Carbon Black Enterprise Response (v2.1.63)
Query and respond with Carbon Black endpoint detection and response.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Categories
- Endpoint
Incident fields (4)
- Carbon Black EDR IOC Value
- Carbon Black EDR Segment ID
- Carbon Black EDR Watchlist Id
- Carbon Black EDR Watchlist Name
Integrations (2)
- VMware Carbon Black EDR v2
- VMware Carbon Black EDR (Deprecated)
Layouts (1)
- Carbon Black EDR Incidents
Playbooks (10)
- Block Endpoint - Carbon Black Response
- Block Endpoint - Carbon Black Response V2
- Block Endpoint - Carbon Black Response V2.1
- Block File - Carbon Black Response
- Carbon Black EDR - Enrich Process
- Carbon Black Response - Unisolate Endpoint
- Get File Sample By Hash - Carbon Black Enterprise Response
- Get File Sample From Path - Carbon Black Enterprise Response
- Get the binary file from Carbon Black by its MD5 hash
- Search Endpoints By Hash - Carbon Black Response V2
Scripts (9)
- CBAlerts
- CBEvents
- CBFindIP
- CBLiveFetchFiles
- CBLiveGetFile
- CBLiveGetFile_V2
- CBSensors
- CBSessions
- CBWatchlists
README
This response and threat hunting pack provides you with endpoint data enabling you to investigate and analyze potential threats in real time.
What does this pack do?
- Hunts for malicious indicators.
- Investigates and analyzes potential malware and threats.
- Remediates/removes unauthorized, malicious, or unwanted processes.
- Gets alerts about suspected processes running on an endpoint.
- Investigates processes and related files with potential malware or threats.
This pack includes several automations and playbooks to help with the malware investigations.