Environment
- EDR Sensor: All Versions
- EDR Console: All Versions
- Microsoft Windows: All Supported Versions
Objective
- How to enable verbose user and kernel-mode logging remotely via CB Live Reponse.
Resolution
- Back up the registry prior to enabling logging
- Remotely enable verbose logging:
- Establish a CB Live Response session with the endpoint
- Enter the following two commands within CB Live Response:
reg add HKLM\Software\CarbonBlack\config -v DebugLevel -t REG_DWORD -d 7
reg add HKLM\Software\CarbonBlack\config -v KernelDebugLevel -t REG_DWORD -d 7
- The registry setting will not take affect until the user-mode sensor service is restarted
execfg cmd.exe /K "sc control carbonblack 203"
- Reproduce the issue
- Collect logs:
- Disable verbose logging in Live Response
- Upload the diagnostics to the CB Vault
Related Content