Environment
- Carbon Black Cloud Console: All Versions
- Enterprise EDR
Symptoms
- Watchlist criteria for process_original_filename receiving inaccurate hits
- Example:
- IOC criteria contains process_original_filename:"x64.exe"
- Watchlist hits occurring for process_original_filename: "*-x64.exe"
Cause
process_original_filename criteria is using standard tokenizer which splits the criteria on hyphens ( - )
Resolution
Engineering fixing issue via DSER-32981 by having process_original_filename use the filename tokenizer which does not split the criteria on hyphens ( - )