IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: How To Allow Specific Users to Execute a Banned File

App Control: How To Allow Specific Users to Execute a Banned File

Environment

App Control Console:  All versions (was CB Protection)

Objective

This article will demonstrate how to craft a rule to allow specific users or groups to execute a banned file.

Resolution

It’s important to understand how a rule could potentially impact endpoint security prior to creating it in your App Control environment. If there are any questions please contact your account team so they can engage Professional Services before continuing. 

To allow banned file execution please walk through the following steps. 
  1. Navigate to Rules > Software Rules > Custom 
  2. Click 'Add Custom Rule'
  3. Create a Name
  4. Select Execution Control 
  5. Complete the Path or File, Process, and User or Group sections
  6. Make the rule as targeted as possible
  7. Rank the rule higher than the rule used to ban the file in question

Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎04-21-2021
Views:
1910