Gökhan Yıldan

Notlarım İçin Bir Alan

Menu
  • Anasayfa
  • Hakkımda
  • İletişim
Menu

Resolve CrowdStrike Issue Using Powershell and SCCM

Posted on 23/07/202423/07/2024 by Gokhan Yildan

Hello,

Today, I’ve developed a solution for the CrowdStrike issue that has caused significant outages for numerous major companies using PowerShell WPF and SCCM. Microsoft recently released a recovery tool specifically designed to address this problem; however, it requires USB devices for recovery operations.

Supplying, imaging, and distributing large numbers of USB devices to various locations can be hard and time-consuming. Fortunately, with SCCM and your existing network infrastructure, you can deploy the recovery solution via PXE.

Note:
I developed this script with the help of ChatGPT. While I have tested it numerous times, use it at your own risk.

Step 1: Download the CrowdStrike Recovery Tool

To download the tool, visit the GitHub repository using the link below: https://github.com/gokhanyildan/CrowdStrikeRecoveryTool

Step 2: Create an SCCM Task Sequence and Deploy the Tool

Before we begin, ensure that the following components are added to your boot image:

After downloading the tool, we can create a task sequence.

Paste the script into the window, then click OK.

Step 3: Deploy the Tool

To deploy this tool, you can select a collection that includes the problematic machines, or you can deploy it to all devices, as it will need to be manually selected since we are deploying it as an available application.

Since we will be running it from PXE, choose the “Only media and PXE” option with the Available deployment purpose.

You can now finalize the process.

Step 4: Using Tool

With Bitlocker Encryption:

Since I don’t have any problematic devices, I created the file that will need to be deleted manually.

Boot the problematic device using SCCM PXE.

You will then see our task sequence.

After selecting “CrowdStrike Recovery Tool,” a window will appear. If the device drive is encrypted, it will display the “BitLocker ID.” Enter the recovery key associated with that ID.

As you can see, the problematic file has been deleted.

Without Bitlocker Encryption:

This time it says “Bitlocker Encryption Not Found” and you can directly run the tool.

Thanks.

References:

New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints – Microsoft Community Hub

Paylaş:
Category: Powershell, PXE, SCCM (MECM), Task Sequence, Troubleshooting

Post navigation

← Driver Import Problemi – Some driver(s) can not be imported successfully.
Check Which Task Sequence Contains a Specific Package →

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SOSYAL MEDYA

LinkedIn
Twitter
RSS
Follow by Email

SON BAŞLIKLAR

  • Check Which Task Sequence Contains a Specific Package
  • Resolve CrowdStrike Issue Using Powershell and SCCM
  • Driver Import Problemi – Some driver(s) can not be imported successfully.
  • IPerf Aracı İle Network Kapasite ve Performans Analizi
  • Powershell ile SCCM Baseline Tetiklemek

ARŞİV

  • January 2025
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • February 2024
  • December 2023
  • November 2023
  • June 2023
  • March 2023
  • February 2023

KATEGORİLER

  • Applications
  • Baseline
  • Client Troubleshooting
  • CMG
  • Distribution Point
  • Dynamic Collection
  • Imaging
  • Inplace Upgrade
  • Networking
  • Optimization
  • PKI
  • Power BI
  • Powershell
  • Prerequisites Error/Warning
  • PXE
  • SCCM (MECM)
  • Site Recovery
  • SQL
  • SRSS
  • SUP
  • Task Sequence
  • Troubleshooting
  • Windows PC
  • Windows Server
  • Windows Update
  • WSUS

ETİKETLER

AnyDesk Azure Build Geçişi Certification Config Man Config Mgr English Feature Kaldırmak Maintenance Task MEMCM Nasıl Yapılır? PXE Responder SCCM (MECM) Script Software Update Sorun Giderme SQL Reporting SSL/PKI Türkçe Upgrade Windows 10/11

© 2025 Gökhan Yıldan | Powered by Minimalist Blog WordPress Theme