Unapproved files not blocked by agents in high enforcement policy
book
Article ID: 288455
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Unapproved files not blocked by agents in high enforcement policy
Environment
App Control Console : All Versions
Cause
There is an execution allow custom rule created for target path matching the block, which causes any unapproved file in that path to be allowed to execute (e.g. \device\harddiskvolume*\*, c:\*.*)
Resolution
Disable any allow execute custom rule matching the path or modify the target path to be more precise