IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Managed Detection and Response: Why was ThreatSight recipient added by "VMware employee"?

Managed Detection and Response: Why was ThreatSight recipient added by "VMware employee"?

Environment

  • Carbon Black Cloud Managed Detection and Response: All versions

Question

  • Audit log shows an entry in this format:
    • IP Address: VMware employee IP
    • User: VMware employee
    • Action: Updated ThreatSight recipient X in organization Y

Answer

As of January 2023, the Managed Detection and Response (MDR) team made it mandatory that every organization have at least one recipient for alert notifications, monthly and daily summary reports.

Additional Notes

  • Customers are required to have one recipient for the Alert notifications & monthly reports.
  • Customer is encouraged to update this as needed.
  • Email is the only mechanism the MDR team have to communicate with customers.
  • The MDR team need to ensure when an action is required, it is going to a contact at the customer's organization who can take action.
  • The MDR team unified email records between the CBC console and the MDR analyst console to ensure the customer has full control over the recipient receiving the emails.
  • The MDR team strongly recommend all customers receive a daily summary for record keeping.
  • Customers can learn more about configuring MDR here.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎06-21-2023
Views:
185
Contributors