Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CB Protection: Why are existing HTA Files Approved on Upgrade to 8.1.4

CB Protection: Why are existing HTA Files Approved on Upgrade to 8.1.4

Environment

  • CB Protection Server: 8.1.4
  • CB Protection Agent: All Supported Versions

Question

Why after upgrading to 8.1.4 are existing HTA files marked as interesting and approved?

Answer

8.1.4 contains a new default script rule that is enabled on upgrades or new installations; This pushes a CC3 to the devices to find all the existing HTA files and locally approve them. 

Additional Notes

  • Any new HTA files that are generated or downloaded will be considered unapproved. 
  • Further information can be found in the 8.1.4 Release Notes

Related Content


Labels (1)
Tags (3)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2699
Contributors