IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Audit and Remediation: What Protections are in Place to Prevent Unauthorized Use of LiveQuery?

Audit and Remediation: What Protections are in Place to Prevent Unauthorized Use of LiveQuery?

Environment

  • Audit and Remediation: All Supported Versions
  • Microsoft Windows: All Supported Versions

Question

What controls and protections are offered to prevent unauthorized access to Live Query?

Answer

  • Existing access controls for a Carbon Black Cloud Organization will apply to Audit and Remediation Features.

  • Only Users with the correct permissions can see and use the Live Query Features.


Additional Notes

  • CSR Roles cannot see the Live Query Features in a organization, however they may have access to turn on of off the Live Query feature in an Organization.

  • Existing 2FA or SAML setups will be used as before.

  • Tamper protections are in place to prevent unauthorized deletion of the sensor components. However, by design, osqueryi can still be run on the endpoint.


Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-11-2018
Views:
421
Contributors