The VMware Carbon Black Tech Zone is live! Checkout this great resource: Mastering Carbon Black Audit & Remediation.

Query Exchange

QUERIES

Powershell Execution Policy inquiry (user)

Approved 1 Comment Submitted by jnelson a month ago

Description: This query looks for the 'ExecutionPolicy' registry key under HKEY_USERS hive to provid...

Carbon Black Compliance Help Desk Operations Incident Response IT Hygiene Vulnerability Management Windows

3Votes

Powershell Execution Policy inquiry (machine)

Approved 3 Comments Submitted by HenriqueLima 05-31-2022

Description: This query looks for the 'ExecutionPolicy' registry key under HKLM hive to provide info...

Community Compliance IT Hygiene Vulnerability Management Windows

2Votes

Local Administrator Permissions (w/ Domain Users)

Approved 2 Comments Submitted by jnelson 04-29-2022

Description:
The Least Privileged Model reduces risk by limiting the users who haveadminpermissi...

Carbon Black Compliance Help Desk Operations Incident Response IT Hygiene Windows

3Votes

Find where users have logged in

Approved 2 Comments Submitted by jnelson 02-09-2022

This query looks for the existence of a Windows user's folder which indicates that they have logged ...

Carbon Black Compliance Help Desk Operations Incident Response IT Hygiene Windows

5Votes

CVE-2022-21907 | HTTP Protocol Stack Remote Code Execution Vulnerability

Under Review 1 Comment Submitted by ralamer 01-14-2022

Description:This query checks if the registry value (EnableTrailerSupport) is set or not. If this va...

Community Vulnerability Management Windows

3Votes

Querying Sysmon logs

Approved 1 Comment Submitted by jnelson 01-07-2022

With the ability to query Windows Event Logs we can also query Sysmon logs as they show up in Event ...

Carbon Black Compliance Help Desk Operations Incident Response IT Hygiene Windows

2Votes

Search/Hunt for Persistence through Windows Services installed within the Past 30 days

Approved 5 Comments Submitted by jstreet16 10-12-2021

Description:Search windows service creation events using the system logs event id 7045 from the past...

Community Compliance Help Desk Operations Incident Response Windows

4Votes

Search windows artifacts of execution for evidence of a file

Approved 1 Comment Submitted by jstreet16 10-12-2021

Description: Search multiple artifacts of execution to search for evidence of an executable seen by ...

Community Help Desk Operations Incident Response Windows

2Votes

Ideas for working out FULL OUTER JOIN limitation

Approved 4 Comments Submitted by jstreet16 10-01-2021

Description: Given a file path check for the existence and evidence of execution of a fileWhat The D...

Carbon Black Incident Response Windows

1Vote

Disk utilization on Windows

Approved 3 Comments Submitted by jnelson 09-30-2021

This query converts the size and free space to GB, then calculate the percent full for the disk.

Carbon Black Help Desk Operations IT Hygiene Windows

1Vote

Welcome to the Query Exchange

The Query Exchange is a place for everyone to take, learn, and share queries. Since Live Query is built off of the open source project Osquery, we want to encourage the spirit of community participation. As a collective group we can help each other be more efficient, more innovative, and more secure. All query submissions default to the “Under Review” stage when initially posted. Once submissions are vetted by Carbon Black, submissions will be updated to reflect “Approved.”

Query Use Cases

IT Hygiene: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's IT Hygiene.

Compliance: Provides a list of SQL queries that we recommend you run in Live Query to help manage Compliance across your organization.

Incident Response: Provides a list of SQL queries that we recommend you run in Live Query to help during an investigation.

Vulnerability Management: Provides a list of SQL queries that we recommend you run in Live Query to help with Vulnerability Management in your organization.

Help Desk Operations: Provides a list of SQL queries that we recommend you run in Live Query to help with Help Desk items.

Container Support: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's Container Support.