Neither Tavis Ormanady's, Patrick's or the C++ professional's posts go into detail of how the bug works in CrowdStrike's Falcon sensor. All of it just pointing to a debugger/disassembly output and casting some predictions. (for me personally I trust Tavis' analysis because ... well its his field of specialty over the last decade or so).<p>But still, none of the tweets mentioned come close to even explaining the issue (as in why the .sys channel update file being filled with zeros leading the CS driver to actually crash, the actual bug in the driver and what how it would've functioned normally before the faulty .sys file was pushed).<p>for reference, to see the whole tweet without twitter account:<p><a href="https://twitter-thread.com/t/1814762302337654829" rel="nofollow">https://twitter-thread.com/t/1814762302337654829</a>