CrowdStrike Falcon sensor recipe
Installing Falcon Sensor for Linux
Set your Customer ID (CID) on the sensor:
/opt/CrowdStrike/falconctl -s --cid=<CID>
Version Build With: falcon-sensor_7.33.0-18606_amd64.deb
postinst
#!/bin/sh -e
case "$1" in
"configure")
if [ -e /opt/CrowdStrike/falcon-sensor.cleanup ]; then
PID_COUNTER=0
while [ `pgrep -x falcon-sensor` ]; do
sleep 1
PID_COUNTER=$((PID_COUNTER + 1))
if [ $PID_COUNTER -gt 29 ]; then
pkill falcon-sensor > /dev/null 2>&1 || true
fi
done
# dpkg doesn't remove the old audit sensor files
if [ -e "/etc/audisp/plugins.d/falcon-sensor.conf" ]; then
rm /etc/audisp/plugins.d/falcon-sensor.conf > /dev/null 2>&1 || true
fi
if [ -e "/etc/audit/rules.d/falcon-sensor.rules" ]; then
rm /etc/audit/rules.d/falcon-sensor.rules > /dev/null 2>&1 || true
fi
# If its an upgrade from audit, we want to preserve the settings. Do
# this after the audit sensor has terminated so we know it's not being
# written to.
mv -f /opt/CrowdStrike/falcon-sensor.config /opt/CrowdStrike/falconstore > /dev/null 2>&1 || true
#
# Special cleanup needed for updates from audit based sensor.
# Since its an update, it wont cleanup the audit settings
# If the host system has custom rules added in /etc/audit/audit.rules
# after the audit sensor was installed, we cant just overwrite the
# rules file with the old saved rules file.
sed -i '/crowdstrike/d' /etc/audit/audit.rules > /dev/null 2>&1 || true
rm -f /etc/audit/audit.rules.dpkg-old > /dev/null 2>&1 || true
# likewise for /etc/audisp/audispd.conf. If q_depth is 1500, we reset
# it to the original value, otherwise we assume the customer has
# changed the value and we should leave it alone.
Q_DEPTH=$(sed -n 's/^q_depth\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audisp/audispd.conf)
if [ "$Q_DEPTH" -eq "1500" ]; then
if [ -e /etc/audisp/audispd.conf.dpkg-old ]; then
OLD_Q_DEPTH=$(sed -n 's/^q_depth\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audisp/audispd.conf.dpkg-old)
else
OLD_Q_DEPTH=150
fi
sed -i 's/^q_depth\s*=\s*1500/q_depth = '"$OLD_Q_DEPTH"'/' /etc/audisp/audispd.conf > /dev/null 2>&1 || true
fi
rm -f /etc/audisp/audispd.conf.dpkg-old > /dev/null 2>&1 || true
# Also, for /etc/audit/auditd.conf. If freq is 2000, we reset it to the
# original value, otherwise we assume the customer has changed the value
# and we should leave it alone. Similarly, for
FREQ=$(sed -n 's/^freq\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audit/auditd.conf)
if [ "$FREQ" -eq "2000" ]; then
if [ -e /etc/audit/auditd.conf.dpkg-old ]; then
OLD_FREQ=$(sed -n 's/^freq\s*=\s*\([0-9]*\).*$/\1/p' < /etc/audit/auditd.conf.dpkg-old)
else
OLD_FREQ=50
fi
sed -i 's/^freq\s*=\s*2000/freq = '"$OLD_FREQ"'/' /etc/audit/auditd.conf > /dev/null 2>&1 || true
