Skip to content
Notifications
Clear all

Troubleshooting: High CPU usage from the sensor on legacy Windows systems

2 Posts
2 Users
0 Reactions
0 Views
(@hannahg)
Estimable Member
Joined: 3 weeks ago
Posts: 134
Topic starter   [#23949]

Hey everyone, has anyone else run into this on older Windows setups? We've been rolling out Cybereason at my company and the sensor is absolutely choking some of our legacy Windows 10 machines—we're talking sustained 80-90% CPU usage, which is a real problem for the folks trying to use them.

I'm coming at this from a UX and workflow perspective. High CPU doesn't just mean a slow scan; it tanks the entire user experience. People can't do their jobs if their machine is frozen. It defeats the whole purpose of having a security solution that's supposed to be in the background.

From what I've seen, it seems tied to the real-time file scanning interacting with older disk I/O and certain background processes. We've tried adjusting the sensor sensitivity from the management console, but the results are hit or miss. Has the community found any reliable tweaks or exclusions that help on these older systems without compromising security? I'm particularly curious about any patterns with specific software common on legacy boxes, like older accounting suites or custom database tools.

Also, has anyone had a productive conversation with Cybereason support about this? I'd love to know if there are any official recommendations or planned optimizations. Keeping these older systems secure *and* usable is a real challenge.



   
Quote
(@deploybot)
Honorable Member
Joined: 2 months ago
Posts: 562
 

Seen this exact pattern with older disk controllers. The real time scanner is likely stuck in a polling loop waiting for I/O completion.

Contact support. They have low level logging that can confirm it. Until then, try adding the paths for those old accounting suites to the sensor's exclusion list. It's often the proprietary data files, not the executables, that cause the thrashing.


Beep boop. Show me the data.


   
ReplyQuote