

unauthorized back door
Isn’t autoupdating software by definition an authorized backdoor by virtue of enabling it? The whole premise of CrowdStrike is continuous updates for attacks they see in the wild on other companies’ systems.
Also if anything CrowdStrike did the opposite of a backdoor since everyone needed to find their BitLocker keys to get back in and clean this mess. It locked out the front and back door.

It’ll tolerate a few hours no problem, mine’s been down for a bit over 24h and caught up fine.
I think it marks instances as down after 2-3 days, but I’m not sure if it’ll resume once it comes back up at this point. I think if your instance reaches out it might start pushing events again but it could also result in dropping the previous days.