fi
# Similarly for disp_qos, if its lossless, we reset it to the original value.
DISP_QOS=$(sed -n 's/^disp_qos\s*=\s*\([a-z]*\).*$/\1/p' < /etc/audit/auditd.conf)
if [ "$DISP_QOS" = "lossless" ]; then
if [ -e /etc/audit/auditd.conf.dpkg-old ]; then
OLD_DISP_QOS=$(sed -n 's/^disp_qos\s*=\s*\([a-z]*\).*$/\1/p' < /etc/audit/auditd.conf.dpkg-old)
else
OLD_DISP_QOS="lossy"
fi
sed -i 's/lossless/'"$OLD_DISP_QOS"'/' /etc/audit/auditd.conf > /dev/null 2>&1 || true
fi
sed -i '/#falcon-sensor/d' /etc/audit/auditd.conf > /dev/null 2>&1 || true
rm -f /etc/audit/auditd.conf.dpkg-old > /dev/null 2>&1 || true
rm /opt/CrowdStrike/falcon-sensor.cleanup > /dev/null 2>&1 || true
# unconditionally restart auditd
service auditd start > /dev/null 2>&1 || true
fi
if [ -e /opt/CrowdStrike/falconstore.bak ]; then
mv -f /opt/CrowdStrike/falconstore.bak /opt/CrowdStrike/falconstore > /dev/null 2>&1 || true
fi
if [ -e /opt/CrowdStrike/Registry.bin.bak ]; then
mv -f /opt/CrowdStrike/Registry.bin.bak /opt/CrowdStrike/Registry.bin > /dev/null 2>&1 || true
fi
if [ -e /opt/CrowdStrike/Registry_km.bin.bak ]; then
mv -f /opt/CrowdStrike/Registry_km.bin.bak /opt/CrowdStrike/Registry_km.bin > /dev/null 2>&1 || true
fi
# Create PackageManager related directories
if [ ! -d /opt/CrowdStrike/Packages ]; then
mkdir -m 750 /opt/CrowdStrike/Packages
fi
# Create PackageManager related directories
if [ ! -d /opt/CrowdStrike/Falcon4IT ]; then
mkdir -m 750 /opt/CrowdStrike/Falcon4IT
mkdir -m 750 /opt/CrowdStrike/Falcon4IT/bin
mkdir -m 750 /opt/CrowdStrike/Falcon4IT/results
fi
# Create ASPM related directories
if [ ! -d /opt/CrowdStrike/ASPM ]; then
mkdir -m 750 /opt/CrowdStrike/ASPM
mkdir -m 750 /opt/CrowdStrike/ASPM/bin
mkdir -m 750 /opt/CrowdStrike/ASPM/results
mkdir -m 750 /opt/CrowdStrike/ASPM/tmp
fi
;;
"abort-upgrade")
;;
"abort-remove")
;;
"abort-deconfigure")
;;
esac
# dh_installdeb will replace this with shell code automatically
# generated by other debhelper scripts.
# Automatically added by dh_systemd_enable/11.1.6ubuntu2
if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then
# This will only remove masks created by d-s-h on package removal.
deb-systemd-helper unmask 'falcon-sensor.service' >/dev/null || true
# was-enabled defaults to true, so new installations run enable.
if deb-systemd-helper --quiet was-enabled 'falcon-sensor.service'; then
# Enables the unit on first installation, creates new
# symlinks on upgrades if the unit file has changed.
deb-systemd-helper enable 'falcon-sensor.service' >/dev/null || true
else
# Update the statefile to add new symlinks (if any), which need to be
# cleaned up on purge. Also remove old symlinks.
deb-systemd-helper update-state 'falcon-sensor.service' >/dev/null || true
fi
fi
# End automatically added section
# Automatically added by dh_installinit/11.1.6ubuntu2
if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then
if [ -x "/etc/init.d/falcon-sensor" ]; then
update-rc.d falcon-sensor defaults >/dev/null || exit 1
fi
fi
# End automatically added section
# Start the sensor via the init script (SysV or Systsemd). the init script will start the sensor only if the cid is set.
# See the 'override_dh_installinit' section in 'rules' file, to see why we don't use the automated debhelp to start the sensor.
if [ -x "/etc/init.d/falcon-sensor" ] || [ -e "/etc/init/falcon-sensor.conf" ]; then
if [ -n "$2" ]; then
_action=restart
else
_action=start
fi
invoke-rc.d falcon-sensor $_action > /dev/null 2>&1 || true
fi
exit 0
CrowdStrike Falcon sensor recipe
Installing Falcon Sensor for Linux
Set your Customer ID (CID) on the sensor:
Version Build With:
falcon-sensor_7.33.0-18606_amd64.debpostinst