Windows CrowdStrike Agent Registry Key Removal — Detection Rule

Detects delete events on the CrowdStrike registry keys. These keys are removed as part of the agent uninstallation process. This activity should only occur during planned events and any instances outside that should be evaluated for malicious activity such as CVE-2022-44721.

Read the full analysis on IntelFusions