Environment
- App Control Server: 8.6.0 and Higher
- App Control Agent: 8.6.0
- Microsoft Windows: All Supported Versions
Symptoms
Svchost.exe blocking executable from executing, despite custom rules in place to allow executions.
Cause
When svchost.exe creates a process, there is no process create notification. As a result, no process-create event fires. Another event is then received that basically looks like a file-execute event for the application but is running under the newly created process. This event does not have the correct process and the process that it does have has not been run through the rules and does not have classifications.
Resolution
This will be resolved in Windows Agent 8.7.0.
Additional Notes
There is no workaround for this issue at this time.
Related Content