Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Is autorun.inf automatically blocked from execution on removable media?

Carbon Black Cloud: Is autorun.inf automatically blocked from execution on removable media?

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Windows Sensor: All Supported Versions
  • Microsoft Windows: All Supported Versions

Question

Is autorun.inf automatically blocked from execution on removable media?

Answer

We do not block any file from running by default unless it has a malicious reputation and the applicable policies are in place. However you can create the following Blocking and Isolation policy rule to block files of this type by default:

Application(s) at path:
**\autorun.inf
Runs or is running → Terminate

Once the rule has been saved, please allow time for the device to check-in and download the updated policy rules before testing.

Additional Notes

Starting in Sensor version 3.5, a new feature has been added which will find all malicious services associated with Known Malware hashes and puts them in a disabled state.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-21-2020
Views:
1361
Contributors