Caution: Rapid Configs listed below may not be enabled by default. It is the customer’s responsibility to verify their configuration.
Table 1. List of Rapid Configs

Name

Brief Description

Platform

Browser Protection

Reports or prevents potentially malicious behavior related to browsers.

Windows

Carbon Black App Control Server Tamper Protection

Provides protection against tampering with the Carbon Black App Control Server.

Windows

Carbon Black EDR Tamper Protection

Prevents tampering with Carbon Black EDR.

Windows

Cryptomining Protection

Reports or prevents potentially malicious behavior related to file based cryptomining attacks. 

Windows

Delivery Optimization

Approve files written by the Delivery Optimization Service (DoSvc). 

Windows

Domain Controller Logon Scripts

Allows and optionally promotes all files under the Sysvol and NetLogon directories of the specified domain controllers if an agent is a member of the specified domain.

Windows

Doppelganger Protection

Protect against the exploit known as Doppelganging on windows systems.

Windows

Linux Hardening

Improves the security of computers running Linux by reporting or blocking modification of critical Linux system files.

Linux

Linux System Performance

Improves the performance of computers running Linux by ignoring writes of specified files or by specified processes.

Linux

Microsoft Edge

Approves updates to Microsoft Edge.

Windows

Microsoft Exchange Server

Improves the performance of Microsoft Exchange servers when running along side Carbon Black App Control.

Windows

Microsoft Office Protection

Improve security by watching for suspicious behavior by Microsoft Office apps.

Windows

Microsoft SCCM

Approves software delivered via Microsoft SCCM. 

Windows

Microsoft SQL Server

Improves the performance of Microsoft SQL servers when running alongside Carbon Black App Control.

Windows

Microsoft Teams

Approve Updates to Microsoft Teams.

Windows

Mimikatz Protection

Protect against Mimikatz based attacks on windows systems.

Windows

Powershell Protection

Improve security by watching for suspicious executions of Powershell.exe.

Windows

Process Hollowing Protection

Protect against process hollowing by reporting and preventing the hollowing of processes.

Windows

Ransomware Protection

Protect against ransomware by reporting or blocking modification to files typically targeted by ransomware.

Windows

Reconnaissance and Exfiltration Protection

Protect against reconnaissance and exfiltration of files.

Windows

Script Processors

Improves the security of computers by ensuring that script processors only run from expected locations.

Windows

Self-Service Approvals

Provides a folder from which normal end-users can approve the execution of unapproved files even when in high enforcement.

Windows

SolarWinds-Sunburst Protection

Prevent exploitation of the SolarWinds breach. You can see details of the Sunburst attack here: https://community.carbonblack.com/t5/Threat-Research-Docs/TAU-TIN-SolarWinds-SUNBURST-Solarigate-Incident/ta-p/98346. In additon to this Rapid Config, the 'Reconnaissance and Exfiltration Protection' Rapid Config can provide protection against the SolarWinds breach.

Windows

Suspicious Application Protection

Reports or prevents execution of Microsoft applications that are rarely used and can be used maliciously.

Windows

Suspicious Command Line Protection A-M

Reports or prevents behavior by common applications that is suspicious based on command line.

Windows

Suspicious Command Line Protection N-Z

Reports or prevents behavior by common applications that is suspicious based on command line. 

Windows

Suspicious Parent-Child Protection

Reports or prevents behavior by common applications that is suspicious based on parent-child relationships. 

Windows

Visual Studio

Approves Visual Studio builds and ignores intermediate build files.

Windows

VMware App Volumes Protection

Prevents attackers from impersonating or writing to VMware App Volumes AppStacks while still allowing writable areas to be modified.

Windows

VMware Workspace ONE

Approves software distributed via VMware Workspace ONE.

Windows

Windows App Store

Approves Windows app store installs and updates to specified directories.

Windows

Windows Hardening

Improves the security of computers running Windows by reporting or blocking modification of critical windows files and registry settings.

Windows

Windows Installer Embedded File Protection

Protect against exploiting Windows installers by embedding malicious content in them.

Windows

WMI Protection

Protect against WIndows Management Instrumentation (WMI) abuse on windows systems.

Windows