Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Enterprise EDR: PowerShell Blocked for Executing Fileless Script in Enterprise EDR-only Environment

Enterprise EDR: PowerShell Blocked for Executing Fileless Script in Enterprise EDR-only Environment

Environment

  • Enterprise EDR Console: All Versions
  • Carbon Black Cloud Sensor: 3.8.0.535
  • Microsoft Windows: All Supported Versions

Symptoms

  • Alerts are reported, similar to:
    The application powershell.exe attempted to execute fileless content in order to evade inspection. A Deny policy action was applied.
  • Endpoint Standard is not enabled for the environment.

Cause

A defect in the 3.8.0.535 Sensor caused the script to be blocked by a Tamper Protection rule in Enterprise EDR-only Orgs for attempting to disable AMSI via script.

Resolution

  • This issue was investigated by engineering under EA-21466 and resolved with the release of the 3.8.0.722 Sensor.
  • To remediate, upgrade Sensors on impacted machines to 3.8.0.722 or higher.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-22-2023
Views:
255
Contributors