IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Why is the "process name" is sometimes the process calling a script, and sometimes it's the script (file) name?

Carbon Black Cloud: Why is the "process name" is sometimes the process calling a script, and sometimes it's the script (file) name?

Environment

  • Carbon Black Cloud Console: All versions
  • Enterprise EDR Console: All versions

Question

In the Carbon Black Cloud / Enterprise/EDR Console, why do some pages show the "process name" as the process calling a script?
Examples can be "powershell.exe" or  "msiexec.exe". In contrast, other pages will show the "process name" as the script or file name that's being called such as "my_script.ps1" or "my_install.msi" respectively.

Answer

  • The changing of the process name of the calling process for the script/file being called is referred to as "script host replacement". The process analysis page (bases on Enterprise EDR thread) will not show the replaced script, but rather the calling process (like powershell.exe).
  • Endpoint Standard-based Alert Triage page will usually perform script host replacement and display the script/file name (like myscript.ps1). This is also true for the V6 Alerts API.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎10-29-2021
Views:
785
Contributors