IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Cb Response: What process is used to run Cb Live Response?

Cb Response: What process is used to run Cb Live Response?

Environment

  • Cb Response Server: All Versions
  • Cb Response Sensor: All Versions

Question

What process(es) or executables are used to run Cb Live Response by the sensor?

Answer

  1. The process used by the sensor to run a Live Response session is C:/Windows/CarbonBlack/cb.exe

Additional Notes

  • Communication from the sensor still comes through the sensor port (443) via nginx service and then gets forwarded to the LiveResponsePort where the Live Response service is running. The CB Response sensor service process running on the endpoint is responsible for the Live Response activity on the endpoint. 
  • No .dlls are used to run Cb Live Response on the endpoint
  • Live Repsonse communicates over port TCP/443

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-04-2018
Views:
560
Contributors