IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR Sensor: What is the folder "C:\Windows\CarbonBlack\store" used for?

EDR Sensor: What is the folder "C:\Windows\CarbonBlack\store" used for?

Environment

  • EDR (formerly CB Response) Sensor:  All Supported Versions
  • Microsoft Windows: All Supported Versions

Question

What is the folder "C:\Windows\CarbonBlack\store" used for?

Answer

  • C:\Windows\CarbonBlack\store contains copies of binaries that have not yet been shared with the EDR server as well as a catalog of all observed binaries
  • Any observed binary will be copied and stored in this location.
  • Binaries will persist in the directory until the sensor checks in to the server.
    1. If the server does not have a copy of the binary, it is upload from the endpoint.
    2. If the server already has a copy of the binary, nothing is uploaded.
    3. Binary copies are then purged from the directory after check-in.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2530
Contributors