---
title: Detecting Fake CrowdStrike Domains using Stamus Security Platform
description: Learn how the recent CrowdStrike outage has led to the registration of malicious lookalike domains and how to protect your organization with Stamus Networks' threat intelligence and security platform.
image: https://www.stamus-networks.com/hubfs/Stamus-2024-Crowdstrike-Incident-Graphic-1.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Detecting Fake CrowdStrike Domains using Stamus Security Platform

 by [Stamus Networks Team](https://www.stamus-networks.com/blog/author/stamus-networks-team) | Jul 22, 2024 | [Network Detection and Response](https://www.stamus-networks.com/blog/tag/network-detection-and-response), [Endpoint Detection](https://www.stamus-networks.com/blog/tag/endpoint-detection), [Network Security Monitoring](https://www.stamus-networks.com/blog/tag/network-security-monitoring), [Stamus Security Platform](https://www.stamus-networks.com/blog/tag/stamus-security-platform), [Threat intelligence](https://www.stamus-networks.com/blog/tag/threat-intelligence)

![](https://www.stamus-networks.com/hubfs/Stamus-2024-Crowdstrike-Incident-Graphic-1.jpg)

The [recent global outage](https://www.cnn.com/business/live-news/global-outage-intl-hnk/index.html) caused by an [update to CrowdStrike Falcon](https://www.crowdstrike.com/blog/statement-on-windows-sensor-update/), CrowdStrike's endpoint detection and response (EDR) system has resulted in the registration of numerous lookalike domains. We suspect that many of these were registered by bad actors with the intention of using them for scams and/or malicious phishing campaigns.

Many lookalike CrowdStrike domains have been registered in the past 3 days.  

Due to the suspicious nature of these newly registered domains, we recommend organizations monitor network activity to determine if any of their systems are communicating with these domains.

As these domains are created, Stamus Networks is adding these domains to the [Newly Registered Domain (NRD) ](https://www.stamus-networks.com/blog/threat-hunting-for-unknown-actors-threats-using-nrd-and-sightings?hsLang=en)threat intelligence feed. 

Stamus Security Platform provides for detection and escalation of Newly Registered Domains. Those are available by default to any Stamus Customer. Access the online documentation to verify that you have this feed enabled. 

If you are not a current Stamus Security Platform user, the Newly Registered Domain (NRD) threat intelligence feeds are available [here](https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed?hsCtaTracking=fac2c07b-670f-49ba-a672-0d2a81c24849%7Cc64d7dfb-0ee4-485a-8b0c-e38d65c961cc&hsLang=en#form). All six NRD feeds are free and optimized for SELKS and Suricata 7 users. To learn more about NRD threat intelligence, read our blog post "[Introducing Open NRD: Newly Registered Domain Threat Intel Feeds for Suricata](https://www.stamus-networks.com/blog/introducing-open-nrd?hsLang=en)". 

Please find below examples of the recently registered suspicious (mostly with malicious intent) CrowdStrike-related domains: 

