Troubleshooting OS Crash or Blue Screen Issues
search cancel

Troubleshooting OS Crash or Blue Screen Issues

book

Article ID: 290732

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

Step-by-step guidance on troubleshooting an OS crash or BSOD.

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Sensor: All Supported Versions

Resolution

  1. Verify the impacted machine is running a supported and compatible Sensor version.
  2. Verify any installed third-party security applications (e.g. antivirus, real-time scanner, vulnerability scanner, etc.) have Sensor Exclusions in place and are granted proper Permissions in the impacted CBC Policy, if licensed for Endpoint Standard.
  3. Verify whether the issue is replicable while the Sensor is in Bypass.
  4. Verify whether the issue is replicable while running the latest Sensor version.

If the issue persists, open a case with Carbon Black Technical Support and provide the following items.

  1. Details on scale of issue, including number of systems impacted and any relevant hostnames or Device IDs.
  2. Impacted OS and Sensor versions.
  3. If licensed for Endpoint Standard, are there any blocks observed in the Console at the time of crash? If yes, provide any relevant Alert IDs.
  4. Sensor logs from an impacted device (WindowsmacOSLinux).
  5. Provide a Full Memory Dump or Core Dump, depending on the OS (Windows, macOS, Linux).
  6. Timestamp of crash.
  7. Can the crash be reproduced?  If yes, what steps were performed?
  8. Is the issue replicable while the Sensor is in Bypass?

Additional Information

  • On Windows, mini dumps are several hundred KB in size and do not contain data necessary for in-depth analysis.
  • If the issue cannot be resolved with troubleshooting from Carbon Black Technical Support, it may require further analysis by Carbon Black engineers, which will require the information above and may require additional diagnostics.