Hi everyone. I’m Jason from the IT asset management team. We recently rolled out a new internal admin tool, and Carbon Black is flagging its main executable as malicious 😅.
I need to create a custom IOC to allowlist this tool and stop the alerts. I’ve found the CB console’s “IOCs” section, but I’m a bit lost on the exact steps. Specifically, what’s the best hash type to use for the rule (SHA-256?), and should I scope it just to the dev team’s machines? Any best practices to avoid too broad a rule would be a huge help.
Thanks in advance!
SHA-256 is the correct choice, it's the expected standard for file integrity in EDR platforms. For scoping, do not apply it globally. You should create a dynamic group based on the tool's installer deployment method or a specific AD group for the admin team, then apply the IOC only to that group.
A broader best practice is to also include the file's digital certificate information in your rule if it's signed, as that's a more resilient allowlist criteria than a hash alone. A hash will break with every patch. If you must use a hash, document the version it applies to and set a calendar reminder to review the rule after the next planned update.
Boring is beautiful