VMware Carbon Black Cloud Endpoint Increase of Code Injection Alerts Using CreateRemoteThread or NtQueueApcThread

Summary: This article discusses an issue in VMware Carbon Black Cloud Endpoint increases Code Injection Alerts using CreateRemoteThread or NTQueueApcThread.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Affected Products:

  • VMware Carbon Black Cloud Endpoint

Affected Versions:

  • v3.7.0.1253

Cause

After upgrading or installing sensor version 3.7.0.1253, you may see an increase in observed alerts for code injection by calling for the functions CreateRemoteThread or NtQueueApcThread.

Example Alert

Note: In this example, VMware Carbon Black Cloud is reporting that svchost.exe has injected code into a system process csrss.exe.

Resolution

Support is investigating the changes that caused the increase of observed alerts for a permanent fix.

You can safely dismiss the inject code alerts that are being observed for the functions of CreateRemoteThread or NtQueueApcThread.

To verify and dismiss these alerts

  1. In a web browser, go to [REGION].conferdeploy.net.
  2. Sign In to the VMware Carbon Black Cloud.
    Sign In
  3. In the left menu pane, click Alerts.
    Alerts
  4. Click the carrot to expand the alert.
    Expand The Alert
  5. Click the Investigate icon.
    Investigate
  6. Verify the function being called is either CreateRemoteThread or NtQueueApcThread.
    Verify function
    Note: If inject code alerts are being observed for any other function besides CreateRemoteThread or NtQueueApcThread, reach out to support to investigate further. Reference How to Get Support for VMware Carbon Black Cloud Endpoint.
  7. Expand the corresponding event and click Dismiss Alert.
    Dismiss Alert
  8. Click Dismiss
    Dismiss
    Note: You can elect to dismiss all future occurrences by checking the field next to If this alert occurs in the future, automatically dismiss it from all devices.

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Affected Products

VMware Carbon Black
Article Properties
Article Number: 000191040
Article Type: Solution
Last Modified: 08 Aug 2024
Version:  5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.