IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to Enable AMSI Fileless_Script Capture

EDR: How to Enable AMSI Fileless_Script Capture

Environment

  • EDR: Server: 7.6+

Objective

Enable the collection of AMSI fileless_scriptload event data.

Resolution

Enable AMSI events in the Carbon Black EDR Console by toggling the collection of AMSI events per sensor group:
  1. On the navigation bar, click Sensors.
  2. Select the sensor group.
  3. In the Event Collection Settings section, select the checkbox for Fileless script loads.
  4. Click Save Group.

Additional Notes

  • AMSI event capture is disabled by default.
  • The fileless_scriptload event leverages the Anti-Malware Scanning Interface (AMSI)support that is available in Windows 10 RS2+ and Windows 2019+.
  • To forward the information to the SIEM, check the box in the Event Forwarder > Events > Sensor > ingress.event.filelessscriptload.
  • File-based scripts are logged locally.
  • At this time this feature collects powershell.exe and not powershell_ise.exe

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-10-2021
Views:
1119
Contributors