App Control: Ransomware rapid config reports malicious behavior, but does not stop it.
search cancel

App Control: Ransomware rapid config reports malicious behavior, but does not stop it.


Article ID: 286223


Updated On:


Carbon Black App Control (formerly Cb Protection)


  • In the console, the Ransomware rapid config is enabled.  
  • However, a recent ransomware attack was reported, but not stopped.


  • App Control (formerly CB Protection) Console: All Supported Versions


The rapid config is set to report only, rather than to block.


Enable blocking for the Ransomware rapid config:
  1. Open the App Control Console.
  2. Navigate to Rules > Software Rules > Rapid Config
  3. Edit the config titled "Ransomware Protection"
  4. There are several sections of the rapid config, all defaulting to "report only".  You can switch any or all of these to block for active protection.
  5. Save the configuration changes.