IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: Why are some Events or Alerts with a Known Malware or a Banned reputation being allowed to run then terminated later? (Boot Time Protection)

Endpoint Standard: Why are some Events or Alerts with a Known Malware or a Banned reputation being allowed to run then terminated later? (Boot Time Protection)

Environment

  • Carbon Black Cloud Web Console: All Versions
  • Carbon Black Sensor: All Versions
  • Microsoft Windows: All Supported Versions

Question

Why are some Events / Alerts with a Known Malware / Banned reputation being allowed to run then terminated later?

Answer

  • The CBC Sensor is run as a Service. When the services are started there may be malware that was started already and has taken actions. When the CBC Sensor is active it will prioritize Policy enforcement actions over timestamps for logging to terminate processes according to Policy as quickly as possible. 
  • This issue has been resolved in Sensor Version 3.5 with a new feature that will find all malicious services associated with Known Malware hashes and puts them in a disabled state.

Additional Notes

If this is seen in the Console, you can Search by the Hash on the Device to see what occurred and verify the Sensor is Terminating / Denying the process when able. 

Signs in the CBC Console that malware started before the Sensor: 
  • The Events show Reputation values that should have been Terminated / Denied but there was no action logged for this
  • If the first Event for an Alert ID is services.exe invoking a process with a Reputation that should be stopped by Policy settings but is not
  • If the Events of Known Malware running all occur in the same second
If unsure, please open a Support case for assistance.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
1471
Contributors