IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Application blocks due to svchost.exe, despite custom rules in place to allow

App Control: Application blocks due to svchost.exe, despite custom rules in place to allow

Environment

  • App Control Server: 8.6.0 and Higher
  • App Control Agent: 8.6.0
  • Microsoft Windows: All Supported Versions

Symptoms

Svchost.exe blocking executable from executing, despite custom rules in place to allow executions.

Cause

When svchost.exe creates a process, there is no process create notification. As a result, no process-create event fires. Another event is then received that basically looks like a file-execute event for the application but is running under the newly created process. This event does not have the correct process and the process that it does have has not been run through the rules and does not have classifications.

Resolution

This will be resolved in Windows Agent 8.7.0.

Additional Notes

There is no workaround for this issue at this time.

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-07-2021
Views:
1039
Contributors