The CrowdStrike Settings That Actually Stop Us | Ep 191 episode artwork

EPISODE · Aug 6, 2026 · 38 MIN

The CrowdStrike Settings That Actually Stop Us | Ep 191

from The Cyber Threat Perspective · host SecurIT360

Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned.In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes.From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries.They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream.The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.TOPICS COVERED- Why EDR vendors ship deficient defaults on purpose- Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks- DLL side-loading, WSL2 abuse, and vulnerable driver attacks- Memory scanning and in-memory tooling detection- Blocking RMM tools with custom IOA rule groups- Exclusion hygiene and the wildcard path problem- Device policies, USB blocking, and insider threatSentinel One and Defender for Endpoint are next — let us know what else you want covered.Blog: https://offsec.blogWork with us on an internal pen test: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Episode metadata supplied by the publisher feed · Published Aug 6, 2026

Embed this episode

Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned. In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire lef...

Distinct summary based on available episode metadata or transcript content.

Ready to play

The CrowdStrike Settings That Actually Stop Us | Ep 191

0:00 38:01

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Cyber Threat Perspective?

This episode is 38 minutes long.

When was this The Cyber Threat Perspective episode published?

This episode was published on August 6, 2026.

Can I download this The Cyber Threat Perspective episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!