IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Cb Defense: Why Does My IT Tool / Certificate Whitelisted Application Get Blocked Initially?

Cb Defense: Why Does My IT Tool / Certificate Whitelisted Application Get Blocked Initially?

Environment

  • Cb Defense Web Console: All Versions
  • Cb Defense Sensor: 2.0 and higher
  • Microsoft Windows: all supported versions

Question

I have created an IT Tool / Certificate whitelist for a known trusted application. Why does the application sometimes get blocked initially, but when I try to run it again it runs fine?

Answer

  • There are some instances where the certificate check of an application can be delayed because the application cannot be accessed. As the application cannot be verified, it will have an effective reputation of "not_listed" or "unknown" applied. If there is a specific policy rule in place to block "not_listed" or "unknown" applications the block rule will deny or terminate the action.
  • In these cases where the file could not be accessed the sensor will continue trying to validate the application until a positive identification can be made. This is why a second run of the same application is usually successful.

Additional Notes

  • If the application is known and trusted, a hash whitelist will bypass the certificate check.
  • If the application generates multiple files a bypass rule to allow and log may be appropriate.

Related Content

Cb Defense: Why isn't the reputation updated to LOCAL WHITE?

Cb Defense: Reputation Priority

Cb Defense: How to Utilize Certs Whitelist Feature

Cb Defense: How to Utilize IT Tools Whitelist Feature

Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-09-2018
Views:
1239
Contributors