CrowdStrike has done loads to damage their own credibility to anyone paying attention, but because they've chosen to be favorable to certain power players along political lines there are folks out there that treat them like the be-all-end-all of the industry.
As someone in-industry, hearing people parrot press releases from CrowdStrike has me looking at them sideways.
Edit/Addendum: Just to lay bare my opinion of them... CrowdStrike is a clown-ass company run by clown-ass people and with a clown-ass product.
Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".
For some reason java.exe startup was A-OK though so I started using JEdit again.
Aggravatingly, it would occasionally disappear my builds and then flag me to IT. My dude, I am hired as a developer of native windows C++ applications why the hell is this trash on my would-be workstation-class machine?
That's what it feels like with some of these policies.
There's nothing wrong in hooking ~EvErY~ call to NtCreateUserProcess or even a thousand other functions in and of itself. The issue is what they're doing inside those hooks.
We have installed another product that also hooks +@EvErY sInglE@+ call to NtCreateUserProcess and to couple dozen other functions and you know what? VSCode works just fine. WSL too. Edge and Chrome too.
Sure there's a measurable effect on performance but nothing like you're describing.
Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection modules or does the tool have a significant risk surface? 2) What was the threshold set for quarantining? Does it make sense in this case? 3) Is/should your device be part of a "Developer" policy that is more permissive? Are all users of the tool impacted? 4) Does this happen frequently? If so, should definitions be manually pushed in batches so everyone is not nerfed at once. 5) What is the process for the developer to report/fix the false positive? Is the response time sufficient?
I'm probably forgetting a few. The point is, shit happens (especially with technology). You respond, fix, and hopefully learn. If shit happens a lot, its either because the tool owner doesn't give a shit or the product is shit itself. The delicate balance of security and business operations/innovation is all about weighing and evaluating risk/benefit.
The examples shown were behavior based, not hash based. It didn't look up a file in a dictionary, it detected priviledge elevations and such.
No product is perfect, but if you have a need to be protected (especially if you are at risk from adversaries such as in banking, health care, government work, or against corporate espionage) I'm quite confident in saying that you're much better off with it than without.
The same company would also, at random times, attempt to phish us or send us fake emails to get us to click on links, to help educate us on the kinds of threats our customers faced I consider myself fairly savvy, and even I fell for one of them.
I ended up leaving for a variety of reasons, but "losing faith in the product" was not one of them.
However what I see is essentially their true positive and false negative rate, I would be interested to know what the false positive rate is.
I'm more curious about the case if your org is a few thousand people and you receive random low-effort attacks distributed across those people, will endpoint protection be a panacea?
In practice, most implementations cause more harm than good. Some of them even add vulnerabilities themselves.