Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: How to Test Malware Detection On The Linux Platform

Carbon Black Cloud: How to Test Malware Detection On The Linux Platform

Environment

  • Carbon Black Cloud Linux Sensor: 2.11.x and higher
  • Linux: All Supported Versions

Objective

How to test malware detection and blocking enforcement on the Linux platform? 

Resolution

  1. Download the test file here
  2. Unzip the archive with the password "test", it'll contain the file cctest (with a SHA256 hash value of A99FCE43F5CD5D48169CE085A0469F260FD635225E591EF7B5D962532AF6AB1F)
  3. Ensure the "Known malware" blocking and isolation policy is set to [Runs or is running → Terminate Process]
  4. Also ensure the VM has access to the Carbon Black cloud
  5. Attempt to run the file cctest
  6. Upon execution detection, the Linux terminal should show the message “Operation not permitted” or “Killed” or some similar message indicating that the banned application will not be executed on further attempts
  7. The console will show "A known virus was detected running", and on a separate event, "The application cctest was identified as known malware.  A Terminate Policy Action was applied"
  8. The console will also show "Deny Policy Action was applied" on subsequent access attempts

Additional Notes

When the sensor in bypass, and if marked as executable at the OS level, the file should generate the message "Carbon Black© test, execution allowed".

The test file may be allowed to run if the endpoint does not have access to the cloud, once access is restored the reputation should be updated and the test file blocked as described above.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎07-28-2021
Views:
4312
Contributors