carbonblack-v2 Deprecated
Deprecated. Use VMware Carbon Black EDR v2 instead.
Endpoint · Carbon Black Enterprise Response
Details
| ID | carbonblack-v2 |
|---|---|
| Provider | Broadcom |
| Category | Endpoint |
| From Version | 5.0.0 |
| Docker Image | demisto/python:2.7.18.8715 |
| Supported Modules | Agentix XSIAM EDR Cortex Cloud Cloud Runtime Security |
README
Deprecated. Use VMware Carbon Black EDR v2 instead.
Query and response with Carbon Black endpoint detection and response.
This integration was integrated and tested with version 6.2.0 of Carbon Black Response
Configure carbonblack-v2 in Cortex
| Parameter | Required |
|---|---|
| Server URL | True |
| API Token | True |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
| Fetch incidents | False |
| Incident type | False |
| Fetch Alert Severity Threshold Higher Than | False |
| Maximum Number Of Incidents To Fetch | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
cb-alert
Retrieve alerts from Carbon Black Response.
Base Command
cb-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| status | Alert status to filter by. Possible values are: Unresolved, In Progress, Resolved, False Positive. | Optional |
| username | Alert username to filter by. | Optional |
| feedname | Alert feedname to filter by. | Optional |
| hostname | Alert hostname to filter by. | Optional |
| report | Alert report name (watchlist_id) to filter by. | Optional |
| query | Query string. Accepts the same data as the search box on the Binary Search page. See https://github.com/carbonblack/cbapi/blob/master/client_apis/docs/query_overview.pdf. | Optional |
| rows | Return this many rows, 10 by default. | Optional |
| start | Start at this row, 0 by default. | Optional |
| sort | Sort rows by this field and order. server_added_timestamp desc by default. | Optional |
| facet | Return facet results. ‘false’ by default, set to ‘true’ for facets. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CbResponse.Alerts.CbAlertID | unknown | Alert unique id |
| CbResponse.Alerts.ProcessPath | string | Alert Process Path |
| CbResponse.Alerts.Hostname | string | Alert Hostname |
| CbResponse.Alerts.InterfaceIP | string | Alert interface IP |
| CbResponse.Alerts.CommsIP | string | Communications IP |
| CbResponse.Alerts.MD5 | string | Alert process MD5 |
| CbResponse.Alerts.Description | unknown | Alert description |
| CbResponse.Alerts.FeedName | unknown | Alert feed name |
| CbResponse.Alerts.Severity | unknown | Alert severity |
| CbResponse.Alerts.Time | unknown | Alert created time |
| CbResponse.Alerts.Status | unknown | Alert status. One of: Unresolved, Resolved, False Positive |
Command Example
#### Human Readable Output
### cb-binary
***
Query for binaries based on given parameters
#### Base Command
`cb-binary`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| digital-signature | Whether digital signature is signed or not. Possible values are: Signed, Unsigned. | Optional |
| publisher | Filter binary by publisher. | Optional |
| company-name | Filter binary by company name. | Optional |
| product-name | Filter binary by product name. | Optional |
| filepath | Filter binary by file path. | Optional |
| group | Filter binary by group. | Optional |
| hostname | Filter binary by hostname. | Optional |
| query | Query string. Accepts the same data as the search box on the Binary Search page. See https://github.com/carbonblack/cbapi/blob/master/client_apis/docs/query_overview.pdf. | Optional |
| rows | Return this many rows, 10 by default. | Optional |
| start | Start at this row, 0 by default. | Optional |
| sort | Sort rows by this field and order. server_added_timestamp desc by default. | Optional |
| facet | Return facet results. 'false' by default, set to 'true' for facets. | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| File.DigSig.Publisher | unknown | The publisher of the Digital Signature |
| File.InternalName | unknown | The Internal Name |
| File.ServerAddedTimestamp | unknown | The server added timestamp |
| File.Name | unknown | Binary Name |
| File.Extension | unknown | Binary Extension |
| File.Timestamp | unknown | Binary Timestamp |
| File.Hostname | unknown | Binary Hostname |
| File.Description | unknown | The description |
| File.DigSig.Result | unknown | Cb's decision after checking this binary's Digital Signature |
| File.LastSeen | unknown | Last time binary was seen |
| File.Path | unknown | Binary Path |
| File.ProductName | unknown | The Product Name |
| File.OS | unknown | The OS |
| File.MD5 | unknown | Binary MD5 |
| File.Company | string | Name of the company that released a binary |
| File.DigitalSignature.Publisher | string | Publisher of the digital signature for the file. |
| File.Name | string | Full Filename e.g. data.xls. |
| File.Signature.OriginalName | string | File's original name. |
| File.Signature.InternalName | string | File's internal name. |
| File.Signature.FileVersion | string | File version. |
| File.Signature.Description | string | Description of the signature. |
#### Command Example
Human Readable Output
cb-block-hash
Blocking hash
Base Command
cb-block-hash
Input
| Argument Name | Description | Required |
|---|---|---|
| md5hash | the blacklisted hash. | Required |
| text | text description of block list. | Required |
| lastBanTime | the last time the hash was blocked or prevented from being executed. | Optional |
| banCount | total number of blocks on this block list. | Optional |
| lastBanHost | last hostname to block this hash. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| File.LastAction | unknown | Last action taken on this file |
Command Example
#### Human Readable Output
### cb-get-hash-blacklist
***
Returns a list of hashes on block list, with each list entry describing one hash on block list.
