IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Enterprise EDR: Why Are There Continuous Watchlist Hits For The Same Watchlist?

Enterprise EDR: Why Are There Continuous Watchlist Hits For The Same Watchlist?

Environment

  • Enterprise EDR (Formerly CB ThreatHunter) Console: All Supported Versions

Question

Why Are There Continuous Watchlist Hits For The Same Watchlist?

Answer

If a watchlist is only looking at metadata (e.g: process_cmdline) for a long running process, then anytime that process does anything (makes a netconn, filemod, etc), another hit will trigger

Additional Notes

This is working as designed because watchlist searcher just sees a new segment with a copy of the the process metadata and the query is metadata only

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
300
Contributors