Endpoint Standard: Why Image File Accessed on a USB Device Currently Being Blocked
Carbon Black Cloud Console: November '20 Release (0.60) and Higher
Endpoint Standard Windows Sensor: 22.214.171.1247 and Higher
Why Image file accessed on a USB device currently being blocked
The image files are actually being viewed via MS Windows caching capabilities and are the result of the files being viewed or accessed prior to the Device Control policy being enforced. Windows Photo application also caches the previous and next images and may result in a similar experience for files that were not directly accessed.
To validate this you can clear the cache and attempt to access the image or preview again. To clear the cache manually delete the contents of
Once the content is cleared you can return to the file and attempt to open it and you will receive the expected “Access Denied”.
Note: Closing or killing the explorere.exe process before deleting may be required to delete all the content