CB Response: Process Exclusions for OSX does not catch all instances
book
Article ID: 287916
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Process exclusion for OSX does not catch all instances
Environment
- Carbon Black Response Sensor: 5.x and above
- Apple MacOS: All Supported Versions
Cause
- Processes such as launchd that start as part of the boot sequence ahead of the sensor daemon and/or launches the sensor itself will not be excluded.
- If an already running system process loading a new image during the boot sequence it will also not be excluded.
Resolution
This is currently working as designed.
Feedback
thumb_up
Yes
thumb_down
No