Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CB Defense: How to verify Bypass Mode from the CB Defense PSC Web Console

CB Defense: How to verify Bypass Mode from the CB Defense PSC Web Console

Environment

  • CB Defense PSC Web Console: All Versions
  • CB Defense PSC Sensor: All Versions
  • Microsoft Windows: All Versions
  • Apple MacOS: All Versions

Objective

How to verify Bypass Mode from the CB Defense PSC Web Console

Resolution

Endpoints Page

In order for Sensor Bypass actions to take effect, the sensor must check-in to the CB Defense backend. Typically this occurs every 5-10 minutes.
  1. Search for the device where Bypass was Enabled. Status can be changed to "All" to widen the search scope or "Bypass" to narrows the search scope.
  2. Under Device Last Check-In there will be one of two bypass descriptions:

Inbox Page

"bypass Sent to Sensor" means that the bypass request has been sent to the sensor and "bypass triggered" means that the sensor has received the request to put the sensor in or out of bypass
  • Enable Bypass
00:00:00 am\pm <MM> <DD>, <YY> <device hostname>\<user> bypass Sent to Sensor <admin username> On 
00:00:00 am\pm <MM> <DD>, <YY> <device hostname>\<user> bypass triggered <admin username> On
  • Disable Bypass 
00:00:00 am\pm <MM> <DD>, <YY> <device hostname>\<user> bypass Sent to Sensor <admin username> Off 
00:00:00 am\pm <MM> <DD>, <YY> <device hostname>\<user> bypass triggered <admin username> Off



 

Additional Notes

Sensor UI Taskbar Icon Meanings
  • User-added image Sensor is in Active mode
  • User-added image Sensor is in Bypass mode
  • User-added imageSensor is in Quarantine mode

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎06-20-2019
Views:
1238
Contributors