crowdstrike24[. ]site

crowdstrike24[. ]online

thecrowdstrike[. ]com

thecrowdstrike[. ]com

thecrowdstrike[. ]com

crowdstrike[. ]blue

crowdstrike[. ]bot

crowdstrike[. ]cam

crowdstrike[. ]fail

crowdstrike[. ]help

crowdstrikeoutage[. ]info

crowdstrikedown[. ]site

crowdstrikereport[. ]com

crowdstrike-bluescreen[. ]com

crowdstrike-helpdesk[. ]com

crowdstrike-out[. ]com

crowdstrike0day[. ]com

crowdstrikebluescreen[. ]com

crowdstrikebsod[. ]com

crowdstrikebug[. ]com

crowdstrikeclaim[. ]com

crowdstrikeclaims[. ]com

crowdstrikeclassaction[. ]com

crowdstrikedoomsday[. ]com

crowdstrikedown[. ]com

crowdstrikefail[. ]com

crowdstrikefixer[. ]com

crowdstrikeglitch[. ]com

crowdstrikelawsuit[. ]com

crowdstrikeold[. ]com

crowdstrikeoops[. ]com

crowdstrikeoopsie[. ]com

crowdstrikeout[. ]com

crowdstrikeoutage[. ]com

crowdstrikerecovery[. ]com

crowdstrikesucks[. ]com

crowdstrikesuporte[. ]com

crowdstriketoken[. ]com

crowdstrikeupdate[. ]com

crowdstrikewindowsoutage[. ]com

crowdstrikezeroday[. ]com

fix-crowdstrike[. ]com

fuckcrowdstrike[. ]com

fuckingcrowdstrike[. ]com

iscrowdstrikedown[. ]com

isitcrowdstrike[. ]com

microsoftcrowdstrike[. ]com

suportecrowdstrike[. ]com

whatiscrowdstrike[. ]com

crowdstrike[. ]feedback

crowdstrikehelp[. ]info

crowdstrikeplatform[. ]info

crowdstrikesupport[. ]info

crowdstrikerescue[. ]org

crowdstrikeyou[. ]xyz

crowdstrike-fix[. ]zip

crowdstrikefix[. ]zip

 

## **DETECTION AND ESCALATION**

Please follow the steps listed below in the Stamus Security Platform (SSP) “Hunt” interface.

### Create a Filter

NOTE: Portions of this are not applicable to the Stamus Probe Management license tier.

To create a filter:

1. 1. In Hunt, click on the magnifying icon next to any 

***Domain*** in  ***FQDN breakdown for HTTP, TLS and DNS*** ( Dashboard tab). 

1.  
2. 2. Example:

1.  
2. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXeV7y61fXnoja_pvDYJV6ZFFEp6hPvKrtYE-LyRJg3oEoKS6oRklytwSJ04p7BOa7UPQYzf23L1hMHOtE8YfhdhE9MeXwa0Htj8_2JjXjqsjUwlEj5dzcxZJdxbw6OGO8Vx4XIrWfMYp7Nu-Ma0pQ8eDDpu?key=YarN3QUIu-bkP1owKOFKJQ)
3.  
4.  
5. 3,  Click on the pencil/Edit icon on the resulting filter displayed as “Active Filters:”.
6.  
7. 4.  Type ****Crowdstrike**** or ****Falcon***** * (Not all will be related to Crowdstrike)
8.  
9. 5.  Select the checkbox “Wildcard view”
10.  
11. 6.  Click Save
12.  
13. 7.  The result should be identical as on the screenshot below:
14.  
15. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXfQcPftfpVuZoog_TCnbOCmhFLoaW-YYCpianEnraoYDLOmVuhCkWui8EtuKWECJ83RgEJweWcMKOA2E-0jgUfni3BcMGp69DREM1xKgcUs_93-u3PZ_acDTDIDUFJhAYWxTA7Cy--KhTiBlhhI4uyRRhI?key=YarN3QUIu-bkP1owKOFKJQ)
16.  
17. 8.  Add another filter for Newly Registered Domains 
18.  
19. 9.  From the drop down menu in Hunt, select Filter-> Message and type in “***NRD***”, click Save.
20.  
21. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXfazhRDJGxLu2_byxMvdbN0y86oTO8WEQEfK3pUphcfLo4U9ZkurYEknKNS91yW804Y6eI_-dhCK8qnRtdcj6hNKrJaETFKf6-gJ79ZxyTlQfs7rpxfYosPeOS16M8mT7bbwYtkH3fWe1RuKth8vft_Bfk7?key=YarN3QUIu-bkP1owKOFKJQ)
22.  
23. 10.  The resulting filter combination should be as follows

 

1. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXcvUqGyvrBMJ7gQBNeBi2iVvV2AgUM6NTaTDB68gdVSs62_uf6SKfXxsX_y44tsP8tZspNd6IVA-xRV29d5tC1W2yByTHM8AtMmaBUqUYTufmS-np49cW6_uKG0PtwEpaz88QxzoTL7zpMWXdHyfsq0lZyE?key=YarN3QUIu-bkP1owKOFKJQ)  
   11.  You are now ready to review the results and events in the Dashboard,Host Insights and Alert views.

 

### Save the Filter

NOTE: some items described here are not applicable to Stamus Probe Management license tier

The resulting filter can be saved by simply clicking on the “Save” link on the right-hand side of the “Active filter”.  Check “Shared” in the resulting dialog box if you want to make the filter available to all users. 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXf887Iuhjpudtrjlw7QBfNkOk9FUwrCXKVoDrHHMB-cM4NchBqYlAYnITXbioZ_x_8W-DiPXyCiCCkhczU97p7PhJgR59yPl8z4x1_OJKafdFWwWBFPnjAwOWZpW-kD6zW6Pf4VurZkn6N1sET2BS5gTTv0?key=YarN3QUIu-bkP1owKOFKJQ)