#### Base Command
`cb-get-hash-blacklist`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| filter | OPTIONAL filters blacklist by fields. Example: filter="md5hash == put_your_hash_here". | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| CbResponse.BlockedHashes.MD5 | unknown | Blocked MD5 |
| CbResponse.BlockedHashes.Enabled | unknown | Is Enabled |
| CbResponse.BlockedHashes.Description | unknown | Blocked Description |
| CbResponse.BlockedHashes.Timestamp | unknown | Blocked Timestamp |
| CbResponse.BlockedHashes.BlockCount | unknown | Blocked Count |
| CbResponse.BlockedHashes.Username | unknown | Blocked hash username |
| CbResponse.BlockedHashes.LastBlock.Time | unknown | Last block time |
| CbResponse.BlockedHashes.LastBlock.Hostname | unknown | Last block hostname |
| CbResponse.BlockedHashes.LastBlock.CbSensorID | unknown | Last block sensor ID |
#### Command Example
Human Readable Output
cb-get-process
Gets basic process information for segment (segment_id) of process (process_id)
Base Command
cb-get-process
Input
| Argument Name | Description | Required |
|---|---|---|
| pid | the internal CB process id; this is the id field in search results. | Required |
| segid | the process segment id, the segment_id field in search results. | Required |
| get_related | If set to true, will get process siblings, parent and children. Possible values are: false, true. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Process.Siblings.MD5 | unknown | The sibling Process MD5 |
| Process.CbSegmentID | unknown | Cb ‘segment’ where this process instance is stored. Required to fetch further info on a process. |
| Process.Parent.MD5 | unknown | The parent Process MD5 |
| Process.Children.CommandLine | unknown | The children Process CommandLine |
| Process.Hostname | unknown | Process Hostname |
| Process.Parent.CbSegmentID | unknown | The parent Cb ‘segment’ where this process instance is stored. Required to fetch further info on a process. |
| Process.CbID | unknown | Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. |
| Process.Siblings.CbSegmentID | unknown | The sibling Cb ‘segment’ where this process instance is stored. Required to fetch further info on a process. |
| Process.Children.Name | unknown | The children Process Name |
| Process.Parent.Name | unknown | The parent Process Name |
| Process.Siblings.Hostname | unknown | The sibling Process Hostname |
| Process.Parent.Path | unknown | The parent Process Path |
| Process.Children.Hostname | unknown | The children Process Hostname |
| Process.PID | unknown | Process PID |
| Process.Children.CbSegmentID | unknown | The children Cb ‘segment’ where this process instance is stored. Required to fetch further info on a process. |
| Process.Children.CbID | unknown | The children Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. |
| Process.Path | unknown | Process Path |
| Process.Parent.PID | unknown | The parent Process PID |
| Process.Children.Path | unknown | The children Process Path |
| Process.Name | unknown | Process Name |
| Process.Children.PID | unknown | The children Process PID |
| Process.Parent.CbID | unknown | The parent Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. |
| Process.CommandLine | unknown | Process CommandLine |
| Process.Siblings.CommandLine | unknown | The sibling Process CommandLine |
| Process.Siblings.Name | unknown | The sibling Process Name |
| Process.Parent.CommandLine | unknown | The parent Process CommandLine |
| Process.Parent.Hostname | unknown | The parent Process Hostname |
| Process.MD5 | unknown | Process MD5 |
| Process.Children.MD5 | unknown | The children Process MD5 |
| Process.Siblings.CbID | unknown | The sibling Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. |
| Process.Siblings.Path | unknown | The sibling Process Path |
| Process.Siblings.PID | unknown | The sibling Process PID |
| Process.StartTime | date | Start time of the process. |
Command Example
#### Human Readable Output
### cb-get-processes
***
Query processes based on given parameters
#### Base Command
`cb-get-processes`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| name | Filter processes by name. | Optional |
| group | Filter processes by group. | Optional |
| hostname | Filter processes by hostname. | Optional |
| parent-process-name | Filter processes by parent process name. | Optional |
| process-path | Filter processes by process path (Example: "c:\windows\resources\spoolsv.exe"). | Optional |
| md5 | Filter processes by md5 hash. | Optional |
| query | Query string. Accepts the same data as the search box on the Binary Search page. See https://github.com/carbonblack/cbapi/blob/master/client_apis/docs/query_overview.pdf. | Optional |
| rows | Return this many rows, 10 by default. | Optional |
| start | Start at this row, 0 by default. | Optional |
| sort | Sort rows by this field and order. server_added_timestamp desc by default. | Optional |
| facet | Return facet results. 'false' by default, set to 'true' for facets. | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| File.Name | unknown | File Name |
| File.MD5 | unknown | File MD5 |
| File.Path | unknown | File Path |
| Endpoint.Hostname | unknown | Endpoint Hostname |
| Process.CommandLine | unknown | Process Commandline |
| Process.PID | unknown | Process PID |
| Process.CbID | unknown | Cb unique ID for this process instance - required \(together with CbSegmentID\) to fetch further info on a process. |
| Process.CbSegmentId | unknown | Cb "segment" where this process instance is stored. Required to fetch further info on a process. |
| Process.Parent.PID | unknown | Process Parent PID |
| Process.Parent.Name | unknown | Process Parent Name |
| Process.StartTime | date | Start time of the process. |
#### Command Example
Human Readable Output
cb-list-sensors
List the CarbonBlack sensors
Base Command
cb-list-sensors
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum amount of sensors to be returned. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CbResponse.Sensors.Status | unknown | Sensor Status |
| CbResponse.Sensors.LastUpdate | unknown | Sensor Last Updated |
| CbResponse.Sensors.Uptime | unknown | The Sensor uptime |
