Managing the Process Hollowing Protection Rapid Config
book
Article ID: 288529
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Steps to enable and configure the Rapid Config for Process Hollowing Protection.
Environment
App Control Console: All Supported Versions
App Control Agent: 8.9.0 or Higher
Rules Installer: 1.20 or Higher
Microsoft Windows: All Supported Versions
Resolution
WARNING: If both an App Control Agent and a Cloud Sensor are installed, it is not recommended to have both products configured to prevent process hollowing.
Log in to the Console and navigate to Rules > Software Rules > Rapid Configs.
Click View Details (pencil icon) for Process Hollowing Protection.
Change the Status to Enabled.
Fill in the required fields
Report or Block Process Hollowing Applications
Applications Allowed To Hollow Processes
Click Save & Exit
Additional Information
It's recommended to start this Rapid Config in "Report" to monitor for false positives.
Trusted applications that trigger the Rapid Config should be added to the list: "Applications Allowed To Hollow Processes."