IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: What is the meaning of "isolation" as it applies to the Carbon Black EDR sensor?

EDR: What is the meaning of "isolation" as it applies to the Carbon Black EDR sensor?

Environment

  • Carbon Black EDR Server (on-prem and hosted): All Supported Versions
  • Carbon Black EDR Sensor: All Supported Versions

Question

What is the meaning of "isloation" as it applies to the Carbon Black EDR sensor, and if it is kept in a state of "isolation", what will happen to the endpoint?

Answer

When an endpoint is isolated, its connectivity is limited to the following (unless you have created network isolation exclusions):
  • The Carbon Black EDR server can communicate with an isolated computer.
  • To allow the sensor to communicate with the Carbon Black EDR server, ARP, DNS, and DHCP services remain operational on the sensor’s host. (For Windows operating systems prior to Vista, ICMP (for example, ping) will remain operational.)
  • DNS and DHCP are allowed through on all platforms. This is required for proper communications to the Carbon Black EDR server. Protocols are allowed by UDP/53, UDP/67, and UDP/68.
  • ICMP is allowed on the following operating systems:-Windows (operating systems prior to Vista)-OSX -Linux
  • UDP is blocked on all platforms.

 If kept in an isolated state, the endpoint will only be able to communicate to the items listed above. After it is isolated, endpoints normally remain isolated until the isolation is ended through the Carbon Black EDR console. However, if an isolated system is rebooted, it is not isolated again until it checks in with the Carbon Black EDR server, which could take several minutes. "Endpoint Isolation" is used as a remediation step in response to a potential security incident on an endpoint(s).

 

Related Content

For further detailed information, please see the latest EDR user guides: Repository of Carbon Black EDR Documentation
 

Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎12-21-2021
Views:
1790
Contributors