App Control: How to enable Filter Driver Verifier for BSOD issues
search cancel

App Control: How to enable Filter Driver Verifier for BSOD issues

book

Article ID: 289133

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Explain the steps to enable the Windows Driver Verifier tool for the parity.sys driver and reproduce BSOD behavior

Environment

  • App Control Agent: All Supported Versions
  • Windows OS: Windows 10 x64 and higher
  • Windows Driver Verifier

Resolution

  1. To enable the Filter Driver Verifier, open an Admin CMD prompt and execute: verifier /flags 0x10 /driver parity.sys
  2. Ensure that complete memory dumps are enabled on the system: https://community.carbonblack.com/t5/Knowledge-Base/All-Products-How-to-Create-a-Full-Complete-Memory-Dump-Via/ta-p/34630
  3. Reboot OS to apply the configuration.
  4. Reproduce the issue that triggers the BSOD behavior.
  5. Collect the memory.dmp file in c:\windows and submit to the CB Vault.