CSAgent.sys

CrowdStrike Falcon Sensor

CrowdStrike, Inc.

It runs as a Windows 64-bit file system device driver named “CSAgent”.
Publisher:
CrowdStrike, Inc.  (signed and verified)

Product:
CrowdStrike Falcon Sensor

Description:
CrowdStrike Falcon Sensor Driver

Version:
1.0.0021.1829

MD5:
9fc2fdf5ba58ca5dc31a90086c6bca93

SHA-1:
e26c0d9b5bc59c77b89bfe6b3a25f46cf726aabf

SHA-256:
1e435b93ac29cd8802c73ce112b6ebebd79210a9f2f053b94e561b3303bfb790

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:52:58 PM UTC  (today)

File size:
829.6 KB (849,472 bytes)

Product version:
1.0.0021.1829

Copyright:
(c) CrowdStrike, Inc. All rights reserved.

Original file name:
CSAgent.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\crowdstrike\csagent.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/19/2012 5:00:00 PM

Valid to:
6/20/2015 4:59:59 PM

Subject:
CN="CrowdStrike, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="CrowdStrike, Inc.", L=Laguna Niguel, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A7BEF620A0D4D7FD7ECD5CCB6846663

File PE Metadata
Compilation timestamp:
8/20/2014 11:33:17 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0xCF180

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 42, 27, F3, FF, CC, CC, B0, F5, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8A, 04, 0D, 00, 48, 63, 09, 00, 68, F2, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2C, 05, 0D, 00, 00, 60, 09, 00, 58, F5, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, EA, 05, 0D, 00, F0, 62, 09, 00, 18, F4, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 34, 06, 0D, 00, B0, 61, 09, 00, B8, F3, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 11, 0D, 00...
 
[+]

Entropy:
6.1329

Code size:
633 KB (648,192 bytes)

Driver
Display name:
CSAgent

Description:
CrowdStrike Falcon

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan CSAgent.sys - Powered by Reason Core Security