IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Cb Defense: Potentially Unwanted Program (PUP) Allowed to Run

Cb Defense: Potentially Unwanted Program (PUP) Allowed to Run

Environment

  • Cb Defense Sensor: 3.2.x
  • Blocking and Isolation Policy for "Adware or PUP" is set to terminate upon "Perform ransomware-like behavior" rule

Symptoms

Logs show a Potentially Unwanted Program (PUP) was allowed to execute the function "CreateWindowExW"

Cause

CreateWindowExW is not one of the APIs the sensor checks for ransomware behavior, so this was allowable under the policy.

Resolution

  1. From the main Dashboard screen, access Enforce > Policies
  2. Select policy where "Adware or PUP" rule is set to terminate upon "Perform ransomware-like behavior"
  3. Change policy  to "Runs or is running" > "Terminate process"

Additional Notes

  • Carbon Black recommends testing policy changes on a test group/environment prior to deployment into production.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-17-2018
Views:
1316
Contributors