| CbResponse.Sensors.SupportsCbLive | unknown | Sensor Support CB Live |
| CbResponse.Sensors.Notes | unknown | Sensor Notes |
| CbResponse.Sensors.Hostname | unknown | Hostname |
| CbResponse.Sensors.CbSensorID | unknown | Sensor ID |
| CbResponse.Sensors.Isolated | unknown | Sensor Isolated |
| CbResponse.Sensors.IPAddresses | unknown | Sensor IP Addresses |
| CbResponse.Sensors.OS | unknown | Sensor OS |
| Endpoint.Hostname | unknown | Sensor Hostname |
| Endpoint.OS | unknown | Sensor OS |
| Endpoint.IPAddresses | unknown | Sensor IP Addresses |
Command Example
#### Human Readable Output
### cb-process-events
***
Retrieve all process events for a given process segmented by segment ID
#### Base Command
`cb-process-events`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| pid | the internal CB process id; this is the id field in search results. | Required |
| segid | the process segment id; this is the segment_id field in search results. | Required |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| Process.CrossProc.OtherProcessMD5 | unknown | Other process MD5 |
| Process.MD5 | unknown | Process MD5 |
| Process.Modules.MD5 | unknown | Module MD5 |
| Process.CommandLine | unknown | Process CommandLine |
| Process.Registry.RegistryPath | unknown | Registry path |
| Process.Path | unknown | Process Path |
| Process.CbID | unknown | Cb unique ID for this process instance - required \(together with CbSegmentID\) to fetch further info on a process. |
| Process.Parent.Name | unknown | The parent Process Name |
| Process.Hostname | unknown | Process Hostname |
| Process.Binaries.DigSig.Publisher | unknown | The publisher of the Digital Signature |
| Process.CrossProc.Action | unknown | Cross process action |
| Process.CrossProc.OtherProcessCbID | unknown | Other process CbID |
| Process.CbSegmentID | unknown | Cb 'segment' where this process instance is stored. Required to fetch further info on a process. |
| Process.Name | unknown | Process Name |
| Process.CrossProc.Time | unknown | Time of action |
| Process.PID | unknown | Process PID |
| Process.Modules.Filepath | unknown | Module path |
| Process.Binaries.DigSig.Result | unknown | Cb's decision after checking this binary's Digital Signature |
| Process.Parent.PID | unknown | The parent Process PID |
| Process.Binaries.MD5 | unknown | Binary MD5 |
| Process.CrossProc.OtherProcessBinary | unknown | Other process binary |
| Process.Registry.Time | unknown | Registry time |
| Process.Modules.Time | unknown | Module time |
#### Command Example
Human Readable Output
cb-quarantine-device
Isolate the endpoint from the network
Base Command
cb-quarantine-device
Input
| Argument Name | Description | Required |
|---|---|---|
| sensor | the sensor ID to quarantine. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Endpoint.LastAction | unknown | Endpoint Actions |
Command Example
#### Human Readable Output
### cb-sensor-info
***
Display information about the given sensor
#### Base Command
`cb-sensor-info`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| sensor | the sensor id. | Optional |
| ip | returns the sensor registration(s) with specified IP address. | Optional |
| hostname | returns the sensor registration(s) with matching hostname. | Optional |
| groupid | returns the sensor registration(s) in the specified sensor group id. | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| CbResponse.Sensors.Status | unknown | Sensor Status |
| CbResponse.Sensors.LastUpdate | unknown | Sensor Last Updated |
| CbResponse.Sensors.Uptime | unknown | The Sensor uptime |
| CbResponse.Sensors.SupportsCbLive | unknown | Sensor Support CB Live |
| CbResponse.Sensors.Notes | unknown | Sensor Notes |
| CbResponse.Sensors.Hostname | unknown | Sensor Hostname |
| CbResponse.Sensors.CbSensorID | unknown | Sensor ID |
| CbResponse.Sensors.Isolated | unknown | Sensor Isolated |
| CbResponse.Sensors.IPAddresses | unknown | Sensor IP Addresses |
| CbResponse.Sensors.OS | unknown | Sensor OS |
#### Command Example
Human Readable Output
cb-unblock-hash
Unblocking hash
Base Command
cb-unblock-hash
Input
| Argument Name | Description | Required |
|---|---|---|
| md5hash | the hash on the block list. | Required |
| text | text description of block list. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| File.LastAction | unknown | Last action taken on this file |
Command Example
#### Human Readable Output
### cb-unquarantine-device
***
Unquarantine the endpoint
#### Base Command
`cb-unquarantine-device`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| sensor | the sensor ID to quarantine. | Required |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| Endpoint.LastAction | unknown | Endpoint Actions |
#### Command Example
Human Readable Output
cb-version
Display the CarbonBlack version
Base Command
cb-version
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
Command Example
#### Human Readable Output
### cb-watchlist-del
***
Delete a watchlist in Carbon black Response.
#### Base Command
`cb-watchlist-del`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| watchlist-id | Watchlist ID. | Required |
#### Context Output
There is no context output for this command.
#### Command Example
Human Readable Output
cb-watchlist-get
Retrieve info for a watchlist in Carbon black Response.
Base Command
cb-watchlist-get
Input
| Argument Name | Description | Required |
|---|---|---|
| watchlist-id | Watchlist ID. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CbResponse.Watchlists.LastHit | unknown | Watchlist last hit |
| CbResponse.Watchlists.TotalHits | unknown | Watchlist Total hits |
| CbResponse.Watchlists.SearchQuery | unknown | Cb search query used for the watchlist. |
| CbResponse.Watchlists.Name | unknown | Watchlist Name |
| CbResponse.Watchlists.Enabled | unknown | Watchlist is enabled |
| CbResponse.Watchlists.LastHitCount | unknown | Watchlist last hit count |
| CbResponse.Watchlists.DateAdded | unknown | Watchlist Date added |
| CbResponse.Watchlists.SearchTimestamp | unknown | Watchlist last hit count |
| CbResponse.Watchlists.CbWatchlistID | unknown | Watchlist ID |
Command Example
#### Human Readable Output
### cb-watchlist-new
***
Create a new watchlist in Carbon black Response.
