Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Audit and Remediation: What Protections are in Place to Prevent Unauthorized Use of LiveQuery?

Audit and Remediation: What Protections are in Place to Prevent Unauthorized Use of LiveQuery?

Environment

  • Audit and Remediation: All Supported Versions
  • Microsoft Windows: All Supported Versions

Question

What controls and protections are offered to prevent unauthorized access to Live Query?

Answer

  • Existing access controls for a Carbon Black Cloud Organization will apply to Audit and Remediation Features.

  • Only Users with the correct permissions can see and use the Live Query Features.


Additional Notes

  • CSR Roles cannot see the Live Query Features in a organization, however they may have access to turn on of off the Live Query feature in an Organization.

  • Existing 2FA or SAML setups will be used as before.

  • Tamper protections are in place to prevent unauthorized deletion of the sensor components. However, by design, osqueryi can still be run on the endpoint.


Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-11-2018
Views:
305
Contributors