EICAR Does not alert when Horizon App Volume Exclusions Enabled
search cancel

EICAR Does not alert when Horizon App Volume Exclusions Enabled

book

Article ID: 286913

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard

Issue/Introduction

  • Testing EICAR does not alert
  • Identifying the EICAR file during an Unzip is not detected

Environment

  • Carbon Black Cloud Sensor: All Supported Versions
  • Horizons App Volumes
  • Exclusions as listed in the article Antivirus Considerations in a VMware Environment Specifically:
    C:\SnapVolumesTemp
    C:\SVROOT
    C:\{00000000-0000-0000-0000-000000000000}\SVROOT
    C:\Program Files (x86)\CloudVolumes

Cause

This is caused by the combination of the exclusions in place for the Horizon VDI, and that the extraction of the ZIP file does not count as an execution.

Resolution

While disabling the exclusions is a possibility, this could impact the performance per the article Antivirus Considerations in a VMware Environment. As the device is still protecting the executions, leaving the exclusions is our current recommendation.

Additional Information

  • Although the alert for the extraction of the EICAR file does not take place, you are still protected. When an execution takes place an analysis will take place
  • Unzipping of files, do not trigger an Execution in the kernel events, it does a Create, rename and a Write
  • Editing the file, for example in a Notepad document, runs a Read and a Memory Map operation
  • Executing manually does trigger an alert on the execution