#### Base Command
`cb-watchlist-new`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| search-query | the raw Carbon Black query that this watchlist matches. | Required |
| name | name of this watchlist. | Required |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| CbResponse.Watchlists.LastHit | unknown | Watchlist last hit |
| CbResponse.Watchlists.TotalHits | unknown | Watchlist Total hits |
| CbResponse.Watchlists.SearchQuery | unknown | Cb search query used for the watchlist. |
| CbResponse.Watchlists.Name | unknown | Watchlist Name |
| CbResponse.Watchlists.Enabled | unknown | Watchlist is enabled |
| CbResponse.Watchlists.LastHitCount | unknown | Watchlist last hit count |
| CbResponse.Watchlists.DateAdded | unknown | Watchlist Date added |
| CbResponse.Watchlists.SearchTimestamp | unknown | Watchlist last hit count |
| CbResponse.Watchlists.CbWatchlistID | unknown | Watchlist ID |
#### Command Example
Human Readable Output
cb-watchlist-set
Modify a watchlist in Carbon black Response.
Base Command
cb-watchlist-set
Input
| Argument Name | Description | Required |
|---|---|---|
| watchlist-id | Watchlist ID. | Required |
| search-query | the raw Carbon Black query that this watchlist matches. | Optional |
| name | name of this watchlist. | Optional |
| indexType | the type of watchlist. Valid values are ‘modules’ and ‘events’ for binary and process watchlists, respectively. | Optional |
Context Output
There is no context output for this command.
Command Example
#### Human Readable Output
### cb-alert-update
***
Alert update and resolution
#### Base Command
`cb-alert-update`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| uniqueId | Alert unique identifier. | Required |
| status | Updated alert's status: Resolved,Unresolved,In Progress or False Positive. Possible values are: Resolved, Unresolved, In Progress, False Positive. | Required |
| setIgnored | Whether to stop showing this type of alert. Possible values are: true, false. | Optional |
#### Context Output
There is no context output for this command.
#### Command Example
Human Readable Output
cb-watchlist
Retrieve watchlist in Carbon black Response.
Base Command
cb-watchlist
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| CbResponse.Watchlists.LastHit | unknown | Watchlist last hit |
| CbResponse.Watchlists.TotalHits | unknown | Watchlist Total hits |
| CbResponse.Watchlists.SearchQuery | unknown | Cb search query used for the watchlist. |
| CbResponse.Watchlists.Name | unknown | Watchlist Name |
| CbResponse.Watchlists.Enabled | unknown | Watchlist is enabled |
| CbResponse.Watchlists.LastHitCount | unknown | Watchlist last hit count |
| CbResponse.Watchlists.DateAdded | unknown | Watchlist Date added |
| CbResponse.Watchlists.SearchTimestamp | unknown | Watchlist last hit count |
| CbResponse.Watchlists.CbWatchlistID | unknown | Watchlist ID |
Command Example
#### Human Readable Output
### cb-binary-download
***
Retrieve a binary from CarbonBlack based on hash. Returns a .zip file containing the requested file and it's metadata.
#### Base Command
`cb-binary-download`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| md5 | MD5 hash of the file. | Required |
| summary | Whether to include the summary. Possible values are: yes, no. | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| File.DigSig.Publisher | unknown | The publisher of the digital signature. |
| File.InternalName | unknown | The internal name. |
| File.ServerAddedTimestamp | unknown | The timestamp when the server was added. |
| File.Name | unknown | The binary name. |
| File.Extension | unknown | The binary extension. |
| File.Timestamp | unknown | The binary timestamp. |
| File.Hostname | unknown | The binary hostname. |
| File.Description | unknown | The binary description. |
| File.DigSig.Result | unknown | The Carbon Black decision after checking this binary's digital signature. |
| File.LastSeen | unknown | LThe lst time the binary was seen. |
| File.Path | unknown | The binary path. |
| File.ProductName | unknown | The product name. |
| File.OS | unknown | The OS. |
| File.MD5 | unknown | The MD5 hash of the binary. |
| File.Company | unknown | Name of the company that released a binary. |
| File.DigitalSignature.Publisher | unknown | Publisher of the digital signature for the file. |
| File.Name | unknown | Full filename, for example data.xls. |
| File.Signature.OriginalName | unknown | The file's original name. |
| File.Signature.InternalName | unknown | The file's internal name. |
| File.Signature.FileVersion | unknown | The file version. |
| File.Signature.Description | unknown | The description of the signature. |
#### Command Example
Human Readable Output
Configuration parameters
serverurl— Server URL (required)apitoken— API Token (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsisFetch— Fetch incidentsincidentType— Incident typefetchAlertsSeverityThreshold— Fetch Alert Severity Threshold Higher Thanrows— Maximum Number Of Incidents To Fetch
Commands (21)
-
cb-alertRetrieve alerts from Carbon Black Response.
-
cb-alert-updateAlert update and resolution
-
cb-binaryQuery for binaries based on given parameters
-
cb-binary-downloadRetrieve a binary from CarbonBlack based on hash. Returns a .zip file containing the requested file and it's metadata.
-
cb-binary-getDeprecatedDeprecated. Use the cb-binary-download command instead.
-
cb-block-hashBlocking hash
-
cb-get-hash-blacklistReturns a list of hashes on block list, with each list entry describing one hash on block list.
-
cb-get-processGets basic process information for segment (segment_id) of process (process_id)
-
cb-get-processesQuery processes based on given parameters
-
cb-list-sensorsList the CarbonBlack sensors
-
cb-process-eventsRetrieve all process events for a given process segmented by segment ID
-
cb-quarantine-deviceIsolate the endpoint from the network
-
cb-sensor-infoDisplay information about the given sensor
-
cb-unblock-hashUnblocking hash
-
cb-unquarantine-deviceUnquarantine the endpoint
-
cb-versionDisplay the CarbonBlack version
-
cb-watchlistRetrieve watchlist in Carbon black Response.
