Carbon Black Enterprise EDR
VMware Carbon Black Enterprise EDR (formerly known as Carbon Black ThreatHunter) is an advanced threat hunting and incident response solution delivering continuous visibility for top security operations centers (SOCs) and incident response (IR) teams. (formerly known as ThreatHunter).
- Category
- Endpoint
- Pack
- CarbonBlackEnterpriseEDR
Configuration parameters
- url — Server URL (e.g. https://defense.conferdeploy.net) (required)
- organization_key — Organization Key (required)
- custom_key — Custom Key
- custom_id — Custom ID
- credentials_custom — Custom ID
- isFetch — Fetch incidents
- incidentType — Incident type
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- fetch_limit — Fetch limit
- incidentFetchInterval — Incidents Fetch Interval
Commands (39)
- cb-eedr-add-alert-notes — Update alert ID notes.
- cb-eedr-add-threat-notes — Update threat ID notes.
- cb-eedr-add-threat-tags — Update threat ID tags.
- cb-eedr-alert-workflow-update — Updates the workflow of a single alert.
- cb-eedr-device-background-scan — Start a background scan on device.
- cb-eedr-device-background-scan-stop — Stops a background scan on the specified devices.
- cb-eedr-device-bypass — Enable a bypass on device.
- cb-eedr-device-policy-update — Update device policy.
- cb-eedr-device-quarantine — Quarantines a device.
- cb-eedr-device-unbypass — Disable a bypass on device.
- cb-eedr-device-unquarantine — Removes a device from quarantine.
- cb-eedr-devices-list — List devices based on the search query.
- cb-eedr-events-by-process-get — Retrieves the events associated with a given process.
- cb-eedr-file-device-summary — Gets an overview of the devices that executed the file.
- cb-eedr-file-paths — Return a summary of the observed file paths.
- cb-eedr-files-download-link-get — The files are able to be downloaded via AWS S3 pre-signed URLs.
- cb-eedr-get-file-metadata — Returns all of the metadata for the specified binary identified by the SHA256 hash.
- cb-eedr-get-threat-tags — Output a list of tags for the provided threat ID.
- cb-eedr-get-watchlist-by-id — Gets watchlist information by watchlist ID.
- cb-eedr-ioc-ignore — IOC ioc_id for report report_id will not match future events for any watchlist.
- cb-eedr-ioc-ignore-status — Gets the current ignore status for IOC ioc_id in report report_id.
- cb-eedr-ioc-reactivate — IOC ioc_id for report report_id will match future events for all watchlists.
- cb-eedr-list-alerts — Returns a list of alerts.
- cb-eedr-process-search — Creates a process search job and returns results if 'polling' argument is True.
- cb-eedr-process-search-results — Retrieves the process search results for a given job ID.
- cb-eedr-report-create — Adds a new watchlist report.
- cb-eedr-report-get — Retrieves the specified report.
- cb-eedr-report-ignore — Report with report_id and all contained IOCs will not match future events for any watchlist.
- cb-eedr-report-ignore-status — Get current ignore status for report with report_id.
- cb-eedr-report-reactivate — Report with report_id and all contained IOCs will match future events for all watchlists.
- cb-eedr-report-remove — Remove report with report_id.
- cb-eedr-report-update — Updates the specified report.
- cb-eedr-watchlist-alerts-disable — Turns off alerts for the watchlist with the specified watchlist ID.
- cb-eedr-watchlist-alerts-enable — Turns on alerts for the watchlist with the specified watchlist ID.
- cb-eedr-watchlist-alerts-status — Retrieves the alert status for the watchlist with given watchlist ID.
- cb-eedr-watchlist-create — Creates a new report or classifier watchlist.
- cb-eedr-watchlist-delete — Removes the specified watchlist.
- cb-eedr-watchlist-list — Retrieves all watchlists.
- cb-eedr-watchlist-update — Updates the specified watchlist. This will update the tags and alert status as well as any reports or classifiers attached to the watchlist.