IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: What changes are implemented on the Linux machine after sensor installation?

EDR: What changes are implemented on the Linux machine after sensor installation?

Environment

  • EDR(Formerly Carbon Black Response) Sensor: All Supported Versions


Question

What changes are implemented on the Linux machine after sensor installation?

Answer

  • The sensor has its own configuration files but does not modify any system level settings or libraries.
  • The sensor daemon has privileges and there is a kernel module that "hooks" into some system calls or a eBPF module that uses APIs to capture data.
  • The sensor may install some kernel packages that we need to capture events on some Operating Systems.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎05-16-2021
Views:
369