-
cb-watchlist-delDelete a watchlist in Carbon black Response.
-
cb-watchlist-getRetrieve info for a watchlist in Carbon black Response.
-
cb-watchlist-newCreate a new watchlist in Carbon black Response.
-
cb-watchlist-setModify a watchlist in Carbon black Response.
commonfields: id: carbonblack-v2 version: -1 name: carbonblack-v2 display: VMware Carbon Black EDR (Deprecated) deprecated: true fromversion: 5.0.0 category: Endpoint provider: Broadcom description: Deprecated. Use VMware Carbon Black EDR v2 instead. configuration: - display: Server URL name: serverurl defaultvalue: "" type: 0 required: true - display: API Token name: apitoken defaultvalue: "" type: 4 required: true - display: Trust any certificate (not secure) name: insecure defaultvalue: "" type: 8 required: false - display: Use system proxy settings name: proxy defaultvalue: "" type: 8 required: false - display: Fetch incidents name: isFetch type: 8 required: false - display: Incident type name: incidentType type: 13 required: false - display: Fetch Alert Severity Threshold Higher Than name: fetchAlertsSeverityThreshold defaultvalue: "" type: 0 required: false - display: Maximum Number Of Incidents To Fetch name: rows defaultvalue: "10" type: 0 required: false script: script: '' type: javascript commands: - name: cb-alert arguments: - name: status auto: PREDEFINED predefined: - Unresolved - In Progress - Resolved - False Positive description: Alert status to filter by - name: username description: Alert username to filter by - name: feedname description: Alert feedname to filter by - name: hostname description: Alert hostname to filter by - name: report description: Alert report name (watchlist_id) to filter by - name: query default: true description: Query string. Accepts the same data as the search box on the Binary Search page. See https://github.com/carbonblack/cbapi/blob/master/client_apis/docs/query_overview.pdf - name: rows description: Return this many rows, 10 by default. - name: start description: Start at this row, 0 by default. - name: sort description: Sort rows by this field and order. server_added_timestamp desc by default. - name: facet description: Return facet results. 'false' by default, set to 'true' for facets. outputs: - contextPath: CbResponse.Alerts.CbAlertID description: Alert unique id - contextPath: CbResponse.Alerts.ProcessPath description: Alert Process Path type: string - contextPath: CbResponse.Alerts.Hostname description: Alert Hostname type: string - contextPath: CbResponse.Alerts.InterfaceIP description: Alert interface IP type: string - contextPath: CbResponse.Alerts.CommsIP description: Communications IP type: string - contextPath: CbResponse.Alerts.MD5 description: Alert process MD5 type: string - contextPath: CbResponse.Alerts.Description description: Alert description - contextPath: CbResponse.Alerts.FeedName description: Alert feed name - contextPath: CbResponse.Alerts.Severity description: Alert severity - contextPath: CbResponse.Alerts.Time description: Alert created time - contextPath: CbResponse.Alerts.Status description: 'Alert status. One of: Unresolved, Resolved, False Positive' description: Retrieve alerts from Carbon Black Response. - name: cb-binary arguments: - name: digital-signature auto: PREDEFINED predefined: - Signed - Unsigned description: Whether digital signature is signed or not - name: publisher description: Filter binary by publisher - name: company-name description: Filter binary by company name - name: product-name description: Filter binary by product name - name: filepath description: Filter binary by file path - name: group description: Filter binary by group - name: hostname description: Filter binary by hostname - name: query default: true description: Query string. Accepts the same data as the search box on the Binary Search page. See https://github.com/carbonblack/cbapi/blob/master/client_apis/docs/query_overview.pdf - name: rows description: Return this many rows, 10 by default. - name: start description: Start at this row, 0 by default. - name: sort description: Sort rows by this field and order. server_added_timestamp desc by default. - name: facet description: Return facet results. 'false' by default, set to 'true' for facets. outputs: - contextPath: File.DigSig.Publisher description: The publisher of the Digital Signature - contextPath: File.InternalName description: The Internal Name - contextPath: File.ServerAddedTimestamp description: The server added timestamp - contextPath: File.Name description: Binary Name - contextPath: File.Extension description: Binary Extension - contextPath: File.Timestamp description: Binary Timestamp - contextPath: File.Hostname description: Binary Hostname - contextPath: File.Description description: The description - contextPath: File.DigSig.Result description: Cb's decision after checking this binary's Digital Signature - contextPath: File.LastSeen description: Last time binary was seen - contextPath: File.Path description: Binary Path - contextPath: File.ProductName description: The Product Name - contextPath: File.OS description: The OS - contextPath: File.MD5 description: Binary MD5 - contextPath: File.Company description: Name of the company that released a binary type: string - contextPath: File.DigitalSignature.Publisher description: Publisher of the digital signature for the file. type: string - contextPath: File.Name description: Full Filename e.g. data.xls. type: string - contextPath: File.Signature.OriginalName description: File's original name. type: string - contextPath: File.Signature.InternalName description: File's internal name. type: string - contextPath: File.Signature.FileVersion description: File version. type: string - contextPath: File.Signature.Description description: Description of the signature. type: string description: Query for binaries based on given parameters - name: cb-binary-get arguments: - name: md5 required: true default: true description: MD5 File Hash - name: summary auto: PREDEFINED predefined: - "yes" - "no" description: Whether to include summary - name: decompress auto: PREDEFINED predefined: - "yes" - "no" description: Whether to decompress results defaultValue: "yes" outputs: - contextPath: File.DigSig.Publisher description: The publisher of the Digital Signature - contextPath: File.InternalName description: The Internal Name - contextPath: File.ServerAddedTimestamp description: The server added timestamp - contextPath: File.Name description: Binary Name - contextPath: File.Extension