Unapproved files not blocked by agents in high enforcement policy
search cancel

Unapproved files not blocked by agents in high enforcement policy

book

Article ID: 288455

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

 Unapproved files not blocked by agents in high enforcement policy 

Environment

  • App Control Console : All Versions

Cause

There is an execution allow custom rule created for target path matching the block, which causes any unapproved file in that path to be allowed to execute (e.g. \device\harddiskvolume*\*, c:\*.*)

Resolution

Disable any allow execute custom rule matching the path or modify the target path to be more precise