Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Are Sensor Tamper Protection Events Reported in the Console?

Carbon Black Cloud: Are Sensor Tamper Protection Events Reported in the Console?

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Sensor: All Supported Versions

Question

Are attempts to tamper with the Sensor (e.g. delete Sensor files, stop services, etc.) reported in the Console as Events or Alerts?

Answer

No, Tamper Protection is silently enforced and does not generate any Alerts or Events in the Console.

Additional Notes

  • Alarms related to tamper attempts are stored locally by the Sensor in C:\ProgramData\CarbonBlack\Logs\SensorAlarms.log, though details are limited to the tampering process and target file.
  • Running third-party security applications (e.g. antivirus, real-time scanner, vulnerability scanner, etc.) concurrently with the Sensor without proper Exclusions can trigger Tamper Protection alarms and cause unexpected blocks or interoperability/performance issues.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎06-08-2023
Views:
358
Contributors