IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: Where can I find information about Alternate Data Stream Detection queries?

EDR: Where can I find information about Alternate Data Stream Detection queries?

Environment

  • EDR (formerly CB Response): Version 7.x and Higher
  • Hosted EDR (formerly CB Response Cloud)

Question

Where can information be found to write queries regarding Alternate Data Stream Detection (ADS)?

Answer

The User Exchange Alternate Data Stream Detection (ADS) has older information about this kind of investigation. An updated version of the query for 7.x EDR and above would look like this:
process_name:msedge.exe AND (filemod:*.iso*\:* OR path:*.iso*\:*)

Additional Notes

  • If more information is necessary please reply in the comment section of the post.
  • Sometimes files get downloaded using "browser_broker.exe" OR "runtimebroker.exe" so it is possible to add these process to the query as well.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-11-2020
Views:
759
Contributors