Carbon Black Cloud: Occasionally an executable that should be blocked by a policy is allowed to run.
search cancel

Carbon Black Cloud: Occasionally an executable that should be blocked by a policy is allowed to run.

book

Article ID: 288165

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

The issue is intermittent and can occur during boot time or any other time where the sensor service is in the middle of starting up or restarting.

 

Environment

  • Carbon Black Cloud Sensor: All versions
  • Carbon Black Cloud Server: All versions
  • Operating Systems: All versions

Cause

The CBC sensor is in the middle of its startup process and is an "unstable" (not completely functional) state.

Resolution

This is normal, expected behavior. Occasionally another service may start ahead of the CBC sensor and not be blocked/denied/terminated until the sensor is fully up and running.
One obvious solution is to delete the undesired executable file from the machine since it's meant to be blocked from running.
Another possible workaround is to delay the Windows service for that executable to be invoked until the CBC sensor is fully up.
For example, with MS Windows OS's services can be delayed at boot time as so: Delay start programs