Carbon Black Cloud: Can Policy Rules Be Created To Block Network Activity?
book
Article ID: 290298
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
Can an administator utilize policy rules to block network based activity?
Environment
Carbon Black Cloud Console: All Versions
Resolution
Yes, you can create a policy rule with the "Communicates over the network" Operation Attempt, using either "Deny operation" or "Terminate process" to block the behavior for specific applications, filenames or paths.
Additional Information
Network rules cannot be made more granular, meaning that specific IP ranges, URLS, etc. cannot be leveraged in policy rules.
The "Communicates over the network" Operation Attempt involves any attempted network access, so applications that have been blocked via policy rules will not be able to connect at all.