Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Reputation, what is it good for? (Absolutely Nothing)

Posted on November 29, 2018November 29, 2018 By Michael Kavka No Comments on Reputation, what is it good for? (Absolutely Nothing)

Reputation, something that should be taken (and usually is) seriously. It affects how we look at people and companies, what level of trust there is, and should we recommend said people/companies to others. In the world of NextGen AV and EDR reputation is suppose to work the same. This is not always the case, and can be very detrimental when it is not. When reputation levels are not proper inside of such software or security solutions you have situations where good software is blocked.

Let us start with a simple situation. You use a well known piece of software, say Commvault, which properly signs their software. CarbonBlack Protect, knows this software, and there is no issue with getting it whitelisted properly. This is not the case with CarbonBlack Defense. You would think that it would have the certificate already in the system (it doesn’t and there are other, more well known certificates that are not in there either), or at least have had the software in their back end as a known vector. Again, this is not the case as of this writing (again there is other software I have run into this issue with so it is not an isolated case). Easy enough to add the certificate into the system, but that does not make the software known at this point, it just adjusts the secret sauce scoring down, but does not guarantee that the software will not be blocked. Requesting an upload for every file that is run as part of the software would be a full time job for at least one person (if not multiple people) and that still does not mean that you will lose that unknown file tag. Even whitelisting the file itself (which can make for a huge database of exceptions to manage) does not guarantee the file will be allowed to do what it needs to do. The only way to guarantee is to put the path to the file(s) in a bypass mode of some sort. This will then prevent such things from being looked at or recorded, leaving blind spots on the system for malicious software/actors to hide in. This is an unacceptable risk, and really defeats the purpose of EDR software.

There are other issues with Unknown and Not Listed reputations that I have run into also. I have set certain policies up so that unknown software can do certain things, but surprisingly it gets blocked because the reputation in Not Listed, again even though it should be known software. The CarbonBlack Engineers have been working on this for over a month with no solution other than to put said software into a bypass type mode. Again, not a good solution.

I am lucky as I have been dealing with this on test machines before rolling out to the full company, and have heard of similar type issues with other NextGenAV and EDR products. The worst part is the response from the company, and length of time it is taking to track down such issues. This sort of issue should be a deal breaker for anyone who wants to use such software. AV is still an important and needed product on endpoints, and the shift to EDR software can be a good thing, but not when it leaves you blind. This is yet another reason why I feel EDR software is not quite ready for prime time, or in other words, the reputation I have of such software is diminishing rapidly.

Reviews, Security Tags:CarbonBlack, Reputation, Unknown Software

Post navigation

Previous Post: Just another week
Next Post: 2018 A Look Back

Related Posts

  • Security is Reactionary, No Matter What Security
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
First Defcon – The results Reviews
Defender, KQL and Lockbit Microsoft
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Viral AI actress' hotline face-scans every caller, watches their mood September 19, 2026 Ax Sharma
  • Calling viral AI actress Tilly Norwood? Agree to a face scan first September 19, 2026 Ax Sharma
  • HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th) September 19, 2026

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Viral AI actress' hotline face-scans every caller, watches their mood September 19, 2026 Ax Sharma
  • Calling viral AI actress Tilly Norwood? Agree to a face scan first September 19, 2026 Ax Sharma
  • HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th) September 19, 2026
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.