IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: What Do The Reputation Values Mean For Different Sections Of Investigate Page?

Endpoint Standard: What Do The Reputation Values Mean For Different Sections Of Investigate Page?

Environment

  • Carbon Black Console: All Versions
    • Endpoint Standard
      • Investigate Page

Question

What do the Reputation values mean for different locations on the Investigate Page?
 

Answer

There are three different reputations which can be seen for all applications tied to an Event. The table below provides more detail

Reputation types
NameInvestigate page LocationDescription
Reputation Selected/Target/Parent App tabs, above Event listCurrent reputation in the Carbon Black Cloud (Formerly Predictive Security Cloud - PSC)
App/Parent/Target ReputationExpanded Event detailsCarbon Black Cloud reputation for hash, matched to the time of the Event after uploading to the Carbon Black Cloud for analysis
App/Parent/Target Reputation (applied, {source})Expanded Event detailsHighest priority reputation (from all sources) the Sensor had at the time of the Event; used to determine whether to take action based on Policy Rules. Sent up to the Carbon Black Cloud from the Sensor
 
Reputation sources
SourceDescription
cloudSensor applied the hash reputation from Carbon Black Cloud
AV scanSensor applied the hash reputation from local AV scanner
pre-existingSensor treated the hash as "Pre-existing" file, and gave it a "Local_white" reputation
cert whitelistingSensor applied the Cert Approved list to give this hash a "Local_white" reputation
IT toolsSensor applied the IT Tools Approved list to give this hash a "Local_white" reputation
hash reputation listSensor applied the Company Approved list/Banned list database reputation
white databaseSensor applied the Carbon Black Cloud Approved list Database

Additional Notes

  • The Reputation in the Tabs for Selected, Parent and Target Apps is the current Carbon Black Cloud Reputation for the Hash
  • While the Event Details will show the the data at time of execution, these Tabs are the current values for comparison and to show updates

Related Content


Was this article helpful? Yes No
100% helpful (3/3)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
1462
Contributors