IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Protection: How To Enable Windows Installer Embedded File Protection Using Custom Rules

CB Protection: How To Enable Windows Installer Embedded File Protection Using Custom Rules

Environment

  • CB Protection Server: 8.0.0 Patch 3 - 8.0.0 Patch 6

Objective

The Windows Installer Embedded File Protection Rapid Config is available to customers running 8.0.0 patch 7 and higher. For customers unable to upgrade to patch 7 at this time, the solution below can be used to import custom rules for the same functionality.

Resolution

  1. Download the .rules from this link:  https://sflinks.carbonblack.com/CkgUvNrDlmo/
  2. In the CB Protection Console, navigate to Rules > Software Rules > Custom
  3. Click on the Import Rules button
  4. Choose the file downloaded in the first step
  5. Check the box in front of the rule named "Report execution of jar files identified as Installers"
  6. Click on Import
  7. After importing, the rule will appear at the top of the list.
  8. Make sure to enable the rule here so it will take effect

Additional Notes

Information on the Rapid Config can be found here:
Windows Installer Embedded File Protection Rapid Config

The post from Threat Research can be found here:
TAU-TIN - Java Embedded MSI files

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-14-2019
Views:
748
Contributors