description: Binary Extension - contextPath: File.Timestamp description: Binary Timestamp - contextPath: File.Hostname description: Binary Hostname - contextPath: File.Description description: The description - contextPath: File.DigSig.Result description: Cb's decision after checking this binary's Digital Signature - contextPath: File.LastSeen description: Last time binary was seen - contextPath: File.Path description: Binary Path - contextPath: File.ProductName description: The Product Name - contextPath: File.OS description: The OS - contextPath: File.MD5 description: Binary MD5 - contextPath: File.Company description: Name of the company that released a binary type: string - contextPath: File.DigitalSignature.Publisher description: Publisher of the digital signature for the file. type: string - contextPath: File.Name description: Full Filename e.g. data.xls. type: string - contextPath: File.Signature.OriginalName description: File's original name. type: string - contextPath: File.Signature.InternalName description: File's internal name. type: string - contextPath: File.Signature.FileVersion description: File version. type: string - contextPath: File.Signature.Description description: Description of the signature. type: string description: Deprecated. Use the cb-binary-download command instead. deprecated: true - name: cb-block-hash arguments: - name: md5hash required: true description: the hash on the block list - name: text required: true description: text description of block list - name: lastBanTime description: the last time the hash was blocked or prevented from being executed - name: banCount description: total number of blocks on this block list - name: lastBanHost description: last hostname to block this hash outputs: - contextPath: File.LastAction description: Last action taken on this file important: - contextPath: File(val.LastAction) description: File Actions related: "" description: Blocking hash - name: cb-get-hash-blacklist arguments: - name: filter description: 'OPTIONAL filters blacklist by fields. Example: filter="md5hash == put_your_hash_here"' outputs: - contextPath: CbResponse.BlockedHashes.MD5 description: Blocked MD5 - contextPath: CbResponse.BlockedHashes.Enabled description: Is Enabled - contextPath: CbResponse.BlockedHashes.Description description: Blocked Description - contextPath: CbResponse.BlockedHashes.Timestamp description: Blocked Timestamp - contextPath: CbResponse.BlockedHashes.BlockCount description: Blocked Count - contextPath: CbResponse.BlockedHashes.Username description: Blocked hash username - contextPath: CbResponse.BlockedHashes.LastBlock.Time description: Last block time - contextPath: CbResponse.BlockedHashes.LastBlock.Hostname description: Last block hostname - contextPath: CbResponse.BlockedHashes.LastBlock.CbSensorID description: Last block sensor ID description: Returns a list of hashes on block list, with each list entry describing one hash on block list. - name: cb-get-process arguments: - name: pid required: true description: the internal CB process id; this is the id field in search results - name: segid required: true description: the process segment id, the segment_id field in search results. - name: get_related auto: PREDEFINED predefined: - "false" - "true" description: If set to true, will get process siblings, parent and children. defaultValue: "false" outputs: - contextPath: Process.Siblings.MD5 description: The sibling Process MD5 - contextPath: Process.CbSegmentID description: Cb 'segment' where this process instance is stored. Required to fetch further info on a process. - contextPath: Process.Parent.MD5 description: The parent Process MD5 - contextPath: Process.Children.CommandLine description: The children Process CommandLine - contextPath: Process.Hostname description: Process Hostname - contextPath: Process.Parent.CbSegmentID description: The parent Cb 'segment' where this process instance is stored. Required to fetch further info on a process. - contextPath: Process.CbID description: Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. - contextPath: Process.Siblings.CbSegmentID description: The sibling Cb 'segment' where this process instance is stored. Required to fetch further info on a process. - contextPath: Process.Children.Name description: The children Process Name - contextPath: Process.Parent.Name description: The parent Process Name - contextPath: Process.Siblings.Hostname description: The sibling Process Hostname - contextPath: Process.Parent.Path description: The parent Process Path - contextPath: Process.Children.Hostname description: The children Process Hostname - contextPath: Process.PID description: Process PID - contextPath: Process.Children.CbSegmentID description: The children Cb 'segment' where this process instance is stored. Required to fetch further info on a process. - contextPath: Process.Children.CbID description: The children Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. - contextPath: Process.Path description: Process Path - contextPath: Process.Parent.PID description: The parent Process PID - contextPath: Process.Children.Path description: The children Process Path - contextPath: Process.Name description: Process Name - contextPath: Process.Children.PID description: The children Process PID - contextPath: Process.Parent.CbID description: The parent Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. - contextPath: Process.CommandLine description: Process CommandLine - contextPath: Process.Siblings.CommandLine description: The sibling Process CommandLine - contextPath: Process.Siblings.Name description: The sibling Process Name - contextPath: Process.Parent.CommandLine description: The parent Process CommandLine - contextPath: Process.Parent.Hostname description: The parent Process Hostname - contextPath: Process.MD5 description: Process MD5 - contextPath: Process.Children.MD5 description: The children Process MD5 - contextPath: Process.Siblings.CbID description: The sibling Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. - contextPath: Process.Siblings.Path description: The sibling Process Path - contextPath: Process.Siblings.PID description: The sibling Process PID - contextPath: Process.StartTime description: Start time of the process. type: date description: Gets basic process information for segment (segment_id) of process (process_id) - name: cb-get-processes arguments: - name: name description: Filter processes by name - name: group description: Filter processes by group - name: hostname description: Filter processes by hostname - name: parent-process-name description: Filter processes by parent process name - name: process-path description: 'Filter processes by process path (Example: "c:\windows\resources\spoolsv.exe")' - name: md5 description: Filter processes by md5 hash - name: query default: true description: Query string. Accepts the same data as the search box on the Binary Search page. See https://github.com/carbonblack/cbapi/blob/master/client_apis/docs/query_overview.pdf - name: rows description: Return this many rows, 10 by default. - name: start description: Start at this row, 0 by default. - name: sort description: Sort rows by this field and order. server_added_timestamp desc by default. - name: facet description: Return facet results. 