 

The newly created filter is now available in “Global Filter Sets” or “Private Filter Sets”

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXf7sJ9RgVVzCa3ZBTZ-Q8q3LRgJoQ74o5_nsBecR7GnSGDKHp6NimHUtFhSegVjyvO4T5lIT2yw7LBWIE6o0CtThxn0ecUk9cDVq4fcyuGef-JoPTq9Jma5U2dEsVM8AZP2d90sVavOECxcBYqV_xjeGwx4?key=YarN3QUIu-bkP1owKOFKJQ)

## Automated Escalation and RestAPI Notification

NOTE: Portions are not applicable to Stamus ND or Stamus Probe Management license tiers.

If needed, an automated escalation to a Declaration of Compromise (DoC) and webhooks is also possible, including from historical data.

For example, if it happened 24hrs or 7 days ago it will still be detected and escalated based on that custom filter.

To do so:

1. 1.  After creating your filter as above 
2.  
3. 2.  From the right-hand side drop down menu, *Policy Actions*, select “Create DoC events”.

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXdbD8LsfetvkaSukh8If-1h8q2A7mcf7aR1SL_a9vga8RryEerlM8tsdbZUWNb7dQxhTc5bZp8UFioBbf32Uv9aF1VKXVdgo30EhedhaDtToKIRpkP-RPG3P4g_f_I4Uw7zk-sbQtNKiCClNX_9TqqBe1QF?key=YarN3QUIu-bkP1owKOFKJQ)

1. 3.  Choose the plus (+) next to the Threat: Name
2. 4.  Fill in the Threat Name, Description, and Additional information.
3. 5.  Enter an Offender Key (i.e. src_ip)
4. 6.  Enter an Asset Key (i.e. dest_ip)
5. 7.  Leave Asset Type “IP”
6. 8.  Set a Kill Chain phase (i.e. Exploit)
7. 9.  Select “Generate DoC events from historical data”. [This will make sure historical events are also checked]
8. 10. If desired and webhooks are setup also select “Generate webhooks events from historical data”

The screenshot below shows the DoC event creation form:

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXeM7OvGVKHY_Sv4vIpvu5oWS_7x61ygg-DyKEDut5fkeQOiesOKjgG--HyEO1pxcKe4rk33FnnTazx18RhlNv_kUf7ZuCOfVCqRW4idvJ4a205rznsAdYOjg32YJWljU9OWD4xJkHFTAMGvp6-QFc_LbY_n?key=YarN3QUIu-bkP1owKOFKJQ)

## Automated Classification and Tagging

Auto Tagging all relevant events is also an option. This will allow for any logs (alerts or protocol transaction events related to the alerts) to have a “Relevant” tag inserted in the JSON logs:

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXds71B5y_dHbb7kNVAhwuZoXRbS3oc9TEKfeuN6z3zmiFtYLwYDHHsPjopgUXIq40JhJmt95P0AicXmC_iXPPe55qFvrLP4qokPRYDa18_mqB1y0WBBX8Yz_xO8_NJ-kMuN8welKtdrwLXqBVqeE9F3E56J?key=YarN3QUIu-bkP1owKOFKJQ)

 

To do so:

1. 1.  After creating your filter as above.
2.  
3. 2.  From the right-hand side drop down menu -  Policy Actions , Select “Tag”.
4.  
5. 3.  Add in an optional comment and select a ruleset.
6.  
7. 4.  Update the threat detection (upload button in the middle of the top bar on the Hunt page, on the left-hand side of History, Filter Sets )

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXfHZzvQWICgO_VrzgSpyYWk7WBDKUilnURrz_l6GstCkvj42tFO-F36IQPgNUilR1FhXcM9w_OFSBM7A7zuGMsbQTUJ8JcbeR2LkWiZL0OtsNdNBN7sWbb4CRhKRNuxbrxU3p9C8rbey2c6Kb0dtRdtQXGN?key=YarN3QUIu-bkP1owKOFKJQ)

## Export Data - SIEM / Elasticsearch / Kibana 

All data generated by Stamus ND/NDR, such as alerts, protocol transactions, sightings events or HostID information, may be exported and shared with any SIEM or SOAR system.

Over 4000 fields are available -- from domain requests, http user agents used, hostnames, usernames logged in --  to encrypted analysis including JA3/JA4/JA3S fingerprinting, TLS certificates and more.

Any query of the Stamus Networks data (protocol transaction or alert logs) can be exported via a regular JSON log query or visualization export.

