VMware Carbon Black EDR v2
VMware Carbon Black EDR (formerly known as Carbon Black Response).
- Category
- Endpoint
- Pack
- Carbon_Black_Enterprise_Response
Configuration parameters
- url — Server URL (required)
- credentials —
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- alert_query — Filter alerts by query
- alert_status — Filter alerts by status
- alert_feed_name — Filter alerts by feed name
- max_fetch — Maximum Number Of Incidents To Fetch
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (21)
- cb-edr-alert-search — Retrieve alerts from Carbon Black Response.
- cb-edr-alert-update — Alerts update and resolution. Updating Alerts requires an API key with Global Administrator privileges.
- cb-edr-binary-ban — Prevent execution of a specified md5 hash.
- cb-edr-binary-bans-list — Returns a list of banned hashes.
- cb-edr-binary-download — Download the binary with this md5 hash.
- cb-edr-binary-search — Binary search.
- cb-edr-binary-summary — Returns the metadata for the binary with the provided md5.
- cb-edr-process-events-list — Gets the events for the process with CB process id (process_id) and segment id (segment_id).
- cb-edr-process-get — Gets basic process information for segment of process.
- cb-edr-process-segments-get — Gets segment data for a given process.
- cb-edr-processes-search — Process search.
- cb-edr-quarantine-device — Isolate the endpoint from the network.
- cb-edr-sensor-installer-download — Download a zip archive including a sensor installer for Windows, Mac OS X or Linux.
- cb-edr-sensors-list — List the CarbonBlack sensors.
- cb-edr-unquarantine-device — Unquarantine the endpoint.
- cb-edr-watchlist-create — Creates a new Watchlist within EDR,.
- cb-edr-watchlist-delete — Delete a Watchlist that is specified using ID.
- cb-edr-watchlist-update — Updates a Watchlist that is specified using ID.
- cb-edr-watchlist-update-action — Updates a Watchlist action that is specified using ID.
- cb-edr-watchlists-list — Retrieve watchlist in Carbon black Response.
- endpoint — Display information about the given sensor.