IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: How to Enable and Configure Process Hollowing Protection Rapid Config

App Control: How to Enable and Configure Process Hollowing Protection Rapid Config

Environment

  • App Control Agent: 8.9.0 or Higher 
  • App Control Console: All Supported Versions
  • Rules Installer: 1.20 or Higher
  • Microsoft Windows: All Supported Versions

Objective

To enable and configure the Rapid Config for Process Hollowing Protection.

Resolution

  1. Log in to the Console and navigate to Rules > Software Rules > Rapid Configs.
  2. Click View Details (pencil icon) for Process Hollowing Protection.
  3. Change the Status to Enabled.
  4. Fill in the required fields
    • Report or Block Process Hollowing Applications
    • Applications Allowed To Hollow Processes
  5. Click Save & Exit

Additional Notes

  • It's recommended to start this Rapid Config in "Report" to monitor for false positives.
  • Trusted applications can be added to the list for "Applications Allowed To Hollow Processes."
  • Wildcards are supported in this field. 
    Example:
    C:\Program Files (x86)\Acme Account\AcmeAcct.exe
    or
    *AcmeAcct.exe

 

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎04-10-2024
Views:
68