Getting Read_Security_Data Alerts in Carbon Black Cloud
search cancel

Getting Read_Security_Data Alerts in Carbon Black Cloud

book

Article ID: 434858

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard

Issue/Introduction

Getting Alerts associated with the action read_security_data. This indicates that a process is attempting to access sensitive security information on the endpoint. 

Environment

  • Carbon Black Cloud Windows Sensor: All Supported Versions
  • Windows OS: All Supported Versions

Cause

While often malicious, these alerts can be triggered by legitimate software as well

  • Security Scanners/Antivirus: Vulnerability or compliance scanners that perform system audits.
  • Monitoring Tools: Performance monitors or system utilities (like Sysinternals tools) that may request broad memory access.
  • Administrative Agents: Remote management agents (like SCCM, Tanium, or specialized backup agents) that interact with user sessions.

Resolution

Additional Information

This can also occur if an application is scanning lsass.exe