IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

How Carbon Black Protection determines a file is an 'installer'

How Carbon Black Protection determines a file is an 'installer'

Version

All.

Topic

How executable files are deemed as an 'installer'.

Q/A

Question

What criteria is used by Cb Protection to determine if a file is an 'installer'?

Answer

The Cb Protection Agent looks at the file's contents.

Then, the Agent scans the file looking for various signatures that would indicate that the file has embedded executable content (like a zip/cab).

It also looks for characteristics common to known installer technologies, like the ones found inside a standard-compliant MSI or typical Wyse or InstallShield package.

The full set of heuristics and data detail is something Carbon Black updates regularly as we encounter new vendor technologies and field edge cases.

Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-07-2015
Views:
941
Contributors