IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

PSC Console: TAU-TIN Death Ransomware Query Incorrect Results

PSC Console: TAU-TIN Death Ransomware Query Incorrect Results

Environment

  • PSC Console: December 19' Release

Symptoms

When selecting the December 2nd 2019 TAU-TIN Death Ransomware threat query link from the main console page too many process_name:WMIC results are returned that do not match the correct process_cmdline:shadowcopy OR process_cmdline:delete

Cause

The linked search query has missing parenthesis that cause the required process_cmdlines to not be evaluated correctly 

Resolution

While we work to fix this in the console a workaround is available by using the search below:
(((process_cmdline:vssadmin.exe OR process_cmdline:vssadmin) AND (process_cmdline:shadows process_cmdline:delete process_cmdline:\/quiet)) OR ((process_cmdline:wmic OR process_cmdline:wmic.exe) AND (process_cmdline:shadowcopy OR process_cmdline:delete)))

 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
469
Contributors