If CrowdStrike's system wasn't able to prevent a kernel driver thats all zeros from getting by, you can be sure a malicious payload would have breezed right through.
Oh yeah, at a quick glance looks like that file could have had any payload and it would have been loaded right into the kernel.
What makes you think so?
Earlier there were some screenshots showing an entirely zero-filled .sys file but now we know that's not what the payload was.
To send a malicious payload into the kernel, you would have to take over crowdstrikes deploy infrastructure first, right? I hope the program doesn’t just accept updates from anywhere