Access official resources from Carbon Black experts
All versions of Carbon Black
This document covers not only how to turn off the event-collection of Non-Binary file writes, but also explains why this can be extremely beneficial for one's environment.
For the most part, Cb Response does not record information regarding non-binary files types. However, file writes of certain non-binary file types are recorded by Cb Response. The following is a list of non-binary files types that are recorded by the Cb Response sensor when written to disk:
PE
Elf
UniversalBin
EICAR
OfficeLegacy
OfficeOpenXml
ArchivePkzip
ArchiveLzh
ArchiveLzw
ArchiveRar
ArchiveTar
Archive7zip
Some endpoints may produce large amounts of one or more of the above files types, and therefore could produce a massive inbound queue of mostly uninteresting files. This could lead to decreased data retention due to these extra noisy sensors, as well as more system resources used to ingest this data on the server. If the large amount of non-binary file writes is determined to be an issue on certain machines, the following can assist to remedy the issue.
You can still turn off the collection of Non-Binary File Writes after a group has been created by going into Administration > Sensors , the selecting the group you want to edit, and then "Edit Settings" > "Event Collection"
Copyright © 2005-2023 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.