Tracking, Reporting and Blocking Registry Changes With The Agent
book
Article ID: 288728
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Is it possible to track, report, or block modifications to the Registry with the Agent?
Environment
App Control Agent: All Supported Versions
Microsoft Windows: All Supported Versions
Resolution
By default, registry tracking and enforcement is limited to Rapid Configs, Tamper Protection, and any existing Registry Rules (Rules > Software Rules > Registry).
More details on creating Registry Rules can be found in the App Control Tech Docs > User Guide > Registry Rules.
More details on Rapid Configs can be found in the App Control Tech Docs > Rules Installer & Rapid Configs.
Additional Information
When creating Rapid Configs or Registry Rules it is recommended to start in Report Only on a select group of test machines before implementing enforcement.