Environment
- Enterprise EDR Console: All Versions
- Carbon Black Cloud Sensor: 3.8.0.535
- Microsoft Windows: All Supported Versions
Symptoms
Cause
A defect in the 3.8.0.535 Sensor caused the script to be blocked by a Tamper Protection rule in Enterprise EDR-only Orgs for attempting to disable AMSI via script.
Resolution
- This issue was investigated by engineering under EA-21466 and resolved with the release of the 3.8.0.722 Sensor.
- To remediate, upgrade Sensors on impacted machines to 3.8.0.722 or higher.
Related Content