IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Occasionally an executable that should be blocked by a policy is allowed to run.

Carbon Black Cloud: Occasionally an executable that should be blocked by a policy is allowed to run.

Environment

  • Carbon Black Cloud Sensor: All versions
  • Carbon Black Cloud Server: All versions
  • Operating Systems: All versions

Symptoms

The issue is intermittent and can occur during boot time or any other time where the sensor service is in the middle of starting up or restarting.

 

Cause

The CBC sensor is in the middle of its startup process and is an "unstable" (not completely functional) state.

Resolution

This is normal, expected behavior. Occasionally another service may start ahead of the CBC sensor and not be blocked/denied/terminated until the sensor is fully up and running.
One obvious solution is to delete the undesired executable file from the machine since it's meant to be blocked from running.
Another possible workaround is to delay the Windows service for that executable to be invoked until the CBC sensor is fully up.
For example, with MS Windows OS's services can be delayed at boot time as so: Delay start programs

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-25-2023
Views:
303
Contributors