Trusted file assigned ADAPTIVE_WHITE reputation during updates causing a block
search cancel

Trusted file assigned ADAPTIVE_WHITE reputation during updates causing a block

book

Article ID: 286183

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard

Issue/Introduction

  • Trusted file assigned ADAPTIVE_WHITE reputation during updates causing a block
  • Hash for such trusted blocked binaries change with each update

Environment

  • Carbon Black Cloud Console: Current Version
    • Endpoint Standard
  • Carbon Black Cloud Windows Sensor: Supported Versions
  • Microsoft Windows: Supported Versions

Cause

  • ADAPTIVE_WHITE reputation is synonymous with a reputation of NOT_LISTED in the eyes of the sensor
  • Blocking rules configured for the Policy to block applications from invoking binaries with NOT_LISTED reputation causes block

Resolution

  1. Verify that the application is trusted for the environment
  2. If the application SHA256 hash is expected to remain unchanged then approve the application by adding its SHA256 hash to "Approved List"
  3. If the application SHA256 hash changes regularly then add a permission rule to the policy to bypass application path as follows:
    Application at Path: <file path for application> 
    Operation: Runs or is running 
    Action: Allow & Log