Skip to content

CrowdStrike Falcon sensor recipe #413

Description

@rneher-igel

CrowdStrike Falcon sensor recipe

Installing Falcon Sensor for Linux

Set your Customer ID (CID) on the sensor:

/opt/CrowdStrike/falconctl -s --cid=<CID>

Version Build With: falcon-sensor_7.33.0-18606_amd64.deb

postinst

#!/bin/sh -e

case "$1" in
"configure")
    if [ -e /opt/CrowdStrike/falcon-sensor.cleanup ]; then
        PID_COUNTER=0
        while [ `pgrep -x falcon-sensor` ]; do
            sleep 1
            PID_COUNTER=$((PID_COUNTER + 1))
            if [ $PID_COUNTER -gt 29 ]; then
                pkill falcon-sensor > /dev/null 2>&1 || true
            fi
        done
        # dpkg doesn't remove the old audit sensor files
        if [ -e "/etc/audisp/plugins.d/falcon-sensor.conf" ]; then
            rm /etc/audisp/plugins.d/falcon-sensor.conf > /dev/null 2>&1 || true
        fi
        if [ -e "/etc/audit/rules.d/falcon-sensor.rules" ]; then
            rm /etc/audit/rules.d/falcon-sensor.rules > /dev/null 2>&1 || true
        fi

        # If its an upgrade from audit, we want to preserve the settings.  Do
        # this after the audit sensor has terminated so we know it's not being
        # written to.
        mv -f /opt/CrowdStrike/falcon-sensor.config /opt/CrowdStrike/falconstore > /dev/null 2>&1 || true
        #
        # Special cleanup needed for updates from audit based sensor.
        # Since its an update, it wont cleanup the audit settings

        # If the host system has custom rules added in /etc/audit/audit.rules
        # after the audit sensor was installed, we cant just overwrite the
        # rules file with the old saved rules file.
        sed -i '/crowdstrike/d' /etc/audit/audit.rules > /dev/null 2>&1 || true
        rm -f /etc/audit/audit.rules.dpkg-old > /dev/null 2>&1 || true

        # likewise for /etc/audisp/audispd.conf. If q_depth is 1500, we reset
        # it to the original value, otherwise we assume the customer has
        # changed the value and we should leave it alone.
        Q_DEPTH=$(sed -n 's/^q_depth\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audisp/audispd.conf)
        if [ "$Q_DEPTH" -eq "1500" ]; then
            if [ -e /etc/audisp/audispd.conf.dpkg-old ]; then
                OLD_Q_DEPTH=$(sed -n 's/^q_depth\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audisp/audispd.conf.dpkg-old)
            else
                OLD_Q_DEPTH=150
            fi
            sed -i 's/^q_depth\s*=\s*1500/q_depth = '"$OLD_Q_DEPTH"'/' /etc/audisp/audispd.conf > /dev/null 2>&1 || true
        fi
        rm -f /etc/audisp/audispd.conf.dpkg-old > /dev/null 2>&1 || true

        # Also, for /etc/audit/auditd.conf.  If freq is 2000, we reset it to the
        # original value, otherwise we assume the customer has changed the value
        # and we should leave it alone.  Similarly, for
        FREQ=$(sed -n 's/^freq\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audit/auditd.conf)
        if [ "$FREQ" -eq "2000" ]; then
            if [ -e /etc/audit/auditd.conf.dpkg-old ]; then
                OLD_FREQ=$(sed -n 's/^freq\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audit/auditd.conf.dpkg-old)
            else
                OLD_FREQ=50
            fi
            sed -i 's/^freq\s*=\s*2000/freq = '"$OLD_FREQ"'/' /etc/audit/auditd.conf > /dev/null 2>&1 || true
        fi
        # Similarly for disp_qos, if its lossless, we reset it to the original value.
        DISP_QOS=$(sed -n 's/^disp_qos\s*=\s*\([a-z]*\).*$/\1/p' < /etc/audit/auditd.conf)
        if [ "$DISP_QOS" = "lossless" ]; then
            if [ -e /etc/audit/auditd.conf.dpkg-old ]; then
                OLD_DISP_QOS=$(sed -n 's/^disp_qos\s*=\s*\([a-z]*\).*$/\1/p' < /etc/audit/auditd.conf.dpkg-old)
            else
                OLD_DISP_QOS="lossy"
            fi
            sed -i 's/lossless/'"$OLD_DISP_QOS"'/' /etc/audit/auditd.conf > /dev/null 2>&1 || true
        fi
        sed -i '/#falcon-sensor/d' /etc/audit/auditd.conf > /dev/null 2>&1 || true
        rm -f /etc/audit/auditd.conf.dpkg-old > /dev/null 2>&1 || true

