Skip to main content
Question

Crowdstrike TCC.xml for PPPC

  • October 16, 2019
  • 38 replies
  • 299 views

Show first post

38 replies

Forum|alt.badge.img+4
  • Contributor
  • February 13, 2020

After each Catalina version updates, it looks like CrowdStrike asking authorization to run even though Kext & Full Disk access granted via Jamf


stephanpeterson
Forum|alt.badge.img+12

I thought I had everything worked out and my Config Profile looks correct in Profiles pref pane. However, I don't see falcond listed in Full Disk Access section of Security & Privacy pref pane. Not listed at all, checkmark or no. Very curious.

I'm starting to think that when FDA is given via a config profile that there's no indication shown in Security & Privacy. Is that right?


stephanpeterson
Forum|alt.badge.img+12

I finally pieced it together. You need to use the following command:

plutil -p /Library/Application Support/com.apple.TCC/MDMOverrides.plist

In the output you need to find a section for falcond:

    {
      "/Library/CS/falcond" => {
        "kTCCServiceSystemPolicyAllFiles" => {
          "Allowed" => 1
          "CodeRequirement" => "identifier falcond and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = X9E956P446"
          "CodeRequirementData" => <fade0c00 00000094 00000001 00000006 00000006 00000006 00000006 00000002 00000007 66616c63 6f6e6400 0000000f 0000000e 00000001 0000000a 2a864886 f7636406 02060000 00000000 0000000e 00000000 0000000a 2a864886 f7636406 010d0000 00000000 0000000b 00000000 0000000a 7375626a 6563742e 4f550000 00000001 0000000a 58394539 35365034 34360000>
          "Identifier" => "/Library/CS/falcond"
          "IdentifierType" => "path"
          "StaticCode" => 0
        }
      }

Forum|alt.badge.img+1
  • New Contributor
  • June 1, 2020

So I've uploaded the pkg to JAMF, it gets installed on my test vm and I can see all the contents within /Library/CS/falcond. I've applied a simple script for the license and created the PPPC that CS documentation calls for, however, the client won't run and I can't see it on Activity Monitor.

Am I missing something?


Forum|alt.badge.img+9
  • New Contributor
  • June 2, 2020

@jeanviales do you have the kernel extension approved? CrowdStrike would be able to run even without the PPPC policy (that's only needed for the agent to be able to read data in certain places), but it wouldn't keep the agent from running. Not having the kernel extension loaded would keep it from running.


Forum|alt.badge.img+1
  • New Contributor
  • June 2, 2020

Hi @patgmac ,

I set the kernel extension and entered the following attributes for it:

Isn't this the way it is supposed to go?

I ran the: kextstat | grep crowd command and it returns: com.crowdstrike.sensor which according to CS means that the sensor is approved but i cant see it.


Forum|alt.badge.img+1
  • New Contributor
  • June 2, 2020

@patgmac So I literally just accessed CS admin portal and went to see the dashboard and somehow my vm is showing there even tho I can't see the falcond process running within the vm.


Forum|alt.badge.img+5
  • Contributor
  • November 17, 2020

Anyone know the folder location for Big Sur or Catalina? I don't see it under /Library/CS


Forum|alt.badge.img+14
  • Contributor
  • November 17, 2020

It is built into the Application:
/Applications/Falcon.app/Contents/Resources/falconctl


mykool
Forum|alt.badge.img+10
  • Contributor
  • November 24, 2020

Did it change locations? Used to be under /Library/CS


Forum|alt.badge.img+9
  • New Contributor
  • November 24, 2020

@mismith223 yes, it changed because Big Sur needs things to be in Applications.


mykool
Forum|alt.badge.img+10
  • Contributor
  • November 24, 2020

@patgmac Thanks. Scared the crap out of me. I have a smart group that shows devices that don't have CS and they all popped up showing I didn't have AV on them.


Forum|alt.badge.img+4
  • Contributor
  • December 2, 2020

CrowdStrike with BigSur - > https://www.jamf.com/jamf-nation/discussions/37488/crowdstrike-configuration-profile-bigsur