Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.

CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.

Environment

  • CBC Console: 1.3 and earlier
  • CBC Windows Sensors: All versions
  • Microsoft Windows: All versions

Symptoms

Querying on the fileless_scriptload_cmdline may return additional process hits where the CMD field (in the process analysis pages) does not render the string searched for.

Cause

This is internal issue LC-1971. In reality, the string DOES occur, and therefore the query is ACCURATE.
What's occurring is the CMD field is so large, it cannot fit into the UI.
The queried string CAN be seen by turning on Chrome Devtools and rendering the process analysis page
where the string can be found in a  "results" field/

Resolution

Feature Request "FR-002859" has been created which will likely create a new field to render the CMD results properly.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-05-2022
Views:
60
Contributors