
          "CSAGENT.SYS kernel driver"
        ],
        "mitre_technique_id": "T1489"
      },
      {
        "phase": "Boot Failure Loop",
        "title": "Persistent Blue Screen Reboot Loop",
        "description": "Affected machines entered continuous reboot loops during boot, unable to reach the operating system desktop or load network drivers.",
        "technical_artifacts": [
          "System recovery screen",
          "BitLocker recovery key prompts"
        ],
        "mitre_technique_id": "T1489"
      },
      {
        "phase": "Global Disruption",
        "title": "Worldwide Critical Infrastructure Outage",
        "description": "Thousands of commercial flights were canceled, hospital surgeries rescheduled, and retail payment registers shut down globally.",
        "technical_artifacts": [
          "Delta Air Lines outage report",
          "SEC Form 8-K disclosures"
        ],
        "mitre_technique_id": "T1489"
      }
    ],
    "defensive_takeaways": [
      "Enforce phased, gradual canary deployment rings for all security sensor and endpoint agent updates.",
      "Adopt memory-safe programming paradigms for kernel-level endpoint drivers and content parsers.",
      "Ensure enterprise BitLocker recovery keys and offline bootable recovery media are accessible during infrastructure blackouts.",
      "Establish independent architectural diversity across mission-critical flight dispatch, surgical, and core banking workloads."
    ]
  }
}