IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: Alert Only Shows the Hash of a Child Process

Endpoint Standard: Alert Only Shows the Hash of a Child Process

Environment

  • Carbon Black Cloud Console: All Versions

Symptoms

Observation for a childproc event assigned to an Alert ID does not contain a filename, command line, or PID, and instead only displays the SHA256 hash, process username, and file reputation.

Cause

This issue is currently under investigation by Carbon Black engineers and understood to be a discrepancy in how the data is populated from the API.

Resolution

No workaround is available at this time.

Additional Notes

If the unknown hash's process name is not found elsewhere in the Console by searching the hash on the Investigate page, it can also be searched in VirusTotal, or other search engine, for identification.

Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-12-2024
Views:
203
Contributors