IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard Sensor: Network files being scanned despite "Scan files on network drives" setting being disabled

Endpoint Standard Sensor: Network files being scanned despite "Scan files on network drives" setting being disabled

Environment

  • Endpoint Standard Sensor: All versions
  • Microsoft Windows: All Supported Versions

Symptoms

  • Network files being scanned despite "Scan files on network drives" setting being disabled
  • Policy is configured with "Scan execute on network drives" enabled and "Scan files on network drives" disabled

Cause

  • Browsing in explorer often does trigger execute and hence the files are scanned.  
  • Windows API for extracting file resource and icons relies on calling LoadLibraryExW w/ LOAD_LIBRARY_AS_DATAFILE argument in order to map the PE file into memory to extract the resources.
  • Even though no process was created by double clicking the resource, just browsing in explorer does often trigger "executions"
  • Content opened with execute access will trigger policy enforcement.  
  • Browsing in cmd.exe/powershell.exe wouldn't exhibit that behavior.

Resolution

This is an expected behavior

Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-18-2022
Views:
302
Contributors