Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?
search cancel

Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?

book

Article ID: 290298

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense)

Issue/Introduction

Can an administator utilize policy rules to block network based activity?

Environment

  • Carbon Black Cloud Console: All Versions

Resolution

Yes, you can create a policy rule with the "Communicates over the network" Operation Attempt, using either "Deny operation" or "Terminate process" to block the behavior for specific applications, filenames or paths.

Additional Information

  • Network rules cannot be made more granular, meaning that specific IP ranges, URLS, etc. cannot be leveraged in policy rules.
  • The "Communicates over the network" Operation Attempt involves any attempted network access, so applications that have been blocked via policy rules will not be able to connect at all.