After CrowdStrike’s July 19, 2024 outage, President Michael Sentonas accused some competitors of using the crisis to frighten customers and sell alternatives, calling their messaging “shady” and “misguided.” His complaint had a commercial basis: rivals had an obvious opportunity to win accounts. But the criticism also raised a legitimate engineering question about how endpoint-security software is built, updated and recovered.
The fairest conclusion is mixed. CrowdStrike was right to reject claims that another vendor could guarantee immunity from a major software failure. Competitors were right to ask whether privileged code, release controls and recovery processes created an unnecessarily large blast radius. Neither side established that its own architecture was categorically safer.
What failed on July 19, 2024
CrowdStrike said a defective Falcon content update for Windows hosts caused systems to crash, commonly producing blue screens. It said the incident was not a cyberattack. The described update did not affect Mac or Linux hosts. CrowdStrike’s account and root-cause analysis are available in its customer statement and root-cause analysis.
Microsoft estimated that about 8.5 million Windows devices—less than 1% of all Windows devices—were affected. That is Microsoft’s estimate, not an independently audited count. Microsoft described cooperation with CrowdStrike to help customers recover, while noting that the event was not a Microsoft-originated incident. The disruption reached airlines, hospitals, broadcasters, banks, retailers, government services and other organizations across the world. Microsoft’s July 20 account provides its scope estimate and remediation context.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
The incident therefore combined a software-quality and change-management failure with unusually broad operational consequences. The update reached many Windows systems before the defective content could be stopped or rolled back, leaving customers to repair machines at fleet scale.
What Michael Sentonas meant by “shady commentary”
In August 2024 comments reported by the Financial Times and reproduced by Ars Technica, Sentonas said rivals were using the outage to scare customers and promote competing products. He argued that no security vendor could technically promise that its software would never cause a comparable event, and said CrowdStrike expected to emerge more battle-tested after adding safeguards.
Sentonas also defended Falcon’s kernel presence. CrowdStrike’s product rationale is that kernel access can provide broad visibility, rapid response and protection for the security software itself. Those are CrowdStrike’s stated benefits, not an independently verified finding that kernel operation is superior in every environment. The remarks and competitor responses are reported at Ars Technica.
What competitors said
| Company | Reported position | What the statement does—and does not—prove |
|---|---|---|
| SentinelOne | CEO Tomer Weingarten described the incident as reflecting “bad design decisions” and “risky architecture.” CISO Alex Stamos reportedly warned against saying any security product could have caused an outage of this scale. | These are competitor assessments reported through secondary coverage, not an independent post-incident finding or proof that SentinelOne cannot suffer a serious failure. |
| Trellix | CEO Bryan Palma emphasized a more conservative product philosophy and suggested it reduced the likelihood of a comparable event. | A different architecture or release process may reduce particular risks; it is not evidence of immunity from a major software or update failure. |
| Palo Alto Networks | CEO Nikesh Arora said the outage prompted some customers to consider alternatives and described that interest as an opportunity. | This demonstrates market impact and a sales opportunity, not that Cortex products are technically safer in every relevant respect. |
| Microsoft | Microsoft focused its July 20 statement on cooperation and customer remediation. | Microsoft’s operational response should not be read as an endorsement of CrowdStrike’s architecture. Microsoft also competes in endpoint security through Defender. |
Was the criticism technically fair?
The legitimate concern: failure radius
Security software with deep operating-system privileges can inspect and intervene in more activity. If a defective component operates at that level, however, the consequences can extend beyond a single application and destabilize the host. The July event supports scrutiny of how much code runs in the kernel, how content is separated from executable sensor code, and how quickly a bad release can be halted.
It does not establish that all kernel-based designs are inherently unsafe, or that a user-space design cannot cause a serious outage. The incident involved a defective update and release-control failure; kernel access may have increased the blast radius but is not a complete causal explanation.
The trade-offs buyers should separate
- Architecture risk: the damage if a privileged component fails.
- Release-process risk: the chance that an unfit update reaches production.
- Operational risk: the speed and practicality of fleet recovery.
- Security risk: whether reducing privilege or delaying updates weakens detection and response.
- Business-continuity risk: the amount of the organization’s estate and security stack dependent on one supplier.
The useful question is not simply “kernel or user space?” It is what functionality is placed in the kernel, how code and configuration are validated, whether a bad content file can crash the sensor or operating system, and whether administrators can pause, revoke and recover safely.
What CrowdStrike said it would change
CrowdStrike committed to additional validation checks, more extensive testing, stronger release safeguards and staggered or phased delivery of Falcon content updates. Its root-cause material describes these as remedial process changes. They should be treated as commitments to reduce recurrence risk, not proof that risk has been eliminated or that every control was fully implemented by a particular later date. CrowdStrike’s RCA is the relevant first-party source.
Was this “ambulance chasing”?
The phrase means using another company’s crisis to market one’s own product. Competitive criticism is not automatically improper: customers needed to hear how vendors differed on privilege, testing, rollout and recovery. It becomes misleading when a vendor implies it could never experience a comparable failure, treats one outage as proof that an entire category is unsafe, omits trade-offs or uses technically incomplete comparisons.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteForrester analyst Allie Mellen reportedly said several vendors were using the outage to sell products and that the security industry generally disapproved of that opportunism. The commercial incentives were clear. Ars Technica, citing Financial Times reporting, said SentinelOne shares rose 19% over the month after the outage, Palo Alto Networks rose 13%, and CrowdStrike lost nearly a quarter of its market value during that period. These are historical market snapshots, not current performance or proof of product quality. The cited report contains the figures.
TechCrunch likewise reported that rivals stood to benefit while cautioning against reducing the event to a simple winner-and-loser story. TechCrunch’s contemporaneous coverage provides that market context.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What customers should test before choosing or switching
A vendor change is not an instant resilience solution. Migration can take weeks or months, temporarily reduce detection coverage and introduce deployment, licensing and compatibility risks. Running two kernel-level agents during a transition can create conflicts or unsupported configurations; obtain written validation from both vendors before attempting it. Removing an agent during an active incident can also create an unprotected window.
Release and update governance
- Are content updates separated from executable sensor updates?
- What automated, manual and internal-canary tests run before release?
- Can customers control deployment rings or cohorts?
- Is there a pause or kill switch, and how quickly can the vendor revoke a bad update?
- Can rollback work when an endpoint cannot boot normally?
Privilege and failure behavior
- Which functions run in the kernel and which remain in user space?
- Is detection logic isolated from system-critical code?
- Does the agent fail open or fail closed, and can it disable or isolate itself safely?
- How does it coexist with operating-system security features and specialized hardware?
Recovery and support
- Are offline recovery media and boot-repair procedures documented and tested?
- Can administrators remediate machines remotely at scale?
- Is emergency support staffed for the organization’s time zones?
- Can recovery proceed without the endpoint agent running?
- Are emergency accounts, out-of-band management and offline backups available?
Contracts and concentration
- Review liability caps, service commitments, outage-notification terms, audit rights and business-continuity obligations.
- Confirm incident cooperation, data-export and termination rights, migration assistance and any cyber-insurance requirements.
- Map dependence on one supplier across endpoint prevention, EDR telemetry, identity, cloud workload, email security, managed detection and incident response.
Healthcare, aviation, manufacturing, retail and other critical environments need manual fallback and offline recovery plans, not merely a new agent. Legacy Windows systems, managed-service deployments, cloud workloads, international support coverage and regulatory requirements may each impose different constraints.
Best Value
What the dispute means for investors and technology buyers
The outage exposed both operational and concentration risk. A competitor’s rising share price or a vendor’s customer-interest statement shows market reaction, not technical superiority. Microsoft’s assistance shows why ecosystem cooperation matters, but Microsoft’s competing Defender business means it is not a neutral market observer.
Organizations should demand evidence of release governance and recovery rather than rely on slogans such as “kernel-free,” “conservative” or “autonomous.” Replacing CrowdStrike with another dominant platform may simply move concentration risk unless deployment rings, rollback, offline recovery and contractual accountability improve as well.
Bottom line
CrowdStrike’s objection to sweeping, fear-based competitor claims was justified, but the outage gave customers a legitimate reason to examine privileged code, update validation, staged deployment and recovery. The evidence supports a trade-off analysis—not “kernel bad, user space good,” and not a guarantee from any vendor. The prudent response is tested resilience and accountable governance, whether an organization stays with CrowdStrike or evaluates SentinelOne, Trellix, Palo Alto Networks, Microsoft Defender or another provider.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




