IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to Enable Tamper Detection or Tamper Protection

EDR: How to Enable Tamper Detection or Tamper Protection

Environment

  • EDR Server: All Supported Versions

Objective

How is Tamper Detection or Tamper Protection enabled within EDR.

Resolution

  • To enable Tamper Detection or Tamper Protection
    1. Login to the EDR Console with a user having an Analyst role or greater.
    2. Enable 'Tamper Detection' or 'Tamper Protection' within the Sensor Group > Settings  > Advanced > Tamper Protection Level.
  • For Global Tamper Alerts enable the Cb Tamper Detection feed.
                Note: The Cb Tamper Detection feed alerts on all sensor groups regardless of Tamper settings.
  • For Tamper alerts per sensor group.
    1. Disable the Cb Tamper Detection feed.
    2. Create watchlist for specific sensor groups - example below:
      • group:"Sensor Group Name" AND tampered:true

         

Additional Notes

  • Tamper Protection prevents users, or local admins, from:
* Starting/stopping the CB Windows sensor services

* Modifying the C:\Windows\CarbonBlack files; Users have no access

* Modifying C:\Windows\system32\drivers\cbk7.sys and cbstream.sys

* Modifying C:\Program Files (x86)\CarbonBlack\CbEDRAMSI.dll

* Modifying C:\Program Files\CarbonBlack\CbEDRAMSI.dll

* Modifying CarbonBlack registry keys
  • “Tamper Protection” can be turned on / off via server UI.
  • “Tamper Protection” can be turned on / off directly from the endpoint should the CB EDR Windows sensor lose comms with the server ("CbEDRCLI.exe")

Related Content

More information on Tamper Detection can be found in the User Guide(s) Tamper Protection of Windows Sensors

Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2613
Contributors