        rm /opt/CrowdStrike/falcon-sensor.cleanup > /dev/null 2>&1 || true

        # unconditionally restart auditd
        service auditd start > /dev/null 2>&1 || true
    fi

    if [ -e /opt/CrowdStrike/falconstore.bak ]; then
        mv -f /opt/CrowdStrike/falconstore.bak /opt/CrowdStrike/falconstore > /dev/null 2>&1 || true
    fi

    if [ -e /opt/CrowdStrike/Registry.bin.bak ]; then
        mv -f /opt/CrowdStrike/Registry.bin.bak /opt/CrowdStrike/Registry.bin > /dev/null 2>&1 || true
    fi

    if [ -e /opt/CrowdStrike/Registry_km.bin.bak ]; then
        mv -f /opt/CrowdStrike/Registry_km.bin.bak /opt/CrowdStrike/Registry_km.bin > /dev/null 2>&1 || true
    fi

    # Create PackageManager related directories
    if [ ! -d /opt/CrowdStrike/Packages ]; then
        mkdir -m 750 /opt/CrowdStrike/Packages
    fi

    # Create PackageManager related directories
    if [ ! -d /opt/CrowdStrike/Falcon4IT ]; then
        mkdir -m 750 /opt/CrowdStrike/Falcon4IT
        mkdir -m 750 /opt/CrowdStrike/Falcon4IT/bin
        mkdir -m 750 /opt/CrowdStrike/Falcon4IT/results
    fi
    # Create ASPM related directories
    if [ ! -d /opt/CrowdStrike/ASPM ]; then
        mkdir -m 750 /opt/CrowdStrike/ASPM
        mkdir -m 750 /opt/CrowdStrike/ASPM/bin
        mkdir -m 750 /opt/CrowdStrike/ASPM/results
        mkdir -m 750 /opt/CrowdStrike/ASPM/tmp
    fi
    ;;
"abort-upgrade")
    ;;
"abort-remove")
    ;;
"abort-deconfigure")
    ;;
esac

# dh_installdeb will replace this with shell code automatically
# generated by other debhelper scripts.

# Automatically added by dh_systemd_enable/11.1.6ubuntu2
if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then
	# This will only remove masks created by d-s-h on package removal.
	deb-systemd-helper unmask 'falcon-sensor.service' >/dev/null || true

	# was-enabled defaults to true, so new installations run enable.
	if deb-systemd-helper --quiet was-enabled 'falcon-sensor.service'; then
		# Enables the unit on first installation, creates new
		# symlinks on upgrades if the unit file has changed.
		deb-systemd-helper enable 'falcon-sensor.service' >/dev/null || true
	else
		# Update the statefile to add new symlinks (if any), which need to be
		# cleaned up on purge. Also remove old symlinks.
		deb-systemd-helper update-state 'falcon-sensor.service' >/dev/null || true
	fi
fi
# End automatically added section
# Automatically added by dh_installinit/11.1.6ubuntu2
if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then
	if [ -x "/etc/init.d/falcon-sensor" ]; then
		update-rc.d falcon-sensor defaults >/dev/null || exit 1
	fi
fi
# End automatically added section


# Start the sensor via the init script (SysV or Systsemd). the init script will start the sensor only if the cid is set.
# See the 'override_dh_installinit' section in 'rules' file, to see why we don't use the automated debhelp to start the sensor.
if [ -x "/etc/init.d/falcon-sensor" ] || [ -e "/etc/init/falcon-sensor.conf" ]; then
    if [ -n "$2" ]; then
        _action=restart
    else
        _action=start
    fi
    invoke-rc.d falcon-sensor $_action > /dev/null 2>&1 || true
fi

exit 0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions