This section describes the location and contents of file information in Carbon Black App Control. It also includes:
This section describes the file tables you can view in the console.
This is your guide to day-to-day administration and security monitoring tasks: monitoring executable files on your network using App Control; configuring the App Control Server; managing computers running the App Control Agent; and managing App Control Console users.
This section covers the basics of using the Carbon Black App Control Console: how to log in and out, how to navigate in the user interface from the Home page and menu system, and how to view the information Carbon Black App Control makes available to you through tables, details pages, and dashboards.
This section describes how to create and manage login accounts for the Carbon Black App Control Console. It also describes how to define user roles that grant access to specified features, and in some cases limit this access by policy.
This section describes the steps necessary to install Carbon Black App Control agents on computers. It also describes how to upgrade or uninstall agents, view the details agents provide to the Carbon Black App Control Console and manage operating system updates on agent-managed systems.
This section explains how to create policies and change their settings, including Enforcement Levels.
This section explains how Carbon Black App Control efficiently manages virtual machines, called clones in the console, and the template computers on which they are based.
The File Catalog tab on the Files page shows unique files discovered on computers running the Carbon Black App Control Agent and reporting to your Carbon Black App Control Server.
The Files on Computers tab provides a table of files that are on agent computers or, for disconnected computers, were on those computers when their agents last communicated with the Carbon Black App Control Server.
The check box labeled Show individual files in the top right area of both Files page tabs, affects what files are shown.
File initialization is the file inventory process that begins immediately after installation of the Carbon Black App Control Agent on a computer.
The File Catalog and Files on Computers tables each have an Action menu in the upper left above the table.
If you add an application to your environment or update an existing program with a new file, you might want to determine whether any computers are missing the file or files involved in this change.
By default, Carbon Black App Control inventories and tracks all instances of interesting files on all agents attached to a server. Many of these files are Windows operating system and Microsoft application files and related system updates.
As files are being installed on a computer, the Carbon Black App Control Agent groups them according to its analysis of what process is installing them.
The console provides two different details pages for files it manages:
The previous sections provided details of the main views of file information in the console. The following table summarizes how to drill down to particular views.
Files in the File Catalog tab on the Files page have the following high-level states:
You can view local file state on the Files on Computers tab of the Files page.
The Publishers tab on the Software Rules page shows file publishers discovered on computers running the Carbon Black App Control Agent in your organization. It also shows any publishers that have been manually added to the File Catalog for your Carbon Black App Control Server.
Carbon Black App Control agents collect information about applications installed on agent systems and report it to the server, which displays the information on the Applications page in the console.
This section describes how to approve or ban software using Carbon Black App Control. It includes information about both global and local file approval.
This section describes how to use the Carbon Black App Control Console to delete files on Windows endpoints.
This section describes reputation approval rules, which can be used to automatically approve files based on the file and publisher trust ratings that Carbon Black File Reputation provides.
This section describes advanced features for using file-signing certificates in Carbon Black App Control file monitoring and enforcement activities.
This section describes features for tracking and control of storage devices detected on computers running the Carbon Black App Control Agent.
Custom rules define actions you want the agent to take in response to file, directory, or process activity that matches conditions you specify. They may be used to optimize performance, protect file integrity, create a trusted file path for software distribution, or meet other special needs
Memory Rules let you protect a process from being accessed or altered by other processes or users.
This chapter describes Registry rules, which control what happens when there is an attempt to make changes in the Windows Registry at locations that match paths you specify. If you choose, you can limit enforcement of the rules to specified users and/or processes.
This chapter describes Script rules, which identify files to be tracked and managed as scripts by Carbon Black App Control. The Carbon Black App Control Server includes built-in script rules, and you can create custom rules to identify other scripts.
Carbon Black App Control provides content-based inspection by using YARA rules, which enables more granular control of the security policy in your environment. YARA rules are descriptions of malware samples that can help you detect and classify malware in files. In a rule, the criteria for the rule is defined and tags are specified. When the rule is enabled, tags are assigned to files that meet the criteria for the rule.
Expert rules are Custom, Memory, and Registry rules created with a special interface that provides many more options than the standard interface for these rules. They are intended for expert users working with Carbon Black Support or Technical Services.
This chapter describes Rapid Configs, which are sets of rules that can be used to accomplish tasks such as application optimization, operating system and application hardening, and approval of files delivered by software distribution systems.
There are Event rules, which allow you to specify an action to be performed when an event matches filters you define.
This chapter describes the Carbon Black App Control features that involve interactions with endpoint users.
This section explains how to use Carbon Black App Control event reports and alerts to monitor file activity and other key operations on your network. It also describes tools for detecting propagation of files on your network and for keeping track of the number of times a specified file executes.
This section describes how to use Baseline Drift Reports, which allow you to track changes in the inventory of files on systems running the Carbon Black App Control Agent.
This section describes how you enable and use Carbon Black App Control’s Advanced Threat Indicators, and how you can monitor threats through events, file details, and alerts.
Carbon Black App Control Dashboards are configurable pages containing compact windows called portlets, each of which provides access to Carbon Black App Control-related information or controls.
This section describes how to use the Find Files page to locate or verify the existence of specific executable files on computers running the Carbon Black App Control Agent. Find Files locates instances of files, not their listings in the File Catalog.
This section describes settings that enable you to configure and maintain your Carbon Black App Control Server installation. Access to the System Configuration page is available only to login accounts in the Administrators group or in customized groups with View System Configuration and Manage System Configuration check boxes selected.
If you have multiple Carbon Black App Control servers, you can centralize the management of those servers. Unified Management allows you to specify that one server can control many common management functions for any connected Carbon Black App Control servers.
This section introduces the System Health page, which provides Carbon Black App Control administrators with the ability to monitor the health and performance of the Carbon Black App Control Server.
In addition to the access provided to the Live Inventory of files and computers through the console, Carbon Black App Control provides public views into the database. You can create your own reporting and data analysis solutions through the use of these public views.
The Carbon Black App Control API is intended for programmers who want to write code to interact with Carbon Black App Control, either using custom scripts or from other applications. It is a RESTful API that can be consumed over HTTPS protocol using any language that can create get URI requests and post/put JSON requests as well as interpret JSON responses.
This section provides instructions for configuring and using the Connector, which integrates the Carbon Black App Control Server with one or more network security devices or services.
The DasCLI.exe program, referred to as DASCLI, is an executable which provides Command Line Interface (CLI) access to the Carbon Black App Control Windows Agent. Messages are transmitted between DASCLI and the Agent.
The Carbon Black App Control Console includes a page that displays certain diagnostic files for the Carbon Black App Control Server and its agents. These files can be useful when you are investigating issues in your Carbon Black App Control environment with the assistance of Carbon Black Support.
This topic describes uploading files from agents.
This section provides instructions for configuring and using Carbon Black App Control External Analytics, which enables the Carbon Black App Control Server to export data it collects from endpoints to external analysis tools.