Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?

Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?

Environment

  • Carbon Black Cloud Console: All Versions

Question

Can an administator utilize policy rules to block network based activity?

Answer

Yes, you can create a policy rule with the "Communicates over the network" Operation Attempt, using either "Deny operation" or "Terminate process" to block the behavior for specific applications, filenames or paths.

Additional Notes

  • Network rules cannot be made more granular, meaning that specific IP ranges, URLS, etc. cannot be leveraged in policy rules.
  • The "Communicates over the network" Operation Attempt involves any attempted network access, so applications that have been blocked via policy rules will not be able to connect at all.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-08-2020
Views:
1829
Contributors