Environment
- Carbon Black EDR: All Versions
- Yara Connector: All Versions
Symptoms
Yara is not alerting on a binary that matches the rule
Cause
Binary is not doing anything interesting outside of modload and is being suppressed
Resolution
By default sensor groups are set to "Recommended" retention. With this setting, binaries executed that do nothing more than modloads will not have their own process document (still searchable by cmdline or childproc via the parent document). If the binary in question is being suppressed, the product will not alert on the binary based on the yara feed.
For example, double clicking a process and closing shortly after may result in no alert if the process did nothing interesting. If the same process was opened, then a netconn for example was generated, an alert will come in for the match against Yara.
Additional Notes
Related Content