Sensor does not apply policy "Bypass" action permission rules
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)


Within EEDR orgs that have Endpoint Standard Rules enabled or have both Endpoint Standard and Enterprise EDR, bypass rules do not appear to be honored as the console still shows Enterprise EDR data.


  • Carbon Black Cloud Console: All Versions
    • Endpoint Standard (formerly CB Defense)
    • Enterprise EDR (formerly CB ThreatHunter) 
  • PSC Sensor: 3.3.x.x and Higher
  • Microsoft Windows: All Supported Versions
  • Apple macOS:: All Supported Versions


Bypass rules created under the standard Policy pages do not apply to the Enterprise EDR portion of the sensor. This means that the sensor will still record events locally and upload these to the console despite a bypass rule in place.


Use the Event Reporting and Sensor Operation Exclusions from the User Guide to create the necessary exclusions for processes/paths.

  • Procmon captures should not show ctiuser.dll injections for bypassed processes as Enterprise EDR doesn't require injection but Endpoint Standard does.