Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud Endpoint Standard: Does The Carbon Black Cloud Sensor Capture Malicious JS File In Browser Events?

Carbon Black Cloud Endpoint Standard: Does The Carbon Black Cloud Sensor Capture Malicious JS File In Browser Events?

Environment

  • Carbon Black Cloud Endpoint Standard Sensor: All Supported Versions
  • Carbon Black Cloud Web Console: All Versions

Question

Will a Carbon Black Cloud Sensor log when JS or any other script-like files hosted on a website run in the browser?

Answer

This is currently not supported. VMware is currently investigating in expanding the sensor capability to treat the browser as a host for these scripts in a future sensor version.

Additional Notes

In the event of code from a remote site trying to execute malicious actions on a Carbon Black Cloud protected endpoint, the sensor will still monitor reputation and execution of any files downloaded to the endpoint or executed locally from the browser which should mitigate direct attacks but will not prevent a phishing attack. 

Was this article helpful? Yes No
100% helpful (2/2)
Article Information
Author:
Creation Date:
‎02-04-2020
Views:
613
Contributors