Use this playbook to search processes in Carbon Black Enterprise EDR.
This playbook implements polling by continuously running the cb-eedr-process-search-results
command
until the operation completes.
Carbon Black Cloud Enterprise EDR
- Details
- Content
- Dependencies
- Version History
Advanced threat hunting and incident response solution.
Name | Description |
---|---|
Carbon Black EDR Search Process |
Name | Description |
---|---|
VMware Carbon Black Enterprise EDR | VMware Carbon Black Enterprise EDR (formerly known as Carbon Black ThreatHunter) is an advanced threat hunting and incident response solution delivering continuous visibility for top security operations centers (SOCs) and incident response (IR) teams. (formerly known as ThreatHunter) |
Name | Description |
---|---|
Carbon Black EDR Search Process | Use this playbook to search processes in Carbon Black Enterprise EDR. |
Name | Description |
---|---|
VMware Carbon Black Enterprise EDR | VMware Carbon Black Enterprise EDR (formerly known as Carbon Black ThreatHunter) is an advanced threat hunting and incident response solution delivering continuous visibility for top security operations centers (SOCs) and incident response (IR) teams. (formerly known as ThreatHunter) |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Common Playbooks | By: Cortex XSOAR |
Pack Name | Pack By |
---|
Pack Name | Pack By |
---|---|
Filters And Transformers | By: Cortex XSOAR |
Rasterize | By: Cortex XSOAR |
Common Playbooks | By: Cortex XSOAR |
MITRE ATT&CK | By: Cortex XSOAR |
Cortex REST API | By: Cortex XSOAR |
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.10.4.29342.
Integrations
VMware Carbon Black Enterprise EDR
- Added type validations and other internal code improvements.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.10.1.27636.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.10.1.26972.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.10.1.25933.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.9.9.25564.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.9.8.24399.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.9.7.24076.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.9.6.24019.
Integrations
VMware Carbon Black Enterprise EDR
- Upgraded the Docker image to: demisto/python3:3.9.6.22912.
Integrations
VMware Carbon Black Enterprise EDR
- Upgraded the Docker image to: demisto/python3:3.9.5.21272.
Integrations
VMware Carbon Black Enterprise EDR
- Upgraded the Docker image to: demisto/python3:3.9.5.20958.
Integrations
VMware Carbon Black Enterprise EDR
- Documentation and metadata improvements.
- Updated the Docker image to: demisto/python3:3.9.1.15759.
Integrations
VMware Carbon Black Enterprise EDR
Maintenance and stability enhancements.
Updated docker image from 3.8.6.13358
to 3.8.6.14516
.
Integrations
VMware Carbon Black Enterprise EDR
- Fixed an issue where the sort_field argument had invalid options in the cb-eedr-list-alerts command.
- Upgraded the Docker image to demisto/python3:3.8.6.13358.
Integrations
VMware Carbon Black Enterprise EDR
- Updated the Docker image to: demisto/python3:3.8.6.12176.
- Added 3 commands.
- cb-eedr-process-search
- cb-eedr-process-search-results
- cb-eedr-events-by-process-search
Playbooks
- Added the new generic polling playbook Carbon Black EDR Search Process, which enables you to search a process by query or parameters.
Integrations
VMware Carbon Black Enterprise EDR
- Renamed the integration Carbon Black Enterprise EDR to VMware Carbon Black Enterprise EDR.
PUBLISHER
Cortex
PLATFORMS
INFO
Certification | Certified | Read more |
Supported By | Cortex | |
Created | September 9, 2020 | |
Last Release | March 23, 2023 |
WORKS WITH THE FOLLOWING INTEGRATIONS:
