IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Enterprise EDR: SANS Feed False Positives for Unusual Parent or Child

Enterprise EDR: SANS Feed False Positives for Unusual Parent or Child

Environment

  • Carbon Black Cloud: All Versions
    • Enterprise EDR

Symptoms

  • Alerts generated for processes such as lsass.exe or services.exe whose parents are not wininit.exe. Further investigation shows that wininit.exe is listed as the parent. 
  • Searching for the process and -parent_name:wininit.exe also return incorrect results. 

Cause

The parent process in the metadata contains a longer name which does not match the search completely.
Ex. $$deletemewininit.exe*

Resolution

Workarounds
  • The parent_name field will need wildcards before and after the name. 
    • ex. For the query SANS Unusual Services.Exe Parent
Original Query:
((process_name:services.exe parent_name:* -parent_name:wininit.exe -parent_name:winlogon.exe)) -(legacy:true OR enriched:true)

Fixed Query:
((process_name:services.exe parent_name:* -parent_name:*wininit.exe* -parent_name:*winlogon.exe*)) -(legacy:true OR enriched:true)
  • To continue to receive alerts for the intended query, create a new watchlist with new reports based on the modified searches as custom reports
    1. Create a custom watchlist - https://docs.vmware.com/en/VMware-Carbon-Black-Cloud/services/carbon-black-cloud-user-guide/GUID-B33...
    2. Copy the report query causing the false positive to the Investigate page. 
    3. Run the query to confirm events match expected results
    4. Select "Add search to threat report"
    5. Select the new watchlist name and Save
    6. In the Sans watchlist, disable the report causing the false positive alert. 

Related Content


Was this article helpful? Yes No
100% helpful (2/2)
Article Information
Author:
Creation Date:
‎09-16-2021
Views:
1243
Contributors