TGViewer
AWS Notes AWS Notes @aws_notes · 5.82K subscribers
Post #2881 2.62K
AWS Health Dashboard — CrowdStrike Falcon Agent Issue

Starting at 9:30 PM PDT on July 18th 2024 some Windows Instances, Windows WorkSpaces and Appstream 2.0 Applications experienced connectivity issues and reboots due to a recent update of the CrowdStrike Falcon agent (csagent.sys). This update caused a stop error (BSOD) within the Windows operating system. Windows instances and WorkSpaces that do not use CrowdStrike, were not affected by this issue. AWS services and network connectivity were also not affected by this event and continued to operate normally.

While the issue was triggered by the CrowdStrike Falcon agent update within the Windows guest operating system, AWS has taken steps to mitigate the issue for as many Windows instances, Windows WorkSpaces and Appstream 2.0 Applications as possible. For the remaining Windows instances and Windows WorkSpaces that are still affected by this issue, customers need to take action to restore connectivity. Customers using Amazon Appstream 2.0 Applications will no longer see the impact.

For EC2 instances, there are currently three paths to recovery.

First, in some cases, a reboot of the instance may allow for the CrowdStrike Falcon agent to be updated to a previously healthy version, resolving the issue. However, this is not successful in all cases, in which case an alternative recovery strategy will be needed.

Second, the following steps can be followed to delete the CrowdStrike Falcon agent file on the affected instance:

(Latest revision: July 19, 7:01 AM PDT)
1. Create a snapshot of the EBS root volume of the affected instance
2. Create a new EBS volume from the snapshot in the same Availability Zone
3. Launch a new instance in that Availability Zone using a different version of Windows
4. Attach the EBS volume from step (2) to the new instance as a data volume
5. Navigate to the \windows\system32\drivers\CrowdStrike\ folder on the attached volume and delete "C-00000291*.sys"
6. Detach the EBS volume from the new instance
7. Create a snapshot of the detached EBS volume
8. Create an AMI from the snapshot by selecting the same volume type as the affected instance
9. Call replace root volume on the original EC2 Instance specifying the AMI just created

Finally, customers can relaunch the EC2 instance from a snapshot or image taken before 9:30 PM PDT. We have been able to confirm that the update that caused the CrowdStrike Falcon agent issue is no longer being automatically updated, so the relaunched instance will no longer be affected by the issue.

For Amazon WorkSpaces, we recommend a reboot of the affected WorkSpaces. As with EC2, this may recover the instance but it does not work in all cases. Alternatively, we would recommend restoring to a recent backup of the workspace.

If you need assistance with any of these actions please contact AWS Support via the AWS Support Center.
More from @aws_notes
  1. Oct 6, 2026AWS Innovation Day 2026: от AI-пилотов к реальным решениям 22 октября в Astana Hub, Астана…
  2. Oct 5, 2026EKS + Kubernetes 1.37 🎉 С официального релиза 1.37 прошло чуть больше месяца и теперь на…
  3. Oct 5, 2026Приглашаем на встречу “Сжечь 50 млрд токенов и собрать кроссплатформенного агента для AI-ф…
  4. Oct 2, 2026#пятничное #перпендикулярныйхайлоад
  5. Oct 2, 2026Приглашаем на встречу Локальные LLM на своём железе, которая пройдет сегодня, 2 октября 20…
  6. Oct 1, 2026Приглашаем на встречу Gnomish Factory. Часть 2: настраиваем свой проект под использование…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →