Block Reads, Writes and Executions on Unapproved USB Devices
book
Article ID: 286427
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
How to use Device Management to prevent reads, writes or executions on USB devices
Environment
- App Control Console: All Supported Versions
- App Control Agent: All Supported Versions
Resolution
Enable Device Control:
This will block writes and executes from any Unapproved USB Device.
- Log in to the Console and navigate to Rules > Policies > relevant Policy > Device Control
- Enable one or more of the desired Settings by toggling the Status.
- Off: Permits listed operations to unapproved removable devices, does not report the Event.
- Report Only: Permits listed operations to unapproved removable devices, reports the Event.
- Active: Tracks listed operations to unapproved removable devices and blocks them in Control mode.
- Add or Edit the Notifiers accordingly.
- Save and Exit.
Block Reads on Unapproved USB Devices: (Custom Rule)
- Verify the Advanced Rule Options is enabled:
- Log in to the Console and navigate to https://ServerAddress/support.php > Advanced Configuration.
- Software Rules > Advanced Rule Options > check: Showing advanced rule options > Update.
- Navigate to Rules > Software Rules > Custom > Add Custom Rule.
- Use the following details:
- Status: Disabled
- Rule Type: Expert
- Operations: Open, Open Execute Intent, Read, Mmap Read
- Actions: Block, Stop Rule Processing
- Path or File: Any
- Process: Any
- User or Group: Any (Can be a specific user if desired)
- Policies: Selected policies > relevant Test Policy (Recommended to test first)
***DO NOT enable the rule yet, or all reads in the environment will be blocked*** |
- Save & Exit the Disabled Custom Rule.
- Edit the Custom Rule.
- Scroll down to the "Advanced" section of the Custom Rule. This only appears after the feature is enabled and the Custom Rule is saved.
- Change File Device Type to: Unapproved Removable.
- Enable & Save the Custom Rule.
Additional Information
- More information on Device Control can be found in the User Guide chapter, Managing Devices.
- Device Control is not available for Policies in Disabled Mode, Control or Visibility must be selected.
- Files on Unapproved Devices
- Can still be seen, but not opened.
- Copied to the local drive.
- Creating an additional rule just above this one in the rule stack with a Read Allow permission will allow tuning this for specific environmental needs
Feedback
thumb_up
Yes
thumb_down
No