IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Allow Deleted Files for Analysis

App Control: Allow Deleted Files for Analysis

Environment

  • App Control (formerly CB Protection) Agent: All Supported Versions

Symptoms

This is one of the agent configuration properties we recommend for unanalyzed file blocks. The most common symptom of that issue is a block occurring with no file hash present in the event in the console. 
 

Cause

Unanalyzed file blocks occur when the agent does not have time to properly analyze a file. This is typically caused by latency on the endpoint; network or third party antivirus being the most common root cause.
 

Resolution

Configuration Property Listed Below: 
  1. Property Name: Allow Deleted Files for Analysis
  2. Host ID: 0 For All
  3. Value: kernelAllowDeletedFiles=1
  4. Status: Enabled

Additional Notes

  • To add an agent config follow this article
  • If an abmiss check found that the file does not exist (has been deleted before the agent could hash the file) and the operation is an open or create of a script file, if kernelAllowDeletedFiles is set to true (1), the driver will allow the operation and let the OS handle the missing file situation.
    • Note that the driver considers an “open” operation on a script file as an execute.
    • Security Risk: Low
    • Operational Risk: Low to none.

Related Content


Labels (1)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎12-17-2018
Views:
1792
Contributors