IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: How does the Linux Sensor determine reputation?

Carbon Black Cloud: How does the Linux Sensor determine reputation?

Environment

  • Carbon Black Cloud Console: All Versions
    • Endpoint Standard (was CB Defense)
    • Enterprise EDR (was CB ThreatHunter)
  • Carbon Black Cloud Sensor: All Versions
  • Linux: All Supported Versions

Question

How does the Linux Sensor detect malware of suspect hashes and determine their reputation as known malware, suspected malware, potentially unwanted program, etc.?

Answer

The Sensor versions which currently support Endpoint Standard and Enterprise EDR functionality rely on streaming prevention and obtaining reputation information from the Carbon Black Cloud only.

Additional Notes

  • The Linux Sensor does not currently have full feature parity with either the macOS or Windows Sensors
  • Other reputation sources like Background Scan and the Local Scanner are not available on Linux
  • As new features and functionality are added to the Linux Sensor, the Release Notes page will be updated

Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-29-2020
Views:
960
Contributors