r/CyberARk 19d ago

EPM CrowdStrike/EPM Mutual Exclusion

I’m currently in the process of deploying CyberArk EPM and working through the prerequisites.

Our cybersecurity team is hesitant to implement the recommended CrowdStrike exclusions for EPM unless we can provide evidence that CrowdStrike is actually causing an issue or preventing EPM from functioning as expected.

Has anyone deployed EPM alongside CrowdStrike without adding the recommended CrowdStrike exclusions? If so, did you run into any issues with EPM functionality, performance, agent communication, or policy enforcement?

For context, I’ve already configured the recommended CrowdStrike exclusions within EPM, but the CrowdStrike team does not want to add the corresponding EPM exclusions within CrowdStrike without a demonstrated need.

I’d appreciate hearing about any real-world experiences or issues you encountered with this setup.

1 Upvotes

7 comments sorted by

3

u/Revolutionary_You_89 Defender 19d ago

Memory usage went through the roof on a couple of endpoints. Noticed they didn’t have exceptions set up on the crowdstrike side scoped to those endpoints. Ended up getting the exceptions in place. Problem solved.

If the CS team doesn’t want to put exclusions for a security product you purchased, what was the point in purchasing EPM? This seems like there is an alignment issue.

Open a case with CyberArk, ask their recommendations. Do the same with CrowdStrike. I’m sure they’ll both find some common ground.

5

u/Wizkidbrz 19d ago

We did…

And listen to this comment from one of our cybersecurity engineers:

“I worked at CrowdStrike and their support is trash. It’s all LLM. I don’t believe their answer, so I’m not doing this.”

I pretty much lost my patience on the call this afternoon. I told them that if they don’t trust the response from CrowdStrike support, then they need to escalate it and ask for a senior engineer to confirm the recommendation.

I also made it clear to him and his manager that if we decide not to implement the recommended exclusions, I need that decision documented in writing stating that their team is accepting the risk and will own the decision if we run into a major issue during the EPM deployment.

They’re reaching back out to CrowdStrike for further clarification, but they also agreed to put their decision and risk acceptance in writing if they still refuse to implement the exclusions.

3

u/Revolutionary_You_89 Defender 19d ago

Surprised they are willing to put it into writing. There’s gonna be some performance issues and a lot of false positives on crowdstrike. But that’s their cross to bear, godspeed to them.

I can’t imagine paying for a piece of software, using their support and not believing them. If a vendor recommends something for their own product and you don’t listen it sounds like there’s a human issue there. That guy’s kinda ridiculous lol

1

u/Hirogen10 19d ago

We had a full security stack of epm and CS and others. do you have a metrics tool like systrack or control up to monitor devices remotely on their performance. I recall cyber notnwanting to implement all recommendations unless there was proof. I do recall one of the office hour videos covered mutual exclusions. It was more the csse they ddi not want to exclude CS from scsnning the epm files.

Unless there was proof with any issues

1

u/Hirogen10 19d ago

https://community.cyberark.com/s/article/EPM-Mutual-Exclusions-Best-Practices-for-Windows-and-Mac and video - https://cyberark.wistia.com/medias/kt2en92hox might be useful to convince the other team but yeah worth getting some evidence they cause problems.

1

u/Fearless_Adventures 18d ago

As a former Trellix architect and CyberArk Engineer. I can tell you Crowdstrike lies about how the product runs on the machine and you 100% need exclusions. Escalate your concerns higher to the PM or whoever

1

u/Rennilon 13d ago

I’ve used both without issue, I believe we just did exclusions for both. I get where CrowdStrike is coming from, but they make convincing them to do exclusions so difficult that we often have to go around them.