Carbon Black Cloud: The sensor blocks scripts (cmd, bat, etc..) due to being fileless
book
Article ID: 289834
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Observe Alert "The application cmd.exe invoked another application (cmd.exe) on behalf of explorer.exe. A Deny\Terminate Policy Action was applied."
Event Description "The application C:\Windows\System32\cmd.exe invoked the application C:\Windows\System32\cmd.exe. The operation was blocked by Cb Defense."
FILELESS TTP is not attached to the event
Environment
Carbon Black Cloud (Formerly PSC) Console: All supported versions
Endpoint Standard (Formerly CB Defense) Sensor: 3.1 and above
Microsoft Windows: All Versions
Cause
The sensor blocks scripts (cmd, bat, etc..) due to policy rule: Application at path: **\cmd.exe Executes a fileless script Deny\Terminate operation
The script is is interpreted as being FILELESS because script is executed using cmd.exe /c. Example: