IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?

Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?

Environment

  • Carbon Black Cloud Console: All Versions

Question

Can an administator utilize policy rules to block network based activity?

Answer

Yes, you can create a policy rule with the "Communicates over the network" Operation Attempt, using either "Deny operation" or "Terminate process" to block the behavior for specific applications, filenames or paths.

Additional Notes

  • Network rules cannot be made more granular, meaning that specific IP ranges, URLS, etc. cannot be leveraged in policy rules.
  • The "Communicates over the network" Operation Attempt involves any attempted network access, so applications that have been blocked via policy rules will not be able to connect at all.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-08-2020
Views:
4275
Contributors