IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Response: How To Alert On Hashes Listed On Managed Banned Hashes Page Whose Bans Are Disabled

CB Response: How To Alert On Hashes Listed On Managed Banned Hashes Page Whose Bans Are Disabled

Environment

  • CB Response Server: 6.x

Objective

How to alert on hashes that are listed on the Managed Banned Hashes page whose bans are disabled, and therefore allowed to execute.

Resolution

  1. Login to the CB Response UI
  2. Go to the "Managed Banned Hashes" page.
  3. Highlight and copy the hash of interest in the banned hashes list.
  4. Go to the "Process Search" page in the CB Response UI.
  5. In the query field, type "md5:" followed by the hash of interest.
  6. Run the query.
  7. Click the "Create Watchlist" button above the results to create a watchlist based on this query.
  8. Verify the "Create Alert" box is checked for this watchlist.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-01-2019
Views:
704
Contributors