<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=2923012&amp;fmt=gif">

How to Guide: Manually Installing the Crowdstrike Falcon Sensor on a Mac

    

high-angle-view-cropped-employee-work-with-laptop

Installing the CrowdStrike Falcon Sensor has sometimes been a challenge on Macs, especially without using a mobile device management (MDM), and recent re-releases from Apple have only amplified that.

Users have been required to approve kernel extensions (kexts) within the Security & Privacy window for each app that uses them since macOS 10.14 (Mojave). However, with macOS 11 (Big Sur), Apple has made their position regarding kexts even more clear by forcing users to agree to “Reduced Security” mode from the boot menu before they even get those approval requests.

Furthermore, starting in late 2020, Apple has begun shipping computers that use their own proprietary chip – the Apple Silicon or M1 – rather than Intel processors. Many applications specifically built for Intel-based Macs require a “translator” to work on M1 Macs. This translator is called Rosetta and is free to download, install, and use, but it can feel like another speed bump for end users (or admins) who are trying to deploy applications across a varied landscape of user devices.

What do these new releases mean for institutions that rely on CrowdsSrike for their security? The good news is, it is still possible to manually install the CrowdStrike Falcon Sensor on a Mac running Big Sur and using the M1 chip, it just takes a couple extra steps. See below for the full installation guide.

For more information about kext extensions in macOS, check out this guide from Apple; and for more information about Rosetta, check out this article.

Enable Kernel Extensions

  1. Shut down the computer.
  2. Once it is off, hold down the power button until you see the following screen:

    image1-3
  3. Click Options.
  4. Click Utilities > Startup Security Utility.

    image3-2-1
  5. Click Security Policy.

    image2
  6. On the following screen:
    1. Select Reduced Security.
    2. Check Allow user management of kernel extensions from identified developers.
    3. Click OK.

      image5
  7. Restart the computer and boot up normally.

Install Rosetta 2

  1. Launch Terminal.
  2. Run the following command: /usr/sbin/softwareupdate --install-rosetta --agree-to-license

Install CrowdStrike Falcon Sensor

  1. Download the sensor installer.
  2. Run the sensor installer on your device using one of these two methods:
    1. Double-click the .pkg file or
    2. Run this command at a terminal, replacing <installer_filename> with the path and file name of your installer package: sudo installer -verboseR -package <installer_filename> -target /
  3. When prompted, enter administrative credentials for the installer.
  4. Click Allow when Falcon asks to monitor network activity:

    image4
  5. Click Open Security Preferences when “CrowdStrike Inc.” tries to load a new system extension:

    image7
  6. In the Security & Privacy window…
    1. Click on the General tab.
    2. Click the padlock icon and enter administrative credentials to unlock.
    3. Click Allow next to the notification about “CrowdStrike Inc.”

      image6
  7. Still within the Security & Privacy window…
    1. Click on the Privacy tab.
    2. In the left pane, select Full Disk Access.
    3. In the right pane, scroll through the list and check both Agent and Falcon.
    4. Click the + button.

      image9-1
  8. Still in the Security & Privacy window…
    1. Click the padlock icon again to lock it.

      image8

Confirm the CrowdStrike Falcon Sensor Installed Successfully

  1. Launch Terminal.
  2. Run the following command: sudo /Applications/Falcon.app/Contents/Resources/falconctl stats

The output should show details about the sensor, including its agent ID (AID), version, customer ID, etc.

FAQs

What is CrowdStrike Falcon Sensor?
The CrowdStrike Falcon Sensor is a lightweight security agent designed to protect your devices from cyber threats. It uses advanced AI and machine learning to detect and prevent malware, ransomware, and other cyberattacks in real time. It’s commonly used by businesses to secure their endpoints, including laptops, desktops, and servers.
How to disable CrowdStrike Falcon Sensor?
Disabling the CrowdStrike Falcon Sensor is not recommended as it leaves your device vulnerable to threats. However, if necessary, it can be temporarily disabled by an administrator through the CrowdStrike Falcon console. Always consult your IT team or managed service provider before making any changes.
What does CrowdStrike do?
CrowdStrike is a leading cybersecurity company that provides endpoint protection, threat intelligence, and incident response services. Its Falcon platform uses cloud-based technology to detect, prevent, and respond to cyber threats across your network.
Does CrowdStrike Falcon Sensor update itself?
Yes, the CrowdStrike Falcon Sensor is designed to update itself automatically. It regularly receives updates from the CrowdStrike cloud to ensure it has the latest threat intelligence and security features, keeping your devices protected without manual intervention.
How to uninstall CrowdStrike Falcon Sensor without a token?
Uninstalling the CrowdStrike Falcon Sensor typically requires an uninstall token for security reasons. If you don’t have a token, contact your IT administrator or CrowdStrike support for assistance. Attempting to uninstall it without proper authorization may violate your organization’s security policies.
Does my computer use CrowdStrike Falcon Sensor?
If your organization uses CrowdStrike for cybersecurity, your computer likely has the Falcon Sensor installed. You can check by looking for the CrowdStrike Falcon agent in your system’s installed programs or task manager. For confirmation, contact your IT department or managed service provider.

Comments