Is error handling enough? A perfectly valid rule file could hang (but not outright crash) the system, for example.
I would not want to do any of this directly on metal, where the only safety is what you make for yourself. But that's the line Crowdstrike are in.
* By EDR standards, at least, where "only" one reboot a week forced entirely by memory lost to an unkillable process counts as exceptionally good.
Failure can happen in strange ways. When in a position as sensitive as deploying software to far-flung machines in arbitrary environments, they need to be paranoid about those failure modes. Excuses aren't enough.
Have timeout
Decrement counter after successful load and parse
Check counter on startup. If it is like 3, maybe consider you are crashing