False Positives Triggered by the Mimikatz Rapid Config
search cancel

False Positives Triggered by the Mimikatz Rapid Config

book

Article ID: 290788

calendar_today

Updated On:

Products

Carbon Black App Control

Issue/Introduction

  • Blocks on processes with the Bit9Terminated process tag
  • Blocks with Rule ID 0 listed

Environment

  • App Control Console: All Supported Versions

Cause

The Mimikatz rapid config triggers when a process imports a handful of specific DLLs.

WMI or a Security or an Inventory app service are most commonly loading the same DLLs that trigger the Mimikatz protection.

Resolution

  1. Collect a list of Trusted Security software services
  2. Edit the Rapid Config for "Report or Block apparent mimikatz applications"
  3. Add the service name for exceptions, for example:
    <OnlyIf:Hostname:COMPUTERNAME><HostedService:Winmgmt>