Approve Inaccessible Files Based on Last Known State
book
Article ID: 290149
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Agent Config to Approve an inaccessible file if the last known state was Approved. This is typically beneficial when the Agent is enforcing Unanalyzed Blocks.
Environment
App Control Agent: All Supported Versions
App Control Console: All Supported Versions
Cause
Unanalyzed file blocks occur when the Agent does not have time to properly analyze a file. This is typically caused by latency on the endpoint; network or third party antivirus being the most common root cause.
Resolution
Verify the Agent Exclusions are present in any other antivirus/security software on the endpoint.
Description: Dictates whether or not the agent will temporarily locally approve a file when unable to re-hash at time of execution when the last known hash for the file was Approved. The purpose of this is to reduce the number of unanalyzed blocks.
Security Risk: Minimal/moderate (A malicious actor could overwrite an approved file with new content and lock the file, preventing analysis as a means of bypassing enforcement)
Operational Risk: Net plus decrease the number of analyzed blocks