'false' by default, set to 'true' for facets. outputs: - contextPath: File.Name description: File Name - contextPath: File.MD5 description: File MD5 - contextPath: File.Path description: File Path - contextPath: Endpoint.Hostname description: Endpoint Hostname - contextPath: Process.CommandLine description: Process Commandline - contextPath: Process.PID description: Process PID - contextPath: Process.CbID description: Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. - contextPath: Process.CbSegmentId description: Cb "segment" where this process instance is stored. Required to fetch further info on a process. - contextPath: Process.Parent.PID description: Process Parent PID - contextPath: Process.Parent.Name description: Process Parent Name - contextPath: Process.StartTime description: Start time of the process. type: date description: Query processes based on given parameters - name: cb-list-sensors arguments: - name: limit description: The maximum amount of sensors to be returned. outputs: - contextPath: CbResponse.Sensors.Status description: Sensor Status - contextPath: CbResponse.Sensors.LastUpdate description: Sensor Last Updated - contextPath: CbResponse.Sensors.Uptime description: The Sensor uptime - contextPath: CbResponse.Sensors.SupportsCbLive description: Sensor Support CB Live - contextPath: CbResponse.Sensors.Notes description: Sensor Notes - contextPath: CbResponse.Sensors.Hostname description: Hostname - contextPath: CbResponse.Sensors.CbSensorID description: Sensor ID - contextPath: CbResponse.Sensors.Isolated description: Sensor Isolated - contextPath: CbResponse.Sensors.IPAddresses description: Sensor IP Addresses - contextPath: CbResponse.Sensors.OS description: Sensor OS - contextPath: Endpoint.Hostname description: Sensor Hostname - contextPath: Endpoint.OS description: Sensor OS - contextPath: Endpoint.IPAddresses description: Sensor IP Addresses description: List the CarbonBlack sensors - name: cb-process-events arguments: - name: pid required: true description: the internal CB process id; this is the id field in search results - name: segid required: true description: the process segment id; this is the segment_id field in search results. outputs: - contextPath: Process.CrossProc.OtherProcessMD5 description: Other process MD5 - contextPath: Process.MD5 description: Process MD5 - contextPath: Process.Modules.MD5 description: Module MD5 - contextPath: Process.CommandLine description: Process CommandLine - contextPath: Process.Registry.RegistryPath description: Registry path - contextPath: Process.Path description: Process Path - contextPath: Process.CbID description: Cb unique ID for this process instance - required (together with CbSegmentID) to fetch further info on a process. - contextPath: Process.Parent.Name description: The parent Process Name - contextPath: Process.Hostname description: Process Hostname - contextPath: Process.Binaries.DigSig.Publisher description: The publisher of the Digital Signature - contextPath: Process.CrossProc.Action description: Cross process action - contextPath: Process.CrossProc.OtherProcessCbID description: Other process CbID - contextPath: Process.CbSegmentID description: Cb 'segment' where this process instance is stored. Required to fetch further info on a process. - contextPath: Process.Name description: Process Name - contextPath: Process.CrossProc.Time description: Time of action - contextPath: Process.PID description: Process PID - contextPath: Process.Modules.Filepath description: Module path - contextPath: Process.Binaries.DigSig.Result description: Cb's decision after checking this binary's Digital Signature - contextPath: Process.Parent.PID description: The parent Process PID - contextPath: Process.Binaries.MD5 description: Binary MD5 - contextPath: Process.CrossProc.OtherProcessBinary description: Other process binary - contextPath: Process.Registry.Time description: Registry time - contextPath: Process.Modules.Time description: Module time description: Retrieve all process events for a given process segmented by segment ID - name: cb-quarantine-device arguments: - name: sensor required: true default: true description: the sensor ID to quarantine outputs: - contextPath: Endpoint.LastAction description: Endpoint Actions important: - contextPath: Endpoint(val.LastAction) description: Endpoint Actions related: "" description: Isolate the endpoint from the network - name: cb-sensor-info arguments: - name: sensor default: true description: the sensor id - name: ip description: returns the sensor registration(s) with specified IP address - name: hostname description: returns the sensor registration(s) with matching hostname - name: groupid description: returns the sensor registration(s) in the specified sensor group id outputs: - contextPath: CbResponse.Sensors.Status description: Sensor Status - contextPath: CbResponse.Sensors.LastUpdate description: Sensor Last Updated - contextPath: CbResponse.Sensors.Uptime description: The Sensor uptime - contextPath: CbResponse.Sensors.SupportsCbLive description: Sensor Support CB Live - contextPath: CbResponse.Sensors.Notes description: Sensor Notes - contextPath: CbResponse.Sensors.Hostname description: Sensor Hostname - contextPath: CbResponse.Sensors.CbSensorID description: Sensor ID - contextPath: CbResponse.Sensors.Isolated description: Sensor Isolated - contextPath: CbResponse.Sensors.IPAddresses description: Sensor IP Addresses - contextPath: CbResponse.Sensors.OS description: Sensor OS description: Display information about the given sensor - name: cb-unblock-hash arguments: - name: md5hash required: true description: the hash on block list - name: text required: true description: text description