IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Protection: How To Block Known Malicious Files

CB Protection: How To Block Known Malicious Files

Environment

CB Protection Server: All Supported Versions

Objective

This article details two ways to block or ban files deemed malicious by reputation.

Resolution

1. In the CB Protection Console, navigate to Rules > Event Rules
Using the 'Malicious file detected' subtype will allow files known to be malicious to trigger the rule, which can be set to ban immediately, or report.

2. In Rules > Software Rules > Reputation tab, set thresholds to block files based on their CDC score.

Additional Notes

Clicking the black and white question mark in the upper right hand of the console will show a help menu contextual to the page currently loaded in the CB Protection console.

Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎03-26-2019
Views:
817
Contributors