Skip to content

Comment on Carbon Black S-1parent

Comments

Freehunter, grateful for your thoughts on the below in response to your comment about technical staff running esoteric and constantly changing apps and therefore whitelisting isn't always possible.

Can apply prevention for

PowerShell, bat, java, javascript(node.js), perl, python, php scripts

Default “Trusted Scripts” applies to msi, msu, bat, cmd, ps1, psc1, psm1, vbs, wsf, vbe, ocx, cab, py, pyo, pyw, pl, pm, pls, rb, rbw, js, php files

Any other specified interpreter can be added using an Enhanced Scripts feature

REGSVR32.EXE (2016) without disabling its use “Trusted Script” technology allows IT to continue using REGSVR32.EXE while blocking any untrusted scripts loaded

Dynamically generated scripts (Trusted Children) e.g. Apps that spit out constantly changing .BAT scripts HP Warranty Checker Dell’s KACE Continuum RMM

And any application can be trusted by one click and that trust propagated across the enterprise similar to Active Directory’s inheritance mode.

Sorry, I honestly have no idea. I don't work with endpoint that closely, I'm more on the security architecture side. I have wonderful technical engineers on my projects who are paid to get that in-depth, but that's not me.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.