Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Endpoint Standard: How are Reputations Assigned?

Endpoint Standard: How are Reputations Assigned?

Environment

  • Carbon Black Cloud Console: All Versions
  • Endpoint Standard Sensor: All Versions
  • Microsoft Windows: All Supported Versions
  • Apple MacOS: All Supported Versions

Question

How are reputations assigned for files?

Answer


Additional Notes

  • Pre-Existing Files: Files that existed on the device prior to the sensor being installed
  • New Files: Files that are created or downloaded on the device after the sensor is installed
  • Network Files: Files that exist on network drives
  • No Execute: Pre-existing files which never executed or new files that were dropped or created on the hard disk but never executed
  • Pre-Execute: Pre-execute refers to the first time that a file is attempting to execute
  • Post-Execute: Post-execute refers to files which are already running or which have run before
  • Definite Reputation: Anything other than NOT_LISTED or UNKNOWN

Related Content


Was this article helpful? Yes No
100% helpful (2/2)
Article Information
Author:
Creation Date:
‎03-08-2018
Views:
4692
Contributors