of block list outputs: - contextPath: File.LastAction description: Last action taken on this file important: - contextPath: File(val.LastAction) description: File Actions related: "" description: Unblocking hash - name: cb-unquarantine-device arguments: - name: sensor required: true default: true description: the sensor ID to quarantine outputs: - contextPath: Endpoint.LastAction description: Endpoint Actions important: - contextPath: Endpoint(val.LastAction) description: Endpoint Actions related: "" description: Unquarantine the endpoint - name: cb-version arguments: [] description: Display the CarbonBlack version - name: cb-watchlist-del arguments: - name: watchlist-id required: true description: Watchlist ID description: Delete a watchlist in Carbon black Response. - name: cb-watchlist-get arguments: - name: watchlist-id default: true description: Watchlist ID outputs: - contextPath: CbResponse.Watchlists.LastHit description: Watchlist last hit - contextPath: CbResponse.Watchlists.TotalHits description: Watchlist Total hits - contextPath: CbResponse.Watchlists.SearchQuery description: Cb search query used for the watchlist. - contextPath: CbResponse.Watchlists.Name description: Watchlist Name - contextPath: CbResponse.Watchlists.Enabled description: Watchlist is enabled - contextPath: CbResponse.Watchlists.LastHitCount description: Watchlist last hit count - contextPath: CbResponse.Watchlists.DateAdded description: Watchlist Date added - contextPath: CbResponse.Watchlists.SearchTimestamp description: Watchlist last hit count - contextPath: CbResponse.Watchlists.CbWatchlistID description: Watchlist ID description: Retrieve info for a watchlist in Carbon black Response. - name: cb-watchlist-new arguments: - name: search-query required: true description: the raw Carbon Black query that this watchlist matches - name: name required: true description: name of this watchlist outputs: - contextPath: CbResponse.Watchlists.LastHit description: Watchlist last hit - contextPath: CbResponse.Watchlists.TotalHits description: Watchlist Total hits - contextPath: CbResponse.Watchlists.SearchQuery description: Cb search query used for the watchlist. - contextPath: CbResponse.Watchlists.Name description: Watchlist Name - contextPath: CbResponse.Watchlists.Enabled description: Watchlist is enabled - contextPath: CbResponse.Watchlists.LastHitCount description: Watchlist last hit count - contextPath: CbResponse.Watchlists.DateAdded description: Watchlist Date added - contextPath: CbResponse.Watchlists.SearchTimestamp description: Watchlist last hit count - contextPath: CbResponse.Watchlists.CbWatchlistID description: Watchlist ID description: Create a new watchlist in Carbon black Response. - name: cb-watchlist-set arguments: - name: watchlist-id required: true description: Watchlist ID - name: search-query description: the raw Carbon Black query that this watchlist matches - name: name description: name of this watchlist - name: indexType description: the type of watchlist. Valid values are 'modules' and 'events' for binary and process watchlists, respectively description: Modify a watchlist in Carbon black Response. - name: cb-alert-update arguments: - name: uniqueId required: true description: Alert unique identifier - name: status required: true auto: PREDEFINED predefined: - Resolved - Unresolved - In Progress - False Positive description: 'Updated alert''s status: Resolved,Unresolved,In Progress or False Positive' - name: setIgnored auto: PREDEFINED predefined: - "true" - "false" description: Whether to stop showing this type of alert description: Alert update and resolution - name: cb-watchlist arguments: [] outputs: - contextPath: CbResponse.Watchlists.LastHit description: Watchlist last hit - contextPath: CbResponse.Watchlists.TotalHits description: Watchlist Total hits - contextPath: CbResponse.Watchlists.SearchQuery description: Cb search query used for the watchlist. - contextPath: CbResponse.Watchlists.Name description: Watchlist Name - contextPath: CbResponse.Watchlists.Enabled description: Watchlist is enabled - contextPath: CbResponse.Watchlists.LastHitCount description: Watchlist last hit count - contextPath: CbResponse.Watchlists.DateAdded description: Watchlist Date added - contextPath: CbResponse.Watchlists.SearchTimestamp description: Watchlist last hit count - contextPath: CbResponse.Watchlists.CbWatchlistID description: Watchlist ID description: Retrieve watchlist in Carbon black Response. - name: cb-binary-download arguments: - name: md5 required: true default: true description: MD5 hash of the file. - name: summary auto: PREDEFINED predefined: - "yes" - "no" description: Whether to include the summary. outputs: - contextPath: File.DigSig.Publisher description: The publisher of the digital signature. - contextPath: File.InternalName description: The internal name. - contextPath: File.ServerAddedTimestamp description: The timestamp when the server was added. - contextPath: File.Name description: The binary name. - contextPath: File.Extension description: The binary extension. - contextPath: File.Timestamp description: The binary timestamp. - contextPath: File.Hostname description: The binary hostname. - contextPath: File.Description description: The binary description. - contextPath: File.DigSig.Result description: The Carbon Black decision after checking this binary's digital signature. - contextPath: File.LastSeen description: LThe lst time the binary was seen. - contextPath: File.Path description: The binary path. - contextPath: File.ProductName description: The product name. - contextPath: File.OS description: The OS. - contextPath: File.MD5 description: The MD5 hash of the binary. - contextPath: File.Company description: Name of the company that released a binary. - contextPath: File.DigitalSignature.Publisher description: Publisher of the digital signature for the file. - contextPath: File.Name description: Full filename, for example data.xls. - contextPath: File.Signature.OriginalName description: The file's original name. - contextPath: File.Signature.InternalName description: The file's internal name. - contextPath: File.Signature.FileVersion description: The file version. - contextPath: File.Signature.Description description: The description of the signature. description: Retrieve a binary from CarbonBlack based on hash. Returns a .zip file containing the requested file and it's metadata. isfetch: true dockerimage: demisto/python:2.7.18.8715 tests: - Carbon Black Response Test