Troubleshooting Unexpected Approvals / Missed Blocks
search cancel

Troubleshooting Unexpected Approvals / Missed Blocks

book

Article ID: 377575

calendar_today

Updated On:

Products

Carbon Black App Control

Issue/Introduction

Steps to investigate when files are unexpectedly being created with a Local Approval or when the Agent did not block an Unapproved File.

Environment

  • App Control Console: All Supported Versions
  • App Control Agent: All Supported Versions

Resolution

  1. Check if the relevant Files were issued a Local Approval:
    1. Navigate to Reports > Events
    2. Use the Saved View: New Files (Approved)
    3. Click Show Filters
      • Add filter > Source > is: relevant Computer > Apply.
      • Set the Max Age accordingly from the dropdown.
      • Click Hide Filters.
    4. Click Show Columns
      • Add the Column for Rule Name
      • Click Apply
      • Click Hide Columns
    5. If relevant results found:
      1. Click Export to CSV
      2. Review the Column Subtype accordingly for any , some examples include:
        • File approved (local approval) means the Agent was in Local Approval.
        • File approved (Custom Rule) means a Custom Rule issued the Approval, review the Column, Rule Name.
  2. Review the File Instance Details:
    1. Navigate to Assets > Files > Files on Computers:
      1. Click Show Filters > add relevant filters, examples:
        • Computer > is: <relevant computer>
        • SHA-256 > is: <relevant hash>
        • File Name > is: <relevant name>
      2. Click View Details (pencil icon) to view the File Instance Details Page.
        • Review Local State and Global State fields.
          • Globally Approved files will have the same Local and Global State.
          • Globally Unapproved files can have different Local and Global States.
          • Local State Details: Primarily for use by Carbon Black Support but could help determine why a file was assigned its top-level Local State.
        • Review History
          • Indicates whether file was identified during or after Initialization
          • Files detected after Initialization are tracked as Unapproved until Approved or Banned
          • Includes any Global Approval or Ban changes for this file.
      3. If necessary, remove Local, Global and/or Reputation Approval using the right-hand menu.

 

If the issue persists open a case with Support and provide: