Per-user Custom Rules Not Working as Expected
search cancel

Per-user Custom Rules Not Working as Expected

book

Article ID: 368285

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

The Agent is associating the file operation with a different/remote user rather than the one reported to the Console.

Environment

  • App Control Console: All Supported Versions
  • App Control Windows Agent: 8.9.0 - 8.9.6
  • Microsoft Windows: All Supported Versions

Cause

The Agent is associating the file operation with a different/remote user rather than the user reported in the Event. 

Resolution

This issue was tracked under EPCB-21383 and resolved with the release of Agent 8.10.0. Upgrading will resolve the issue.

Additional Information

  • Prior to version 8.9.0, Agents only checked the User identity (SID) of running processes, but not of individual process threads.
  • Agent 8.9.0 adds the ability to check the User identity (SID) of a process thread, which is more granular and secure.