The Carbon Black Cloud macOS Sensor continues to deny or terminate files previously classified as SUSPECT_MALWARE or KNOWN_MALWARE, even after the files have had their reputation updated.
This occurs due to an issue where active reputation overrides or bypass rules prevent the sensor from flushing its live kernel enforcement cache. This is being investigated in CRE-24039
Workaround:
A permanent fix is being investigated in CRE-24039