Environment
Objective
How to alert on hashes that are listed on the Managed Banned Hashes page whose bans are disabled, and therefore allowed to execute.
Resolution
- Login to the CB Response UI
- Go to the "Managed Banned Hashes" page.
- Highlight and copy the hash of interest in the banned hashes list.
- Go to the "Process Search" page in the CB Response UI.
- In the query field, type "md5:" followed by the hash of interest.
- Run the query.
- Click the "Create Watchlist" button above the results to create a watchlist based on this query.
- Verify the "Create Alert" box is checked for this watchlist.
Related Content