Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: How to verify Bypass Mode from the Console

Carbon Black Cloud: How to verify Bypass Mode from the Console

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Sensor: All Versions
  • Microsoft Windows: All Versions
  • Apple MacOS: All Versions

Objective

How to verify Bypass Mode from the Carbon Black Cloud Console

Resolution

Endpoints Page

In order for Sensor Bypass actions to take effect, the sensor must check-in to the Carbon Black Cloud backend. Typically this occurs every 5-10 minutes.
  1. Search for the device where Bypass was Enabled. Status can be changed to "All" to widen the search scope or "Bypass" to narrows the search scope.
  2. Under Device Last Check-In there will be one of two bypass descriptions:

Inbox Page

Triggered: Admin requested Bypass via Console
Sent to Sensor: Sensor checked into Console, received Bypass hint
  • Bypass Enabled
    REQUEST TIME
    DEVICESUBTYPESTATUSREQUESTED BYACTION
    Date/Time{InstalledBy} / {DeviceName}BypassTriggered{AdminEmail}On
    Date/Time{InstalledBy} / {DeviceName}BypassSent to Sensor{AdminEmail}On
  • Bypass Disabled
    REQUEST TIME
    DEVICESUBTYPESTATUSREQUESTED BYACTION
    Date/Time{InstalledBy} / {DeviceName}BypassTriggered{AdminEmail}Off
    Date/Time{InstalledBy} / {DeviceName}BypassSent to Sensor{AdminEmail}Off

Additional Notes

Sensor UI Taskbar Icon Meanings
Pre 3.5Post 3.5Sensor Mode
pre-3.5 Activepost-3.5 ActiveActive
pre-3.5 Bypasspost-3.5 BypassBypass
pre-3.5 Quarantinepost-3.5 QuarantineQuarantine
The Sensor Bypass (Admin Action) status is currently used as the default reason if there is a driver failure as well. So this status does not always mean that an Admin initiated the bypass. There is an enhancement request to enable additional bypass reasons here.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
5941
Contributors