Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: How to check current dynamic Sensor Management Content Manifests (macOS)

Carbon Black Cloud: How to check current dynamic Sensor Management Content Manifests (macOS)

Environment

  • Carbon Black Cloud Console: All Versions
    • Endpoint Standard
    • Enterprise EDR
    • Audit & Remediation
    • Workload
  • Carbon Black Cloud Sensor: 3.5.3.x and Higher
  • Apple macOS: All Supported Versions

Objective

Provide steps to check on the current revision of dynamic detection and prevention features (management content manifests) and the last date and time it was updated for a given Sensor

Resolution

  1. Launch terminal emulator
  2. Check for current ruleset revision
    sudo /Applications/VMware\ Carbon\ Black\ Cloud/repcli.bundle/Contents/MacOS/repcli status | grep -Ei --color "revision.*manifest"
  3. Output will show versions/revisions in use
    EEDR Reporting Revision[<rev#>]: Enabled(Manifest)
    Device Control Reporting Policy Revision[<rev#>]: Enabled(Manifest)

Additional Notes

  • Each ruleset revision will have a number and show "Enabled(Manifest)" if the Sensor is getting updated regularly and functioning properly
    EEDR Reporting Revision[<rev#>]: Enabled(Manifest)
    Device Control Reporting Policy Revision[<rev#>]: Enabled(Manifest)

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎04-19-2022
Views:
466
Contributors