carbonblack-v2
Deprecated. Use VMware Carbon Black EDR v2 instead.
- Category
- Endpoint
- Pack
- Carbon_Black_Enterprise_Response
Configuration parameters
- serverurl — Server URL (required)
- apitoken — API Token (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- fetchAlertsSeverityThreshold — Fetch Alert Severity Threshold Higher Than
- rows — Maximum Number Of Incidents To Fetch
Commands (21)
- cb-alert — Retrieve alerts from Carbon Black Response.
- cb-alert-update — Alert update and resolution
- cb-binary — Query for binaries based on given parameters
- cb-binary-download — Retrieve a binary from CarbonBlack based on hash. Returns a .zip file containing the requested file and it's metadata.
- cb-binary-get — Deprecated. Use the cb-binary-download command instead.
- cb-block-hash — Blocking hash
- cb-get-hash-blacklist — Returns a list of hashes on block list, with each list entry describing one hash on block list.
- cb-get-process — Gets basic process information for segment (segment_id) of process (process_id)
- cb-get-processes — Query processes based on given parameters
- cb-list-sensors — List the CarbonBlack sensors
- cb-process-events — Retrieve all process events for a given process segmented by segment ID
- cb-quarantine-device — Isolate the endpoint from the network
- cb-sensor-info — Display information about the given sensor
- cb-unblock-hash — Unblocking hash
- cb-unquarantine-device — Unquarantine the endpoint
- cb-version — Display the CarbonBlack version
- cb-watchlist — Retrieve watchlist in Carbon black Response.
- cb-watchlist-del — Delete a watchlist in Carbon black Response.
- cb-watchlist-get — Retrieve info for a watchlist in Carbon black Response.
- cb-watchlist-new — Create a new watchlist in Carbon black Response.
- cb-watchlist-set — Modify a watchlist in Carbon black Response.