Subscribe to the CyberThreatPOV Podcast

Tuning CrowdStrike: The Settings Most Companies Never Turn On | Episode 191

In this episode, Spencer and Tyler break down the CrowdStrike configuration settings that make a real difference in detecting and blocking attacks. Skip the sales talk—here’s what actually works based on thousands of hours of real-world testing.

  • Why default CrowdStrike settings often fall short for threat detection
  • The most critical prevention policies to enable for maximum visibility
  • How to leverage advanced features like Enhanced Exploitation and DLL Load Visibility
  • Using custom IOA rule groups to block common RMM tools and risky applications
  • Common misconfigurations and exclusion mistakes that undermine your EDR

The takeaway is simple: you’re paying real money for EDR, and default configurations aren’t giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.

Blog: https://offsec.blog
Work with us on an internal pen test: https://securit360.com

Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov

Work with Us: https://securit360.com

Follow Spencer on social ⬇
Spencer’s Links: https://spenceralessi.com