 

### Example of Kibana query on alert events

To export CSV data from any info of the alerts you can open the SN-ALERT dashboard in Kibana, type in the filter:

 “alert.signature.keyword:*NRD* AND hostname_info.domain:*crowdstrike*”

then you can export a CSV of any visualization using “Inspect” (see example below):

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXdvyyPF0zGt75oEcIz612fUG8S2oGUgQ2EwAM73mJOMTLylY3i1BzdRhSaPyDTPpQeyLW2ZzWw4KOhoxZMmWUvmYAoNIzeLz0xQDoMfYkqEAkw-nCMx3b6Zu02qceh8t6A9CAMWOIZOb9ehgYy6JBOQcG40?key=YarN3QUIu-bkP1owKOFKJQ)

 

Click on “Inspect” in any visualization to export a CSV

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXdho635U6VUyVFNfhyq4kAxYZjjTbV9Uvq2nSgvKkmIIgDSlTLG2kceOOtE9buCJH9y2Igwbt8UHs8GIPJri13-HC9TjTtITREP1XGM2CZ0AGCO54_RUITIXg_fgqjHBhdEKBtU7NE2vy6uPEXec-cnw4fg?key=YarN3QUIu-bkP1owKOFKJQ)

## Export Data - Splunk

NOTE: portions of this section are not applicable to Stamus Probe Management.

Any query of the Stamus Networks data (protocol transaction or alert logs a like) in Splunk can be exported via a regular Splunk query or visualization export.

### **Example of a Splunk query on alert events**

 

event_type=alert "alert.signature"="*NRD*" "hostname_info.domain"="*crowdstrike*"

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXchY70zelYiV5Y4-Dt9tlMf4YzdyaF80boAv8IwTImWXzes7d7bY_nbh3Mzk0hQDBS1UBCR6O4tmVfONd2IDTdsRe3I-lOHkAb92fL4E18b-wcfTGVfDzpKzTAxfUPsxge8cffIZ3v-_gvJVvRc8OSAycGf?key=YarN3QUIu-bkP1owKOFKJQ)

 

### **Protocol transactions**

Stamus Networks provides a free Splunk app[https://splunkbase.splunk.com/app/5262](https://splunkbase.splunk.com/app/5262)  that can be used to do specific searches.

If there are any Splunk visualizations queries that have supporting information for the query that needs to be exported, it can be done so by the native Splunk export functionality.

 

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXc-R_vkT1vxXRP0QWE_BnXbm1mhlDnW7gOSh4yzme8EHRTRedQq62xSG0gxiGAC13AapktlBpnQc8Iwhmh3RLQ3SvVa1fozejnGT3fULCmsgsAsaDN_niCk4gL1v5ilC-azU0xJhnCVn_ZbUY4VHRU9glsf?key=YarN3QUIu-bkP1owKOFKJQ)

 

## Troubleshooting and Help

Please feel free to reach out to [support@stamus-networks.com](mailto:support@stamus-networks.com) with any questions or feedback.

To stay updated with new blog posts from Stamus Networks, also make sure to subscribe to the [Stamus Networks blog](https://www.stamus-networks.com/blog?hsLang=en), follow us on [Twitter](https://twitter.com/StamusN/), [LinkedIn](https://www.linkedin.com/company/stamus-networks/mycompany/), and [Facebook](https://www.facebook.com/StamusNetworks/), or join our [Discord](https://discord.com/invite/e6GQKGS5HN).

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-fake-crowdstrike-domains-using-stamus-security-platform%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-fake-crowdstrike-domains-using-stamus-security-platform%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-fake-crowdstrike-domains-using-stamus-security-platform%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-fake-crowdstrike-domains-using-stamus-security-platform%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-fake-crowdstrike-domains-using-stamus-security-platform%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fdetecting-fake-crowdstrike-domains-using-stamus-security-platform%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Stamus Networks Team](https://www.stamus-networks.com/hubfs/Stamus%202020/Images/icon-user.png)

#### Stamus Networks Team

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Stamus Networks: When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/hubfs/SN-Perimeter-Fails-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

### [When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

SentinelOne's "Edge Decay" research names the threat. Here's how network detection and response...

[![When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/hubfs/SN-EDR-Goes-Dark-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

### [When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

I've spent a significant part of my career participating in [NATO cyber defense exercises](https://www.stamus-networks.com/nato-ccdcoe-participation?hsLang=en) -...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.