Alright, let's set the stage. Our security team, in a fit of cloud-envy, pushed out a new Carbon Black policy last week. Standard "hardening" template, straight from a vendor webinar. No one ran a break-even analysis on productivity loss, of course.
Now, a critical legacy application—the kind that invoices customers and has no budget for refactoring—is dead in the water. The policy is blocking a specific, dated DLL it needs to load. I've been through the console for an hour.
* The policy has "Allow" and "Prevent" modes, but the "Prevent" is grayed out for this rule type.
* There's mention of "exceptions" or "overrides" for processes, but the UI seems to assume you're excluding by hash or signer. This thing is unsigned and changes with every patch Tuesday.
* I tried adding the parent process path to an exclusion list, but the block persists.
Before I tell them to roll the entire policy back (which they'll resist), has anyone actually found the magic toggle in this version to let one specific crusty old.exe do its thing? A screenshot of the actual navigation path would be worth its weight in reserved instance savings.
What was the actual TCO of this "improvement" if it halts revenue?
Show me the bill