frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: CrowdStrike Falcon users, check for excess KernelModuleArchiveExt files

6•CaliforniaKarl•2h ago
Hello!

This is a heads-up for folks who run CrowdStrike Falcon on Linux servers, and particularly on Linux servers that were provisioned some time ago. It's a problem that CrowdStrike does not plan on fixing, and so I wanted to let others know before it causes your machines to hang.

You should have CrowdStrike Falcon installed at path /opt/CrowdStrike/. In that directory, you probably have one file whose name begins with "KernelModuleArchive", and many files whose name begins with "KernelModuleArchiveExt". That's the problem.

CrowdStrike appends a version number to every executable & library file. It does a good job of cleaning up old versions of almost all of its files. Except for KernelModuleArchiveExt.

I first noticed this happening when a virtual machine (with a small /opt partition) filled up /opt, and the system stopped responding. Turns out, /opt/CrowdStrike had filled up with 18 different KernelModuleArchiveExt files.

What is the fix? Well, our CrowdStrike admins opened a ticket with CrowdStrike, and we were told:

* Yes, the KernelModuleArchiveExt files are not being cleaned up automatically. Other files are being cleaned up automatically, but not the KernelModuleArchiveExt files.

* Will CrowdStrike release an update that cleans up the KernelModuleArchiveExt files? No.

* Will you put it on your roadmap to implement in the future? No.

* So, what should we do? If you want to clean them up, do it yourself.

If your site uses CrowdStrike uninstall protection, you cannot clean them up yourself without first getting a "maintenance token" from your CrowdStrike admins. Otherwise, deleting all KernelModuleArchiveExt files and restarting the CrowdStrike Falcon sensor works (it goes out and downloads the KernelModuleArchiveExt that it needs). Personally, though, I don't think we should have to do this.

Since CrowdStrike refuses to fix this, I wanted to let folks know, so you can check your systems. If you discover that this problem also affects you, I encourage you to open your own support ticket with CrowdStrike.

Comments

broknbottle•58m ago
I’m assuming this affects their older kernel module variant. Switch to their bpf version if you must use this snake oil
CaliforniaKarl•35m ago
Unfortunately, no.

From what I've seen, CrowdStrike Falcon installations contain both the BPF components and the kernel module. (I think you can tell which one you're using: if falcon-sensor is running, it's the kernel module; if falcon-sensor-bpf is running, it's BPF.)

I manage systems running Debian, Ubuntu, RHEL, and Rocky. Newer and older, kernel and BPF. And unfortunately, this issue is present across all of them.

TrumpRX

https://trumprx.gov/
1•caelinsutch•50s ago•0 comments

North Korea's Contagious Interview Campaign Escalates: 338 Malicious NPM

https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages
1•feross•1m ago•0 comments

The book that could shake the Pope's faith

https://unherd.com/2025/10/the-book-that-could-shake-the-popes-faith/
1•binning•2m ago•0 comments

Legitimate Crypto Recovery Services – Betafort Recovery

1•PatrickHughes•2m ago•0 comments

Sora 2 Prompt Generator – Turn plain text into cinematic Sora 2 video prompts

https://www.sora2prompt.co/
1•Charlie_Wang•4m ago•1 comments

Beating the L1 cache with value speculation

https://mazzo.li/posts/value-speculation.html
1•shoo•7m ago•0 comments

Show HN: Install Cursor rules and Claude agents like NPM packages

https://promptpm.dev
3•khaliqgant•8m ago•0 comments

(Re)Introducing the Pebble Appstore

https://ericmigi.com/blog/re-introducing-the-pebble-appstore/
1•duck•8m ago•0 comments

Chilling discovery: Physicists go to extremes to capture quantum materials

https://news.harvard.edu/gazette/story/2025/10/chilling-discovery/
1•nadis•14m ago•0 comments

Female athletes have faster reaction times on day they ovulate, study finds

https://www.theguardian.com/society/2025/oct/10/female-athletes-faster-reaction-times-day-ovulate...
1•binning•14m ago•0 comments

Everything Is Television

https://www.derekthompson.org/p/why-everything-became-television
1•bookofjoe•16m ago•0 comments

Homebrew's MCP Server

https://docs.brew.sh/MCP-Server
1•alwillis•18m ago•0 comments

Show HN: Ghost-frame: 2click iframe embed webcomponent (e.g. YouTube, gmaps, x)

https://github.com/ulrischa/ghost-frame
1•ulrischa•19m ago•0 comments

Introduction to Computer Organization (2021)

https://bob.cs.sonoma.edu/IntroCompOrg-RPi/intro-co-rpi.html
1•lrsjng•19m ago•0 comments

Rip: Ricardo Arjona. Black Ribbon Request

1•Toby1VC•20m ago•0 comments

Nasdaq falls more than 3.5%

https://www.wsj.com/livecoverage/stock-market-today-dow-sp-500-nasdaq-10-10-2025
3•lossolo•21m ago•0 comments

Liquid Glass Is Cracked, and Usability Suffers in iOS 26

https://www.nngroup.com/articles/liquid-glass/
107•uxjw•27m ago•61 comments

We can just do things together

https://leaflet.pub/d480e34b-f979-4851-8a14-6da1217d72f7
2•knowtheory•28m ago•0 comments

Managers are throwing entry-level workers under the bus in race to adopt AI

https://www.theregister.com/2025/10/10/ai_is_displacing_entrylevel_professionals/
4•rntn•32m ago•0 comments

We're Not Ready for Superintelligence

https://www.youtube.com/watch?v=5KVDDfAkRgc
1•noworld•33m ago•0 comments

Billions of Dollars 'Vanished': Low-Profile Bankruptcy Rings Wall Street Alarms

https://www.nytimes.com/2025/10/10/business/first-brands-bankruptcy-wall-street.html
1•ChrisArchitect•37m ago•1 comments

A Case of Paradoxical Appetite Increase During Semaglutide Therapy

https://www.mdpi.com/2673-4540/6/10/101
1•PaulHoule•40m ago•0 comments

Ask HN: What does your RSS flow look like?

1•rolymath•41m ago•1 comments

Can't Use Copyrighted Characters in Sora Anymore and People Are Freaking Out

https://gizmodo.com/you-cant-use-copyrighted-characters-in-openais-sora-anymore-and-people-are-fr...
9•gnabgib•41m ago•0 comments

DDSE Foundation Announces Agentic Contract Model (ACM) Framework v0.5.0

1•mrmanna•41m ago•0 comments

MIT pres: she 'cannot support' proposal to adopt Trump priorities for funding

https://apnews.com/article/mit-higher-education-compact-trump-627997083eee635fb865249f1bcc3244
3•bikenaga•41m ago•1 comments

Show HN: Rebuilt Bible search app to run 100% client-side with Transformers.js

https://www.biblos.app/
1•j-b•42m ago•1 comments

We built a lawful AGI prototype with emotional coherence – seeking collaborators

https://soulstreamtechnologies.com/
1•Derenek•42m ago•1 comments

Show HN: ChatGPT Tamagochi Pet Using Apps SDK

https://chatagotchi.app/
1•maxwellg•42m ago•0 comments

Tangled, a Git collaboration platform, built on atproto

https://blog.tangled.org/intro
2•mjbellantoni•43m ago•0 comments