CB Protection: Allow Tenable Security Center/Nessus scans to run on Windows endpoints
book
Article ID: 290908
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Agent is preventing Tenable/Nessus scans from completing successfully.
Environment
- CB Protection Agent: All Verisons
- Microsoft Windows: All Supported Versions
- Tenable Security Center/Nessus Agent
Cause
Nessus utilizes .bat files that are unique to each endpoint, and aren’t signed by a publisher.
Resolution
- Create a new custom rule for 'Execution Control' using the following settings:
- Name: Nessus Scan Allow
- Description: Allow Nessus scans
- Status: Enabled
- Platform: Windows
- Rule Type: Execution Control
- Execute Action: Allow
- Path or File:
- c:\windows\temp\nessus*.bat
- c:\windows\tenable_mw_scan*.exe
- Process: Specific Process
- c:\windows\tenable_mw_scan*.exe
- c:\windows\system32\services.exe
- c:\windows\system32\cmd.exe
- User or Group: Any User
- Rule Applies To: All Policies
Additional Information
- Instructions for creating a custom rules can be found in the CB Protection User Guide.
Feedback
thumb_up
Yes
thumb_down
No