IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Why does the target app 'System' have the reputation 'Unknown'

Why does the target app 'System' have the reputation 'Unknown'

Environment

  • Cb Defense all versions
  • Windows endpoints

Question

The app 'System' is being shown with an 'UNKNOWN' reputation but given that System is a basic Windows process it would be expected to be known to Defense, particularly after a background scan.

Event in the Events page may show: Target Name: System Target Process ID: 4 Target Reputation: UNKNOWN

Answer

System is not actually a file, so has no hash and  therefore there was never an attempt to establish reputation.

During the construction of the event the default value of the reputation is NOT_SUPPORTED, which maps to UNKNOWN in the console.

This is normal behaviour for the product.

Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-08-2018
Views:
546
Contributors