Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: How to Troubleshoot Threat Research and Analytics Issues

Carbon Black Cloud: How to Troubleshoot Threat Research and Analytics Issues

Environment

  • Carbon Black Cloud Console: All supported versions

Objective

How to Troubleshoot Threat Research and Analytics Issues

Resolution

If you believe the reputation returned within the PSC and the CB Defense Web Console is incorrect (false positive), please Open a Support Case

The case will start by requesting:
  1. Event or Alert ID
  2. Device ID
  3. Was a Deny or Terminate Action applied?
  4. Is this a threat or monitored event?
  5. Is a malicious behavior being performed?
  6. Is the hash signed?
  7. Customer expected reputation
  8. Screenshot of Carbon Black Cloud Console reputation applied
  9. Sensor logs for the impacted device
    1. Collecting Sensor Logs Windows
    2. Collecting Sensor Logs Mac

If this issue cannot be solved with CB Support troubleshooting steps, it may need escalation to the CB Engineering team.  Escalation will require information collected in the steps above:

  1. Screenshot of Carbon Black Cloud Console reputation applied
  2. Additional reputation information/screenshots (will be collected from Support Engineer)
  3. Logs collected from an impacted endpoint

Additional Notes

Carbon Black has multiple methods for ingesting files, and leverages a number of internal and external data sources to generate reputation. While a single source of information may be valuable, it does not always mean all sources will see the same file as malicious.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
1097