Unzip the archive with the password "test", it'll contain the file cctest (with a SHA256 hash value of A99FCE43F5CD5D48169CE085A0469F260FD635225E591EF7B5D962532AF6AB1F)
Ensure the "Known malware" blocking and isolation policy is set to [Runs or is running → Terminate Process]
Also ensure the VM has access to the Carbon Black cloud
Attempt to run the file cctest
Upon execution detection, the Linux terminal should show the message “Operation not permitted” or “Killed” or some similar message indicating that the banned application will not be executed on further attempts
The console will show "A known virus was detected running", and on a separate event, "The application cctest was identified as known malware. A Terminate Policy Action was applied"
The console will also show "Deny Policy Action was applied" on subsequent access attempts