IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CBC: Does Carbon Black have the CVE Hashes in a Watchlist?

CBC: Does Carbon Black have the CVE Hashes in a Watchlist?

Environment

  • Carbon Black Cloud:  All Products

Question

Are CVE hashes included in CBC watchlists?

Answer

  • No.  CVEs report known vulnerabilities of commonly used software, not a list of malware hashes.   
    • CVEs rarely contain hashes, instead they include software versions affected by the vulnerability.
    • A watchlist containing hashes for commonly used software would create alert fatigue.
    • If a CVE did include a hash (unlikely), the Investigate search page could be used to find the hash in the environment. 
      • If the hash is found, it may be advisable to create a custom watchlist to monitor its use until the patch is available. 
      • Carbon Black creating custom watchlists for commonly used software hashes for all customers is not maintainable.
Example:  If the CVE reports Firefox versions < 82.0.3 (CVE-2020-26950) are vulnerable, then alerts should not occur for each use of Firefox.   Instead, the vulnerability requires a certain configuration be met (an environmental setting) before or after Firefox starts;  The CBC administrator would determine if the certain configuration is needed in their environment. 

Additional Notes

Note: Known malware hashes, of community shared binaries, are added to the Reputation database daily with the intent to detect and protect the endpoints against malware.
  • Hashes listed in VirusTotal are normally included in the Reputation database.
  • CB Support can verify if a hash exists in the Reputation database.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-22-2024
Views:
71
Contributors