Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: What are the Mac TamperBehavior events?

Carbon Black Cloud: What are the Mac TamperBehavior events?

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Sensor: 3.3.3.35 and Higher
  • Apple macOS: All Supported Versions

Question

What do the different Tamper Behavior items mean coming from the Mac Sensors?

Answer

Tamper BehaviorAttempted Activity
“TamperBehavior1”attempt to disable the sensor services with launchd
“TamperBehavior2"attempt to disable / unload KEXT driver
“TamperBehavior3”attempt to terminate/kill sensor processes
“TamperBehavior4"attempt for in memory attacks / memory scraping / code injection
“TamperBehavior11”attempt to modify / delete sensor files

Additional Notes

Other tamper protection violations will be blocked, but are not currently reported to Console. This may change in future Sensor versions.

Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎01-17-2020
Views:
1236
Contributors