Security Connect 2021 is coming Jun 3. Register for free today!

EDR: VDI Sensor keyset lost in imaging process

EDR: VDI Sensor keyset lost in imaging process

Environment

  • EDR(Formerly Carbon Black Response) Sensor: All Supported Versions

Symptoms

  • Sensor diagnostics file "sensorcomms.log" shows these errors:
Time                 | URL                                                                                                  | HRESULT    | Code  | DurationMs | TxBytes  | RxBytes  | Throttle KB/s        | Upload Speed KB/s   
-------------------- + ---------------------------------------------------------------------------------------------------- + ---------- + ----- + ---------- + -------- + -------- + -------------------- + --------------------
2021-03-28 03:30:45  | https://10.38.220.15:443/sensor/register                                                             | 0x80072f9a | 12186 | 16         | 0        | 0        | 500                  | 0                   
2021-03-28 03:32:45  | https://10.38.220.15:443/sensor/register                                                             | 0x80072f9a | 12186 | 15         | 0        | 0        | 500                  | 0                   
2021-03-28 03:34:45  | https://10.38.220.15:443/sensor/register                                                             | 0x80072f9a | 12186 | 16         | 0        | 0        | 500                  | 0
  • Running the Windows certutil shows the following error:
c:\windows\system32 certutil -store carbonblack 

missing stored keyset

Cause

Sysprep changes keysets and other sensor configuration during imaging process of virtual machine creation.
 

Resolution

Use of the action plans.

Action Plan -1:
  • Use Quickprep instead of Sysprep.
Action Plan -2:

Additional Notes


Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎04-14-2021
Views:
64