App Control: How To Track If a Custom Rule Is Being Used
search cancel

App Control: How To Track If a Custom Rule Is Being Used

book

Article ID: 288362

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

To determine if a custom rule is still actively being used

Environment

  • App Control (Formerly CB Protection): All Supported Versions

Resolution

For File Creation Control Rules
  1. Under Rules > Software Rules > Edit the "Approve Write" rules and check the "Send Approval Event" box.
  2. Rule hits will now be shown in the console by searching in Reports > Events for Subtype = File Approved (Custom Rule)

For Execution Allow and Trusted Path Rules
  1. For every rule you are wanting to track, create a "Execution Control - Report" rule with the exact same parameters immediately above (i.e. next lower rank number) your Allow Execute or Trusted Path rule.
  2. Rule hits will now be shown in the console by searching in Reports > Events for Subtype = Report Execution (Custom Rule)